[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*


CCE-93904-1
Use the hardware default graphics adapter for all Remote Desktop Services sessions This policy setting enables system administrators to change the graphics rendering for all Remote Desktop Services sessions on a Remote Desktop Session Host (RD Session Host) server. If you enable this policy sett ...

CCE-94038-7
Change Microsoft XPS Document Writer (MXDW) default output format to the legacy Microsoft XPS format (*.xps) Microsoft XPS Document Writer (MXDW) generates OpenXPS (*.oxps) files by default in Windows 8. If you enable this group policy setting, the default MXDW output format is the legacy Micros ...

CCE-93347-3
Disable detection of slow network connections This policy setting disables the detection of slow network connections. Slow link detection measures the speed of the connection between a user's computer and the remote server that stores the roaming user profile. When the system detects a slow lin ...

CCE-94091-6
IAS Jet Database Access The IAS Jet Database Access service uses the Remote Authentication Dial-In User Service (RADIUS) protocol to provide authentication, authorization, and accounting services. It is only available in 64-bit versions of Windows. With Internet Authentication Services (IAS), you c ...

CCE-94101-3
Windows Internal Database (MICROSOFT**SSEE) Windows Internal Database Service.

CCE-93182-4
Distributed Transaction Coordinator Coordinates transactions that span multiple resource managers, such as databases, message queues, and file systems. If this service is stopped, these transactions will not occur. If this service is disabled, any services that explicitly depend on it will fail to ...

CCE-93227-7
IKE and AuthIP IPsec Keying Modules The IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules. These keying modules are used for authentication and key exchange in Internet Protocol security (IPsec). Stopping or disabling the IKEEXT service ...

CCE-93708-6
Only allow local user profiles This setting determines if roaming user profiles are available on a particular computer. By default, when roaming profile users log on to a computer, their roaming profile is copied down to the local computer. If they have already logged on to this computer in the pas ...

CCE-93410-9
Background Tasks Infrastructure Service Windows infrastructure service that controls which background tasks can run on the system.

CCE-93129-5
Do not allow clipboard redirection Specifies whether to prevent the sharing of clipboard contents (clipboard redirection) between a remote computer and a client computer during a Remote Desktop Services session. You can use this setting to prevent users from redirecting clipboard data to and from ...

CCE-99732-0
This subcategory reports on the activities of the Internet Protocol security (IPsec) driver. Events for this subcategory include: ? 4960: IPsec dropped an inbound packet that failed an integrity check. If this problem persists, it could indicate a network issue or that packets are being modified in ...

CCE-93806-8
User Profile Service This service is responsible for loading and unloading user profiles. If this service is stopped or disabled, users will no longer be able to successfully logon or logoff, applications may have problems getting to users' data, and components registered to receive profile event n ...

CCE-94136-9
Disable Logging If this setting is enabled Windows Error Reporting events will not be logged to the system event log.

CCE-93881-1
All Removable Storage classes: Deny all access Configure access to all removable storage classes. This policy setting takes precedence over any individual removable storage policy settings. To manage individual classes, use the policy settings available for each class. If you enable this policy s ...

CCE-93423-2
Message Queuing Down Level Clients The Message Queuing Down Level Clients service provides Active Directory access for Windows NT 4.0, Windows 95, Windows 98, Windows Millennium Edition, and Windows 2000 clients that use the Message Queuing service on domain controllers. The Message Queuing service ...

CCE-93214-5
Encrypting File System (EFS) Provides the core file encryption technology used to store encrypted files on NTFS file system volumes. If this service is stopped or disabled, applications will be unable to access encrypted files.

CCE-93578-3
Hyper-V Volume Shadow Copy Requestor Coordinates the communications that are required to use Volume Shadow Copy Service to back up applications and data on this virtual machine from the operating system on the physical computer.

CCE-99745-2
The registry value entry PerformRouterDiscovery was added to the template file in the HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\ registry key. The entry appears as MSS: (PerformRouterDiscovery) Allow IRDP to detect and configure Default Gateway addresses (could lead to Do ...

CCE-94212-8
Interactive Services Detection Enables user notification of user input for interactive services, which enables access to dialogs created by interactive services when they appear. If this service is stopped, notifications of new interactive service dialogs will no longer function and there may no lo ...

CCE-93828-2
Fail authentication requests when Kerberos armoring is not available This policy setting controls whether a computer requires that Kerberos message exchanges be armored when communicating with a domain controller. Warning: When a domain does not support Kerberos armoring by enabling 'Support Dyn ...

CCE-93926-4
Turn on network protection against exploits of known vulnerabilities This policy setting allows you to configure network protection against exploits of known vulnerabilities. If you enable or do not configure this setting, the network protection will be enabled. If you disable this setting, t ...

CCE-93552-8
Always wait for the network at computer startup and logon This policy setting determines whether Group Policy processing is synchronous (that is, whether computers wait for the network to be fully initialized during computer startup and user logon). By default, on client computers, Group Policy pro ...

CCE-99701-5
The registry value entry TCPMaxDataRetransmissions was added to the template file in the HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip \Parameters\ registry key. The entry appears as MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 i ...

CCE-93587-4
Allow logon scripts when NetBIOS or WINS is disabled This policy setting allows user logon scripts to run when the logon cross-forest, DNS suffixes are not configured and NetBIOS or WINS is disabled. This policy setting affects all user accounts interactively logging on to the computer. If you ena ...

CCE-93774-8
Do not process the run once list This policy setting causes the run once list, which is the list of programs that Windows Vista runs automatically when it starts, to be ignored. This policy setting differs from the Do not process the legacy run list setting in that programs on this list will run on ...

CCE-93258-2
Accounts: Limit local account use of blank passwords to console logon only This policy setting determines whether local accounts that are not password protected can be used to log on from locations other than the physical computer console. If you enable this policy setting, local accounts that have ...

CCE-93530-4
Automatically send memory dumps for OS-generated error reports This policy setting controls whether memory dumps in support of OS-generated error reports can be sent to Microsoft automatically. This policy does not apply to error reports generated by 3rd-party products, or additional data other tha ...

CCE-94180-7
DFS Replication Enables you to synchronize folders on multiple servers across local or wide area network (WAN) network connections. This service uses the Remote Differential Compression (RDC) protocol to update only the portions of files that have changed since the last replication.

CCE-93992-6
Network access: Do not allow storage of passwords and credentials for network authentication This policy setting determines whether the Stored User Names and Passwords feature may save passwords or credentials for later use when it gains domain authentication. If you enable this policy setting, the ...

CCE-93917-3
Monitor file and program activity on your computer This policy setting allows you to configure monitoring for file and program activity. If you enable or do not configure this setting, monitoring for file and program activity will be enabled. If you disable this setting, monitoring for file a ...

CCE-93663-3
Do not send additional data If this setting is enabled any additional data requests from Microsoft in response to a Windows Error Reporting event will be automatically declined without notice to the user.

CCE-94029-6
Allow printers to be published Determines whether the computer's shared printers can be published in Active Directory. If you enable this setting or do not configure it, users can use the 'List in directory' option in the Printer's Properties' Sharing tab to publish shared printers in Active Direc ...

CCE-93432-3
Always use classic logon This setting forces the user to log on to the computer using the classic logon screen. By default, a workgroup is set to use the simple logon screen. This setting only works when the computer is not on a domain.

CCE-94082-5
Active Directory Web Services This service provides a Web Service interface to instances of the directory service (AD DS and AD LDS) that are running locally on this server. If this service is stopped or disabled, client applications, such as Active Directory PowerShell, will not be able to access ...

CCE-93103-0
Remove Windows Security item from Start menu Specifies whether to remove the Windows Security item from the Settings menu on Remote Desktop clients. You can use this setting to prevent inexperienced users from logging off from Remote Desktop Services inadvertently. If the status is set to Enabled, ...

CCE-99758-5
Enables management of password for local administrator account If you enable this setting, local administrator password is managed If you disable or not configure this setting, local administrator password is NOT managed Countermeasure: Enable this setting. Potential Impact: Loca ...

CCE-93565-0
Turn on catch-up full scan This policy setting allows you to configure catch-up scans for scheduled full scans. A catch-up scan is a scan that is initiated because a regularly scheduled scan was missed. Usually these scheduled scans are missed because the computer was turned off at the scheduled t ...

CCE-93765-6
Turn off app notifications on the lock screen This policy setting allows you to prevent app notifications from appearing on the lock screen. If you enable this policy setting, no app notifications are displayed on the lock screen. If you disable or do not configure this policy setting, users ...

CCE-93414-1
Removable Disks: Deny read access This policy setting denies read access to removable disks. If you enable this policy setting, read access will be denied to this removable storage class. If you disable or do not configure this policy setting, read access will be allowed to this removable storage ...

CCE-93284-8
When enabled, this policy setting causes Local System services that use Negotiate to use the computer identity when NTLM authentication is selected by the negotiation. This policy is supported on at least Windows 7 or Windows Server 2008 R2. Countermeasure: Configure Network security: Allo ...

CCE-93730-0
WPD Devices: Deny write access This policy setting denies write access to removable disks, which may include media players, cellular phones, auxiliary displays, and CE devices. If you enable this policy setting, write access will be denied to this removable storage class. If you disable or do not ...

CCE-93908-2
Configure local setting override for scheduled scan time This policy setting configures a local override for the configuration of scheduled scan time. This setting can only be set by Group Policy. If you enable this setting, the local preference setting will take priority over Group Policy. If yo ...

CCE-93173-3
Require strict KDC validation This policy setting controls the Kerberos client's behavior in validating the KDC certificate. If you enable this policy setting, the Kerberos client requires that the KDC's X.509 certificate contains the KDC key purpose object identifier in the Extended Key U ...

CCE-93427-3
Remote Desktop Licensing The Remote Desktop Licensing service installs a license server and provides registered client licenses when a computer is connecting to a server that has Terminal Server enabled. The Terminal Server Licensing service is a low-impact service that stores the client licenses t ...

CCE-94012-2
Turn off Automatic Root Certificates Update Specifies whether to automatically update root certificates using the Windows Update Web site. Typically, a certificate is used when you use a secure Web site or when you send and receive secure e-mail. Anyone can issue certificates, but to have transac ...

CCE-93271-5
Only use Package Point and print This policy restricts clients computers to use package point and print only. If this setting is enabled, users will only be able to point and print to printers that use package-aware drivers. When using package point and print, client computers will check the drive ...

CCE-93075-0
All Removable Storage: Allow direct access in remote sessions This policy setting grants normal users direct access to removable storage devices in remote sessions. If you enable this policy setting, remote users will be able to open direct handles to removable storage devices in remote sessions. ...

CCE-94167-4
Do not allow font smoothing This policy setting allows you to specify whether font smoothing is allowed for remote connections. By default, font smoothing is allowed for remote connections. You can configure font smoothing on the Experience tab in Remote Desktop Connection (RDC) or by ...

CCE-99847-6
This policy setting allows you to audit user attempts to access file system objects on a removable storage device. A security audit event is generated only for all objects for all types of access requested. If you configure this policy setting, an audit event is generated each time an account access ...

CCE-93623-7
Send data when on connected to a restricted/costed network This policy setting determines whether Windows Error Reporting (WER) checks for a network cost policy that restricts the amount of data that is sent over the network. If you enable this policy setting, WER does not check for network cost ...

CCE-94110-4
Allow restore of system to default state Requirements: At least Windows 7 Description: This policy setting controls whether users can access the options in Recovery (in Control Panel) to restore the computer to the original state or from a user-created system image. If you enable or do not ...

CCE-93752-4
Device Install Service Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.

CCE-93303-6
Allow remote start of unlisted programs This policy setting allows you to specify whether remote users can start any program on the RD Session Host server when they start a Remote Desktop Services session, or whether they can only start programs that are listed in the RemoteApp Programs list. You ...

CCE-99705-6
This policy setting controls the level of validation a computer with shared folders or printers (the server) performs on the service principal name (SPN) that is provided by the client computer when it establishes a session using the server message block (SMB) protocol. The server message block (SM ...

CCE-93218-6
SNMP Service The SNMP service allows incoming Simple Network Management Protocol (SNMP) requests to be serviced by the local computer. SNMP includes agents that monitor activity in network devices and report to the network console workstation. SNMP provides a method of managing network hosts such a ...

CCE-93841-5
Always rasterize content to be printed using a software rasterizer Determines whether the XPS Rasterization Service or the XPS-to-GDI conversion (XGC) is forced to use a software rasterizer instead of a Graphics Processing Unit (GPU) to rasterize pages. On machines with an ARM processor, this po ...

CCE-99803-9
Specifies whether Virtualization Based Security is enabled. Virtualization Based Security uses the Windows Hypervisor to provide support for security services. Virtualization Based Security requires Secure Boot, and can optionally be enabled with the use of DMA Protections. DMA protections require ...

CCE-93534-6
Turn on e-mail scanning This policy setting allows you to configure e-mail scanning. When e-mail scanning is enabled, the engine will parse the mailbox and mail files, according to their specific format, in order to analyze the mail bodies and attachments. Several e-mail formats are currently suppo ...

CCE-93205-3
Group Policy Client The service is responsible for applying settings configured by administrators for the computer and users through the Group Policy component. If the service is stopped or disabled, the settings will not be applied and applications and components will not be manageable through Gro ...

CCE-99682-7
Systems at unsupported servicing levels will not receive security updates for new vulnerabilities, which leave them subject to exploitation. Systems must be maintained at a servicing level supported by the vendor with new security updates. Fix: Update the system to a Version 1809 (Build 17763.xxx) ...

CCE-93667-4
This policy setting determines the strength of the default discretionary access control list (DACL) for objects. The setting helps secure objects that can be located and shared among processes and its default configuration strengthens the DACL, because it allows users who are not administrators to r ...

CCE-94158-3
Shutdown: Allow system to be shut down without having to log on This policy setting determines whether a computer can be shut down when a user is not logged on. If this policy setting is enabled, the shutdown command is available on the Windows logon screen. Microsoft recommends to disable this pol ...

CCE-93062-8
MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes The registry value entry EnableICMPRedirect was added to the template file in the HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\ registry key. The entry appears as MSS: (EnableICMPRedirect) Allo ...

CCE-93009-9
Windows Color System The WcsPlugInService service hosts third-party Windows Color System color device module and gamut map model plug-in modules. These plug-in modules are vendor-specific extensions to the Windows Color System baseline color device and gamut map modules. Stopping or disabling the W ...

CCE-93178-2
Windows All-User Install Agent Install AppX Packages for all authorized users

CCE-93276-4
Do not automatically encrypt files moved to encrypted folders Prevents Windows Explorer from encrypting files that are moved to an encrypted folder. If you disable this setting or do not configure it, Windows Explorer automatically encrypts files that are moved to an encrypted folder. This settin ...

CCE-93690-6
Do not use temporary folders per session This policy setting allows you to prevent Remote Desktop Services from creating session-specific temporary folders. You can use this policy setting to disable the creation of separate temporary folders on a remote computer for each session. By default, Remo ...

CCE-94162-5
DHCP Server Performs TCP/IP configuration for DHCP clients, including dynamic assignments of IP addresses, specification of the WINS and DNS servers, and connection-specific DNS names. If this service is stopped, the DHCP server will not perform TCP/IP configuration for clients. If this service is ...

CCE-93592-4
This policy setting determines whether a domain member should attempt to negotiate encryption for all secure channel traffic that it initiates. If you enable this policy setting, the domain member will request encryption of all secure channel traffic. If you disable this policy setting, the domain m ...

CCE-93700-3
Enable disk quotas Enables and disables disk quota management on all NTFS volumes of the computer, and prevents users from changing the setting. If you enable this setting, disk quota management is enabled, and users cannot disable it. If you disable the setting, disk quota management is disabled ...

CCE-94064-3
Do not set default client printer to be default printer in a session This policy setting allows you to specify whether the client default printer is automatically set as the default printer in a session on an RD Session Host server. By default, Remote Desktop Services automatically designates the ...

CCE-93396-0
Tape Drives: Deny read access This policy setting denies read access to the Tape Drive removable storage class. If you enable this policy setting, read access will be denied to this removable storage class. If you disable or do not configure this policy setting, read access will be allowed to thi ...

CCE-93121-2
CNG Key Isolation The CNG key isolation service is hosted in the LSA process. The service provides key process isolation to private keys and associated cryptographic operations as required by the Common Criteria. The service stores and uses long-lived keys in a secure process complying with Common ...

CCE-94077-5
Network security: Minimum session security for NTLM SSP based (including secure RPC) servers This policy setting determines which behaviors are allowed for applications using the NTLM Security Support Provider (SSP). The SSP Interface (SSPI) is used by applications that need authentication services ...

CCE-93570-0
RemoteApp and Desktop Connection Management Manages the assignment of remoteApp and desktop connection resources to users

CCE-93615-3
Accounts: Guest account status This policy setting determines whether the Guest account is enabled or disabled. The Guest account allows unauthenticated network users to gain access to the system. Note that this setting will have no impact when applied to the domain controller organizational unit v ...

CCE-93722-7
System settings: Optional subsystems This policy setting determines which subsystems are used to support applications in your environment. Note: When you configure this setting you specify a list of one or more objects. The delimiter used when entering the list is a line feed or carriage return, th ...

CCE-93953-8
Check for New Signatures Before Scheduled Scans Checks for new signatures before running scheduled scans. If you enable this policy setting, the scheduled scan checks for new signatures before it scans the computer. If you disable or do not configure this policy setting, the scheduled scan begins ...

CCE-94042-9
Microsoft FTP Service Enables this server to be a File Transfer Protocol (FTP) server. If this service is stopped, the server cannot function as an FTP server. If this service is disabled, any services that explicitly depend on it will fail to start.

CCE-93241-8
Allow NTLM to fall back to NULL session when used with LocalSystem. The default is TRUE up to Windows Vista and FALSE in Windows 7. Countermeasure: Configure Network security: Allow LocalSystem NULL session fallback to Disabled. Potential Impact: Any applications that require NULL ses ...

CCE-93010-7
DHCP Client Registers and updates IP addresses and DNS records for this computer. If this service is stopped, this computer will not receive dynamic IP addresses and DNS updates. If this service is disabled, any services that explicitly depend on it will fail to start.

CCE-94175-7
Internet Connection Sharing (ICS) Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network.

CCE-93428-1
Display instructions in startup scripts as they run This policy setting displays the instructions in startup scripts as they run. Startup scripts are batch files of instructions that run before the user is invited to log on. By default, the system does not display the instructions in the startup ...

CCE-99829-4
Sets the NetBIOS node type. When WINS servers are used, the default is hybrid (h), otherwise broadcast (b).This policy settings allows you to manage the computer's NetBIOS node type. The selected NetBIOS node type determines what methods NetBT will use to register and resolve names. If you enable t ...

CCE-93748-2
Network Connections Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.

CCE-99709-8
This subcategory reports other logon/logoff-related events, such as Terminal Services session disconnects and reconnects, using RunAs to run processes under a different account, and locking and unlocking a workstation. Events for this subcategory include: ? 4649: A replay attack was detected. ? 4778 ...

CCE-93130-3
Application Identity Determines and verifies the identity of an application. Disabling this service will prevent AppLocker from being enforced.

CCE-99664-5
This subcategory reports when a user account or service uses a sensitive privilege. A sensitive privilege includes the following user rights: Act as part of the operating system, Back up files and directories, Create a token object, Debug programs, Enable computer and user accounts to be trusted for ...

CCE-94153-4
Windows Audio Endpoint Builder Manages audio devices for the Windows Audio service. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start

CCE-93526-2
Turn on scan after signature update This policy setting allows you to configure the automatic scan which starts after a definition update has occurred. If you enable or do not configure this setting, a scan will start following a definition update. If you disable this setting, a scan will not ...

CCE-93713-6
Hyper-V Guest Shutdown Service Provides a mechanism to shut down the operating system of this virtual machine from the management interfaces on the physical computer.

CCE-93504-9
Allow Enhanced Storage certificate provisioning This policy setting configures whether or not users can provision certificates on Enhanced Storage certificate silo devices. If you enable this policy setting, users can provision certificates on Enhanced Storage certificate silo devices. If you dis ...

CCE-99807-0
This policy prevents the user from showing account details (email address or user name) on the sign-in screen. If you enable this policy setting, the user cannot choose to show account details on the sign-in screen. If you disable or do not configure this policy setting, the user may choose to sho ...

CCE-93152-7
Web Management Service Enables remote and delegated management capabilities for administrators to manage the Web server, sites, and applications present on this machine.

CCE-93308-5
User Access Logging Service This service logs unique client access requests in the form of IP addresses and user names of installed products and roles on the local server. This information can be queried via Powershell by administrators needing to quantify client demand of server software for offli ...

CCE-93285-5
Allow only USB root hub connected Enhanced Storage devices This policy setting configures whether or not only USB root hub connected Enhanced Storage devices are allowed. Allowing only root hub connected Enhanced Storage devices minimizes the risk of an unauthorized USB device reading data on an En ...

CCE-93833-2
Disallow selection of Custom Locales This policy prevents a user from selecting a supplemental custom locale as their user locale. The user is restricted to the set of locales that shipped with the operating system. Note that this does not affect the selection of replacement locales. To prevent th ...

CCE-93602-1
SSDP Discovery Discovers networked devices and services that use the SSDP discovery protocol, such as UPnP devices. Also announces SSDP devices and services running on the local computer. If this service is stopped, SSDP-based devices will not be discovered. If this service is disabled, any service ...

CCE-93089-1
Allow antimalware service to remain running always This policy setting allows you to configure whether or not the antimalware service remains running when antivirus and antispyware definitions are disabled. It is recommended that this setting remain disabled. If you enable this setting, the anti ...

CCE-93868-8
Scan removable drives This policy setting allows you to manage whether or not to scan for malicious software and unwanted software in the contents of removable drives, such as USB flash drives, when running a full scan. If you enable this setting, removable drives will be scanned during any type ...

CCE-93406-7
Windows Management Instrumentation Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services ...

CCE-94095-7
Peer Name Resolution Protocol Enables Serverless Peer Name Resolution over the Internet. If disabled some Peer to Peer and Collaborative applications such as Windows Meetings may not work.

CCE-94203-7
User Account Control: Only elevate executables that are signed and validated This policy setting enforces public key infrastructure (PKI) signature checks for any interactive applications that request elevation of privilege. Enterprise administrators can control which applications are allowed to ru ...

CCE-93441-4
Turn on definition retirement This policy setting allows you to configure definition retirement for network protection against exploits of known vulnerabilities. Definition retirement checks to see if a computer has the required security updates necessary to protect it against a particular vulnerab ...

CCE-99740-3
The registry value entry ScreenSaverGracePeriod was added to the template file in the HKEY_LOCAL_MACHINE\SYSTEM\Software\Microsoft\ Windows NT\CurrentVersion\Winlogon\ registry key. The entry appears as MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 ...

CCE-93596-5
Microsoft iSCSI Initiator Service Manages Internet SCSI (iSCSI) sessions from this computer to remote iSCSI target devices. If this service is stopped, this computer will not be able to login or access iSCSI targets. If this service is disabled, any services that explicitly depend on it will fail t ...

CCE-94105-4
Devices: Prevent users from installing printer drivers It is feasible for a attacker to disguise a Trojan horse program as a printer driver. The program may appear to users as if they must use it to print, but such a program could unleash malicious code on your computer network. To reduce the possi ...

CCE-93498-4
Configure local setting override for turn on behavior monitoring This policy setting configures a local override for the configuration of behavior monitoring. This setting can only be set by Group Policy. If you enable this setting, the local preference setting will take priority over Group Policy ...

CCE-93223-6
WinHTTP Web Proxy Auto-Discovery Service WinHTTP implements the client HTTP stack and provides developers with a Win32 API and COM Automation component for sending HTTP requests and receiving responses. In addition, WinHTTP provides support for auto-discovering a proxy configuration via its impleme ...

CCE-94007-2
CD and DVD: Deny write access This policy setting denies write access to the CD and DVD removable storage class. If you enable this policy setting, write access will be denied to this removable storage class. If you disable or do not configure this policy setting, write access will be allowed to ...

CCE-94193-0
Netlogon Maintains a secure channel between this computer and the domain controller for authenticating users and services. If this service is stopped, the computer may not authenticate users and services and the domain controller cannot register DNS records. If this service is disabled, any service ...

CCE-99797-3
This policy setting allows you to restrict remote RPC connections to SAM. The recommended state for this setting is: Administrators: Remote Access: Allow . Note: A Windows 10 R1607, Server 2016 or newer OS is required to access and set this value in Group Policy. Note 2: If your organiza ...

CCE-93125-3
Interactive logon: Number of previous logons to cache (in case domain controller is not available) This policy setting determines whether a user can log on to a Windows domain using cached account information. Logon information for domain accounts can be cached locally to allow users to log on even ...

CCE-94060-1
Windows System Resource Manager Assigns computer resources to multiple applications running on Windows Server. If this service is stopped or disabled no management will occur, no accounting data will be collected, and the administrator will not be able to use command-line controls to administer WSR ...

CCE-93672-4
Software Protection Enables the download, installation and enforcement of digital licenses for Windows and Windows applications. If the service is disabled, the operating system and licensed applications may run in a reduced function mode.

CCE-93922-3
Scan all downloaded files and attachments This policy setting allows you to configure scanning for all downloaded files and attachments. If you enable or do not configure this setting, scanning for all downloaded files and attachments will be enabled. If you disable this setting, scanning for ...

CCE-93210-3
Log directory pruning retry events Specifies whether or not to log events when the pruning service on a domain controller attempts to contact a computer before pruning the computer's printers. The pruning service periodically contacts computers that have published printers to verify that the print ...

CCE-93859-7
Turn off Real-Time Monitoring Turns off Real-Time Protection prompts for known malware detection. Windows Defender alerts you when spyware or potentially unwanted software attempts to install itself or to run on your computer. If you enable this policy setting, Windows Defender will not prompt us ...

CCE-93574-2
Recovery console: Allow automatic administrative logon The recovery console is a command-line environment that is used to recover from system problems. If you enable this policy setting, the administrator account is automatically logged on to the recovery console when it is invoked during startup.

CCE-93726-8
ASP .NET State Service ASP.NET State Service provides support for out-of-process session states for Microsoft ASP.NET, a unified Web development platform. ASP.NET has a concept of session state ? a listing of values associated with the client session is accessible from ASP.NET pages through the Ses ...

CCE-93476-0
Do not use Remote Desktop Session Host server IP address when virtual IP address is not available This policy setting specifies whether a session uses the IP address of the Remote Desktop Session Host server if a virtual IP address is not available. If you enable this policy setting, the IP addres ...

CCE-93378-8
Always send compound authentication first This policy setting controls whether a device always sends a compound authentication request when the resource domain requests compound identity. Note: For a domain controller to request compound authentication, the policies 'KDC support for claims, compou ...

CCE-93049-5
Randomize scheduled task times If you enable or do not configure this setting, scheduled tasks will begin at a random time within an interval of 30 minutes before and after the specified start time. If you disable this setting, scheduled tasks will begin at the specified start time.

CCE-99775-9
Determines when registry policies are updated. This setting affects all policies in the Administrative Templates folder and any other policies that store values in the registry. It overrides customized settings that the program implementing a registry policy set when it was installed. If you enab ...

CCE-94118-7
Windows Deployment Services server Manages requests made by Pre-Boot eXecution Environment (PXE) ? enabled client computers. If this service is stopped, PXE-enabled client computers will be unable to install Windows remotely or use other Windows Deployment Services-based tools.

CCE-93628-6
Display highly detailed status messages This policy setting directs the system to display highly detailed status messages. This policy setting is designed for advanced users who require this information. If you enable this policy setting, the system displays status messages that reflect each ...

CCE-93134-5
Do not allow COM port redirection Specifies whether to prevent the redirection of data to client COM ports from the remote computer in a Remote Desktop Services session. You can use this setting to prevent users from redirecting data to COM port peripherals or mapping local COM ports while they ar ...

CCE-93913-2
Scan archive files This policy setting allows you to configure scans for malicious software and unwanted software in archive files such as .ZIP or .CAB files. If you enable or do not configure this setting, archive files will be scanned. If you disable this setting, archive files will not be ...

CCE-93681-5
Do not delete temp folder upon exit Specifies whether Remote Desktop Services retains a user's per-session temporary folders at logoff. You can use this setting to maintain a user's session-specific temporary folders on a remote computer, even if the user logs off from a session. By default, Remot ...

CCE-93169-1
Ignore custom consent settings This setting determines the behavior of the default consent setting in relation to custom consent settings. If this setting is enabled, the default Consent level setting will always override any other consent setting. If this setting is disabled or not configured, ea ...

CCE-93770-6
Devices: Allow undock without having to log on This policy setting determines whether a portable computer can be undocked if the user does not log on to the system. Enable this policy setting to eliminate a Logon requirement and allow use of an external hardware eject button to undock the computer. ...

CCE-99753-6
This subcategory reports each event of application group management on a computer, such as when an application group is created, changed, or deleted or when a member is added to or removed from an application group. If you enable this Audit policy setting, administrators can track events to detect m ...

CCE-93583-3
Add the Administrators security group to roaming user profiles This setting adds the Administrator security group to the roaming user profile share. Once an administrator has configured a users' roaming profile, the profile will be created at the user's next login. The profile is created at the lo ...

CCE-93463-8
Run Windows PowerShell scripts first at user logon, logoff This policy setting determines whether Windows PowerShell scripts will run before non-PowerShell scripts during user logon and logoff. By default, PowerShell scripts run after non-PowerShell scripts. If you enable this policy setting, wi ...

CCE-93717-7
Windows Installer Adds, modifies, and removes applications provided as a Windows Installer (*.msi) package. If this service is disabled, any services that explicitly depend on it will fail to start.

CCE-93254-1
Audit: Audit the access of global system objects This policy setting creates a default system access control list (SACL) for system objects such as mutexes (mutual exclusive), events, semaphores, and MS-DOS devices, and causes access to these system objects to be audited. If the Audit: Audit the ac ...

CCE-94184-9
DNS Client The DNS Client service (dnscache) caches Domain Name System (DNS) names and registers the full computer name for this computer. If the service is stopped, DNS names will continue to be resolved. However, the results of DNS name queries will not be cached and the computer's name will not ...

CCE-93365-5
Turn off Local Group Policy objects processing This policy setting prevents Local Group Policy objects (Local GPOs) from being applied. By default, the policy settings in Local GPOs are applied before any domain-based GPO policy settings. These policy settings can apply to both users and the local ...

CCE-94109-6
Do not display Initial Configuration Tasks window automatically at logon This policy setting allows you to turn off the automatic display of the Initial Configuration Tasks window at logon. If you enable this policy setting, the Initial Configuration Tasks window is not displayed when an administ ...

CCE-93890-2
Turn off Windows Update device driver searching This policy setting specifies whether Windows will search Windows Update for device drivers when no local drivers for a device are present. Note See also Turn off Windows Update device driver search prompt in Administrative Templates/System, which ...

CCE-93606-2
Application Experience Processes application compatibility cache requests for applications as they are launched

CCE-94086-6
Network Location Awareness Collects and stores configuration information for the network and notifies programs when this information is modified. If this service is stopped, configuration information might be unavailable. If this service is disabled, any services that explicitly depend on it will f ...

CCE-94207-8
Thread Ordering Server Provides ordered execution for a group of threads within a specific period of time.

CCE-99731-2
The registry value entry TCPMaxDataRetransmissions for IPv6 was added to the template file in the HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip6 \Parameters\ registry key. The entry appears as MSS: (TcpMaxDataRetransmissions) IPv6 How many times unacknowledged data is retransmitted (3 r ...

CCE-93561-9
Allow Print Spooler to accept client connections This policy controls whether the print spooler will accept client connections. When the policy is unconfigured, the spooler will not accept client connections until a user shares out a local printer or opens the print queue on a printer connection, ...

CCE-93792-0
Turn off picture password sign-in This policy setting allows you to control whether a domain user can sign in using a picture password. If you enable this policy setting, a domain user can't set up or sign in with a picture password. If you disable or don't configure this policy setting, a d ...

CCE-93170-9
Turn off Internet download for Web publishing and online ordering wizards This policy setting controls whether Windows will download a list of providers for the Web publishing and online ordering wizards.

CCE-93215-2
Software Licensing Software Licensing service.

CCE-93784-7
Use Remote Desktop Easy Print printer driver first This policy setting allows you to specify whether the Remote Desktop Easy Print printer driver is used first to install all client printers. If you enable or do not configure this policy setting, the RD Session Host server first tries to use the ...

CCE-99755-1
Specifies whether to require the use of a specific encryption level to secure communications between client computers and RD Session Host servers during Remote Desktop Protocol (RDP) connections. This policy only applies when you are using native RDP encryption. However, native RDP encryption (as op ...

CCE-94159-1
Remote Registry Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start.

CCE-99853-4
Determines whether users that are not Administrators can install print drivers on this computer. By default, users that are not Administrators can not install print drivers on this computer. If you enable this setting or do not configure it, the system will limit installation of print drivers to A ...

CCE-93237-6
Do not allow client printer redirection This policy setting allows you to specify whether to prevent the mapping of client printers in Remote Desktop Services sessions. You can use this policy setting to prevent users from redirecting print jobs from the remote computer to a printer attached to th ...

CCE-93094-1
Use advanced RemoteFX graphics for RemoteApp This policy setting allows you to enable RemoteApp programs to use advanced graphics, including support for transparency, live thumbnails, and seamless application moves. This policy setting applies only to RemoteApp programs and does not apply to remote ...

CCE-94039-5
Recovery console: Allow floppy copy and access to all drives and all folders This policy setting makes the Recovery Console SET command available, which allows you to set the following recovery console environment variables: - AllowWildCards. Enables wildcard support for some commands (such as the ...

CCE-93290-5
User Account Control: Only elevate UIAccess applications that are installed in secure locations This policy setting controls whether applications that request to run with a User Interface Accessibility (UIAccess) integrity level must reside in a secure location in the file system. Secure locations ...

CCE-93139-4
Base Filtering Engine The Base Filtering Engine (BFE) is a service that manages firewall and Internet Protocol security (IPsec) policies and implements user mode filtering. Stopping or disabling the BFE service will significantly reduce the security of the system. It will also result in unpredictab ...

CCE-94092-4
Offline Files The Offline Files service performs maintenance activities on the Offline Files cache, responds to user logon and logoff events, implements the internals of the public API, and dispatches interesting events to those interested in Offline Files activities and changes in cache state.

CCE-94190-6
End session when time limits are reached This policy setting Sspecifies whether to end a Remote Desktop Services session that has timed out instead of disconnecting it. You can use this setting to direct Remote Desktop Services to end a session (that is, the user is logged off and the session is ...

CCE-93642-7
Turn Off Solid State Mode Turns off the solid state mode for the hybrid hard disks. If you enable this policy setting, frequently written files such as the file system metadata and registry may not be stored in the NV cache. If you disable this policy setting, the system will store frequently wr ...

CCE-99733-8
This subcategory reports other account management events. Events for this subcategory include: ? 4782: The password hash an account was accessed. ? 4793: The Password Policy Checking API was called. Refer to the Microsoft Knowledgebase article ?Description of security events in Windows Vista and in ...

CCE-93544-5
Check for the latest virus and spyware definitions on startup This policy setting allows you to manage whether a check for new virus and spyware definitions will occur immediately after service startup. If you enable this setting, a check for new definitions will occur after service startup. ...

CCE-94137-7
Network Policy Server Manages authentication, authorization, auditing, and accounting for virtual private network (VPN), dial-up, 802.1x wireless or Ethernet switch connection attempts sent by access servers that are compatible with the IETF RADIUS protocol. If this service is stopped, users might ...

CCE-93673-2
LAN Manager (LM) is a family of early Microsoft client/server software that allows users to link personal computers together on a single network. Network capabilities include transparent file and print sharing, user security features, and network administration tools. In Active Directory domains, th ...

CCE-93993-4
Turn off the Windows Messenger Customer Experience Improvement Program This policy setting specifies whether Windows Messenger can collect anonymous information about how the Windows Messenger software and service is used.

CCE-93740-9
Interactive logon: Message title for users attempting to log on Microsoft recommends that you use this setting, if appropriate to your environment and your organization's business requirements, to help protect end user computers. This policy setting allows text to be specified in the title bar of t ...

CCE-93477-8
CD and DVD: Deny execute access This policy setting denies execute access to the CD and DVD removable storage class. If you enable this policy setting, execute access will be denied to this removable storage class. If you disable or do not configure this policy setting, execute access will be all ...

CCE-94213-6
UPnP Device Host Allows UPnP devices to be hosted on this computer. If this service is stopped, any hosted UPnP devices will stop functioning and no additional hosted devices can be added. If this service is disabled, any services that explicitly depend on it will fail to start.

CCE-93202-0
Turn off Search Companion content file updates This policy setting specifies whether Search Companion should automatically download content updates during local and Internet searches.

CCE-93797-9
Prevent redirection of USB devices This policy setting prevents redirection of USB devices. If you enable this setting, an alternate driver for USB devices cannot be loaded. If you disable or do not configure this setting, an alternate driver for USB devices can be loaded.

CCE-94115-3
Turn off Internet Connection Wizard if URL connection is referring to Microsoft.com Specifies whether the Internet Connection Wizard can connect to Microsoft to download a list of Internet Service Providers (ISPs). If you enable this setting, the 'Choose a list of Internet Service Providers' path ...

CCE-99711-4
The registry value entry SafeDllSearchMode was added to the template file in the HKEY_LOCAL_MACHINE\ SYSTEM\CurrentControlSet\Control\Session Manager\ registry key. The entry appears as MSS: (SafeDllSearchMode) Enable Safe DLL search mode (recommended) in the SCE. The DLL search order can be config ...

CCE-93651-8
Domain controller: Refuse machine account password changes This security setting determines whether domain controllers will refuse requests from member computers to change computer account passwords. By default, member computers change their computer account passwords every 30 days. If enabled, the ...

CCE-93762-3
Enumerate local users on domain-joined computers This policy setting allows local users to be enumerated on domain-joined computers. If you enable this policy setting, Logon UI will enumerate all local users on domain-joined computers. If you disable or do not configure this policy setting, ...

CCE-93224-4
Diagnostic System Host The Diagnostic System Host service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, some diagnostics will no longer function. If this service is disabled, any services that explicitly depend on it will fail to star ...

CCE-93709-4
Turn off handwriting recognition error reporting Turns off the handwriting recognition error reporting tool. The handwriting recognition error reporting tool enables users to report errors encountered in Tablet PC Input Panel. The tool generates error reports and transmits them to Microsoft over a ...

CCE-93686-4
Turn off Internet File Association service Specifies whether to use the Microsoft Web service for finding an application to open a file with an unhandled file association. When a user opens a file that has an extension that is not associated with any applications on the machine, the user is given ...

CCE-93588-2
Execute print drivers in isolated processes This policy setting determines whether the print spooler will execute print drivers in an isolated or separate process. When print drivers are loaded in an isolated process (or isolated processes), a print driver failure will not cause the print spooler s ...

CCE-93807-6
Application Information Facilitates the running of interactive applications with additional administrative privileges. If this service is stopped, users will be unable to launch applications with the additional administrative privileges they may require to perform desired user tasks.

CCE-93126-1
World Wide Web Publishing Service Provides Web connectivity and administration through the Internet Information Services Manager.

CCE-93174-1
Turn off automatic termination of applications that block or cancel shutdown This policy setting specifies whether Windows will allow console applications and GUI applications without visible top-level windows to block or cancel shutdown. By default, such applications are automatically terminated i ...

CCE-93272-3
PNRP Machine Name Publication Service This service publishes a machine name using the Peer Name Resolution Protocol. Configuration is managed via the netsh context 'p2p pnrp peer'.

CCE-94057-7
Windows Time Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.

CCE-94120-3
Multimedia Class Scheduler Enables relative prioritization of work based on system-wide task priorities. This is intended mainly for multimedia applications. If this service is stopped, individual tasks resort to their default priority.

CCE-93437-2
Configure local setting override for reporting to Microsoft MAPS This policy setting configures a local override for the configuration to join Microsoft MAPS. This setting can only be set by Group Policy. If you enable this setting, the local preference setting will take priority over Group Policy ...

CCE-93851-4
Turn off the 'Publish to Web' task for files and folders This policy setting specifies whether the tasks Publish this file to the Web, Publish this folder to the Web, and Publish the selected items to the Web are available from File and Folder Tasks in Windows folders.

CCE-93339-0
Allow local activation security check exemptions Allows you to specify that local computer administrators can supplement the 'Define Activation Security Check exemptions' list. If you enable this policy setting, and DCOM does not find an explicit entry for a DCOM server application id (appid) in t ...

CCE-93490-1
Microsoft iSNS Server Maintains a database of iSNS client registrations and notifies clients when changes are made to the database.

CCE-93984-3
Allow asynchronous user Group Policy processing when logging on through Remote Desktop Services This policy setting allows Microsoft Windows to process user Group Policy settings asynchronously when logging on through Remote Desktop Services. Asynchronous user Group Policy processing is the default ...

CCE-93392-9
Turn off printing over HTTP This policy setting allows you to disable the client computer?s ability to print over HTTP, which allows the computer to print to printers on the intranet as well as the Internet.

CCE-93753-2
Server Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.

CCE-99835-1
This subcategory reports when a user account or service uses a non-sensitive privilege. A non-sensitive privilege includes the following user rights: Access Credential Manager as a trusted caller, Access this computer from the network, Add workstations to domain, Adjust memory quotas for a process, ...

CCE-93775-5
Printer Extensions and Notifications This service opens custom printer dialog boxes and handles notifications from a remote print server or a printer. If you turn off this service you won?t be able to see printer extensions or notifications.

CCE-93677-3
Do not allow LPT port redirection Specifies whether to prevent the redirection of data to client LPT ports during a Remote Desktop Services session. You can use this setting to prevent users from mapping local LPT ports and redirecting data from the remote computer to local LPT port peripherals. B ...

CCE-93424-0
Turn off Registration if URL connection is referring to Microsoft.com Specifies whether the Windows Registration Wizard connects to Microsoft.com for online registration. If you enable this setting, it blocks users from connecting to Microsoft.com for online registration and users cannot register ...

CCE-94168-2
Do not allow Windows to activate Enhanced Storage devices This policy setting configures whether or not Windows will activate an Enhanced Storage device. If you enable this policy setting, Windows will not activate unactivated Enhanced Storage devices. If you disable or do not configure this ...

CCE-93161-8
Always render print jobs on the server When printing through a print server, determines whether the print spooler on the client will process print jobs itself, or pass them on to the server to do the work. This policy setting only effects printing to a Windows print server. If you enable this pol ...

CCE-93899-3
Allow users to pause scan This policy setting allows you to manage whether or not end users can pause a scan in progress. If you enable or do not configure this setting, a new context menu will be added to the task tray icon to allow the user to pause a scan. If you disable this setting, user ...

CCE-93522-1
Do not allow local administrators to customize permissions Specifies whether to disable the administrator rights to customize security permissions in the Remote Desktop Session Host Configuration tool. You can use this setting to prevent administrators from making changes to the user groups on the ...

CCE-94111-2
Turn off Fair Share CPU Scheduling Fair Share CPU Scheduling dynamically distributes processor time across all Remote Desktop Services sessions on the same RD Session Host server, based on the number of sessions and the demand for processor time within each session. If you enable this policy sett ...

CCE-93655-9
Security Accounts Manager The startup of this service signals other services that the Security Accounts Manager (SAM) is ready to accept requests. Disabling this service will prevent other services in the system from being notified when the SAM is ready, which may in turn cause those services to f ...

CCE-99715-5
The registry value entry KeepAliveTime was added to the template file in the HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\ registry key. The entry appears as MSS: (KeepAliveTime) How often keep-alive packets are sent in milliseconds (300,000 is recommended) in the SCE. This ...

CCE-93864-7
Do not allow non-Enhanced Storage removable devices This policy setting configures whether or not non-Enhanced Storage removable devices are allowed on your computer. If you enable this policy setting, non-Enhanced Storage removable devices are not allowed on your computer. If you disable or do n ...

CCE-93050-3
Display notifications to clients when they need to perform actions This policy setting allows you to configure whether or not to display notifications to clients when they need to perform the following actions: Run a full scan Download the latest virus and spyware definitions Download Standalon ...

CCE-99781-7
This subcategory reports other object access-related events such as Task Scheduler jobs and COM+ objects. Events for this subcategory include: - 4671: An application attempted to access a blocked ordinal through the TBS. - 4691: Indirect access to an object was requested. - 4698: A sched ...

CCE-93766-4
Remote Desktop Gateway Provides secure remote connectivity to remote computers on your corporate network, from anywhere on the Internet. If this service is stopped, connections to remote computers cannot be made through this Terminal Services Gateway server.

CCE-94146-8
This policy setting controls the behavior of all User Account Control (UAC) policy settings for the computer. If you change this policy setting, you must restart your computer. The options are: - Enabled: (Default) Admin Approval Mode is enabled. This policy must be enabled and related UAC pol ...

CCE-93500-7
Windows Presentation Foundation Font Cache 4.0.0.0 Optimizes performance of Windows Presentation Foundation (WPF) applications by caching commonly used font data. WPF applications will start this service if it is not already running. It can be disabled, though doing so will degrade the performance ...

CCE-93909-0
SL UI Notification Service Provides Software Licensing activation and notification.

CCE-93505-6
Removable Storage The Removable Storage service manages and catalogs removable media and operates automated removable media devices. This service maintains a catalog of information that identifies removable media that are used by your computer, including tapes and CDs. Applications such as Backup a ...

CCE-99804-7
This policy setting determines whether the Windows device is allowed to participate in cross-device experiences (continue experiences). If you enable this policy setting, the Windows device is discoverable by other Windows devices that belong to the same user, and can participate in cross-device ex ...

CCE-93603-9
Smart Card Removal Policy Allows the system to be configured to lock the user desktop upon smart card removal.

CCE-93723-5
TCP/IP NetBIOS Helper Provides support for the NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution for clients on the network, therefore enabling users to share files, print, and log on to the network. If this service is stopped, these functions might be unavailable. If this service is ...

CCE-93011-5
Audit: Shut down system immediately if unable to log security audits This policy setting determines whether the system shuts down if it is unable to log Security events. It is a requirement for Trusted Computer System Evaluation Criteria (TCSEC)-C2 and Common Criteria certification to prevent audit ...

CCE-93309-3
Performance Counter DLL Host Enables remote users and 64-bit processes to query performance counters provided by 32-bit DLLs. If this service is stopped, only local users and 32-bit processes will be able to query performance counters provided by 32-bit DLLs.

CCE-94087-4
Windows Error Reporting Service Allows errors to be reported when programs stop working or responding and allows existing solutions to be delivered. Also allows logs to be generated for diagnostic and repair services. If this service is stopped, error reporting might not work correctly and results ...

CCE-94208-6
IIS Admin Service The IIS Admin Service allows administration of IIS components such as FTP, application pools, Web sites, Web service extensions, and both Network News Transfer Protocol (NNTP) and Simple Mail Transfer Protocol (SMTP) virtual servers. If you stop or disable this service, you will n ...

CCE-93046-1
Download missing COM components Directs the system to search Active Directory for missing Component Object Model (COM) components that a program requires. Many Windows programs, such as the MMC snap-ins, use the interfaces provided by the COM components. These programs cannot perform all of their ...

CCE-93144-4
Windows Firewall Windows Firewall helps protect your computer by preventing unauthorized users from gaining access to your computer through the Internet or a network.

CCE-99719-7
This subcategory reports on violations of integrity of the security subsystem. Events for this subcategory include: ? 4612 : Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits. ? 4615 : Invalid use of LPC port. ? 4618 : A monitored ...

CCE-93340-8
Always prompt for password upon connection This policy setting specifies whether Terminal Services always prompts the client computer for a password upon connection. You can use this policy setting to enforce a password prompt for users who log on to Terminal Services, even if they already provided ...

CCE-94163-3
Online Responder Service Enables identity revocation services for PKI (certificate) based services such as secure e-mail smartcard logon, secure web servers, etc as an online request and response query process. If this service is stopped or disabled, revocation services may not be available for PKI ...

CCE-93593-2
Hyper-V Remote Desktop Virtualization Service Provides a platform for communication between the virtual machine and the operating system running on the physical computer.

CCE-93033-9
System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing This policy setting determines whether the Transport Layer Security/Secure Sockets Layer (TLS/SSL) Security Provider supports only the TLS_RSA_WITH_3DES_EDE_CBC_SHA cipher suite. Although this policy setting inc ...

CCE-93131-1
Function Discovery Resource Publication Publishes this computer and resources attached to this computer so they can be discovered over the network. If this service is stopped, network resources will no longer be published and they will not be discovered by other computers on the network.

CCE-93518-9
Initiate definition update on startup This policy setting allows you to configure definition updates on startup when there is no antimalware engine present. If you enable or do not configure this setting, definition updates will be initiated on startup when there is no antimalware engine present ...

CCE-93976-9
Ignore the local list of blocked TPM commands This policy setting allows you to enforce or ignore the computer's local list of blocked Trusted Platform Module (TPM) commands. If you enable this policy setting, Windows will ignore the computer's local list of blocked TPM commands and will only bloc ...

CCE-93745-8
Network Access Protection Agent Enables Network Access Protection (NAP) functionality on client computers.

CCE-99794-0
This subcategory reports other types of security policy changes such as configuration of the Trusted Platform Module (TPM) or cryptographic providers. Events for this subcategory include: - 4909: The local policy settings for the TBS were changed. - 4910: The group policy settings for the TB ...

CCE-93068-5
Define addresses to bypass proxy server This policy, if defined, will prevent antimalware from using the configured proxy server when communicating with the specified IP addresses. The address value should be entered as a valid URL. If you enable this setting, the proxy server will be bypassed f ...

CCE-94198-9
Turn off handwriting personalization data sharing Turns off data sharing from the handwriting recognition personalization tool. The handwriting recognition personalization tool tool enables Tablet PC users to adapt handwriting recognition to their own writing style by providing writing samples. ...

CCE-93967-8
Suspend user sign-in to complete app registration This policy setting allows you to specify whether the app registration is completed before showing the Start screen to the user. By default, when a new user signs in to a computer, the Start screen is shown and apps are registered in the backgro ...

CCE-94078-3
Remote Procedure Call (RPC) Serves as the endpoint mapper and COM Service Control Manager. If this service is stopped or disabled, programs using COM or Remote Procedure Call (RPC) services will not function properly.

CCE-94141-9
Link-Layer Topology Discovery Mapper Creates a Network Map, consisting of PC and device topology (connectivity) information, and metadata describing each PC and device. If this service is disabled, the Network Map will not function properly.

CCE-93647-6
Run startup scripts asynchronously Lets the system run startup scripts simultaneously. Startup scripts are batch files that run before the user is invited to log on. By default, the system waits for each startup script to complete before it runs the next startup script. If you enable this setting ...

CCE-93153-5
Join RD Connection Broker This policy setting allows you to specify whether the RD Session Host server should join a farm in RD Connection Broker. RD Connection Broker tracks user sessions and allows a user to reconnect to their existing session in a load-balanced RD Session Host server farm. To pa ...

CCE-93910-8
Run full scan on mapped network drives This policy setting allows you to configure scanning mapped network drives. If you enable this setting, mapped network drives will be scanned. If you disable or do not configure this setting, mapped network drives will not be scanned.

CCE-94043-7
Application Layer Gateway Service Provides support for 3rd party protocol plug-ins for Internet Connection Sharing

CCE-93188-1
Turn off Windows Defender Turns off Windows Defender Real-Time Protection, and no more scans are scheduled. If you enable this policy setting, Windows Defender does not run, and computers will not be scanned for spyware or other potentially unwanted software. If you disable or do not configure th ...

CCE-93932-2
Specify the time of day to run a scheduled full scan to complete remediation This policy setting allows you to specify the time of day at which to perform a scheduled full scan in order to complete remediation. The time value is represented as the number of minutes past midnight (00:00). For examp ...

CCE-93286-3
Secondary Logon Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.

CCE-93869-6
Scan packed executables This policy setting allows you to configure scanning for packed executables. It is recommended that this type of scanning remain enabled. If you enable or do not configure this setting, packed executables will be scanned. If you disable this setting, packed executable ...

CCE-93318-4
Turn off Data Execution Prevention for HTML Help Executible This policy setting allows you to exclude HTML Help Executable from being monitored by software-enforced DEP. DEP is designed to block malicious code that takes advantage of exception-handling mechanisms in Windows. If you enab ...

CCE-93371-3
Tape Drives: Deny write access This policy setting denies write access to the Tape Drive removable storage class. If you enable this policy setting, write access will be denied to this removable storage class. If you disable or do not configure this policy setting, write access will be allowed to ...

CCE-93175-8
Ignore the default list of blocked TPM commands This policy setting allows you to enforce or ignore the computer's default list of blocked Trusted Platform Module (TPM) commands. If you enable this policy setting, Windows will ignore the computer's default list of blocked TPM commands and will onl ...

CCE-93482-8
Do not turn off system power after a Windows system shutdown has occurred. This setting allows you to configure whether power is automatically turned off when Windows shutdown completes. This setting does not effect Windows shutdown behavior when shutdown is manually selected using the Start menu ...

CCE-93273-1
Interactive logon: Display user information when the session is locked This policy setting determines whether the account name of the last user to log on to the client computers in your organization can display in each computer's respective Windows logon screen. If you enable this policy setting, i ...

CCE-93384-6
Turn off the advertising ID This policy setting turns off the advertising ID, preventing apps from using the ID for experiences across apps. If you enable this policy setting, the advertising ID is turned off. Apps can't use the ID for experiences across apps. If you disable or do not configu ...

CCE-93856-3
Do not check for user ownership of Roaming Profile Folders This setting disables the more secure default setting for the user?s roaming user profile folder. Once an administrator has configured a users' roaming profile, the profile will be created at the user's next login. The profile is created a ...

CCE-93527-0
Extend Point and Print connection to search Windows Update This policy setting allows you to manage where client computers search for Point and Printer drivers. If you enable this policy setting, the client computer will continue to search for compatible Point and Print drivers from Windows Update ...

CCE-93923-1
Turn on Information Protection Control This policy setting allows you to configure Information Protection Control (IPC). If you enable this setting, IPC will be enabled. If you disable or do not configure this setting, IPC will be disabled.

CCE-93780-5
Health Key and Certificate Management Provides X.509 certificate and key management services for the Network Access Protection Agent (NAPAgent). Enforcement technologies that use X.509 certificates may not function properly without this service

CCE-93366-3
Troubleshooting: Allow users to access and run Troubleshooting Wizards This policy setting allows users to access and run the troubleshooting tools that are available in the Troubleshooting Control Panel and to run the troubleshooting wizard to troubleshoot problems on their computers. If you enab ...

CCE-93607-0
DNS Server Enables DNS clients to resolve DNS names by answering DNS queries and dynamic DNS update requests. If this service is stopped, DNS updates will not occur. If this service is disabled, any services that explicitly depend on it will fail to start.

CCE-99808-8
This policy setting determines whether Clipboard contents can be synchronized across devices. If you enable this policy setting, Clipboard contents are allowed to be synchronized across devices logged in under the same Microsoft account or Azure AD account. If you disable this policy setting, Clipbo ...

CCE-93562-7
Start the scheduled scan only when computer is on but not in use This policy setting allows you to configure scheduled scans to start only when your computer is on but not in use. If you enable or do not configure this setting, scheduled scans will only run when the computer is on but not in use ...

CCE-93695-5
Microsoft iSCSI Software Target Enables this computer to serve as an iSCSI target.

CCE-93233-5
Provide information about previous logons to client computers This policy setting controls whether the domain controller provides information about previous logons to client computers. If you enable this policy setting, the domain controller provides the information message about previous logons. ...

CCE-99741-1
This subcategory reports each event of computer account management, such as when a computer account is created, changed, deleted, renamed, disabled, or enabled. Events for this subcategory include: ? 4741: A computer account was created. ? 4742: A computer account was changed. ? 4743: A computer acc ...

CCE-93090-9
Turn off Configuration Allows you to disable System Restore configuration through System Protection. System Restore enables users, in the event of a problem, to restore their computers to a previous state without losing personal data files. The behavior of this setting depends on the 'Turn off Sys ...

CCE-93037-0
Warning for large Kerberos tickets This policy setting allows you to monitor tickets issued during Kerberos authentication whose size is close to or greater than a configured threshold value. The ticket size warnings are logged in the System log. If you enable this policy setting, you can set th ...

CCE-93749-0
Application Management Processes installation, removal, and enumeration requests for software deployed through Group Policy. If the service is disabled, users will be unable to install, remove, or enumerate software deployed through Group Policy. If this service is disabled, any services that expli ...

CCE-93597-3
MSS: (DisableIPSourceRouting IPv6) IP source routing protection level (protects against packet spoofing) This entry appears as MSS: (DisableIPSourceRouting) IPv6 source routing protection level (protects against packet spoofing) in the SCE. IP source routing is a mechanism that allows the sender to ...

CCE-93499-2
Allow pruning of published printers Determines whether the domain controller can prune (delete from Active Directory) the printers published by this computer. By default, the pruning service on the domain controller prunes printer objects from Active Directory if the computer that published them d ...

CCE-93540-3
Allow notifications to disable definitions based reports to Microsoft MAPS This policy setting allows you to configure the antimalware service to receive notifications to disable individual definitions in response to reports it sends to Microsoft MAPS. Microsoft MAPS uses these notifications to dis ...

CCE-93714-4
Network List Service Identifies the networks to which the computer has connected, collects and stores properties for these networks, and notifies applications when these properties change.

CCE-93255-8
Isolate print drivers from applications Determines if print driver components are isolated from applications instead of normally loading them into applications. Isolating print drivers greatly reduces the risk of a print driver failure causing an application crash. Not all applications support d ...

CCE-93718-5
This policy setting determines whether digital certificates are processed when software restriction policies are enabled and a user or process attempts to run software with an .exe file name extension. It enables or disables certificate rules (a type of software restriction policies rule). With soft ...

CCE-94074-2
AD FS Web Agent Authentication Service The AD FS Web Agent Authentication Service validates incoming authentication requests. Users are either allowed or denied access to web applications based on their security token and the permissions on the application.

CCE-93838-1
Use IP Address Redirection This policy setting allows you to specify the redirection method to use when a client device reconnects to an existing Remote Desktop Services session in a load-balanced RD Session Host server farm. This setting applies to an RD Session Host server that is configured to u ...

CCE-94172-4
Active Directory Certificate Services Creates, manages, and removes X.509 certificates for applications such as S/MIME and SSL. If this service is stopped, certificates will not be created. If this service is disabled, any services that explicitly depend on it will fail to start.

CCE-99776-7
This subcategory reports when a user's account is locked out as a result of too many failed logon attempts. Events for this subcategory include: - 4625: An account failed to log on. Refer to the Microsoft Knowledgebase article 'Description of security events in Windows Vista and in Windows S ...

CCE-93375-4
Removable Disks: Deny execute access This policy setting denies execute access to removable disks. If you enable this policy setting, execute access will be denied to this removable storage class. If you disable or do not configure this policy setting, execute access will be allowed to this remov ...

CCE-93793-8
Send additional data when on battery power This policy setting determines whether Windows Error Reporting (WER) checks if the computer is running on battery power. By default, when a computer is running on battery power, WER only checks for solutions, but does not upload additional report data unti ...

CCE-94052-8
Domain controller: Allow server operators to schedule tasks This policy setting determines whether members of the Server Operators group are allowed to submit jobs by means of the AT schedule facility. The impact of this policy setting configuration should be small for most organizations. Users, in ...

CCE-99678-5
Protecting audit information also includes identifying and protecting the tools used to view and manipulate log data. Therefore, protecting audit tools is necessary to prevent unauthorized operation on audit information. Operating systems providing tools to interface with audit information will lev ...

CCE-93179-0
Windows Process Activation Service The Windows Process Activation Service (WAS) provides process activation, resource management and health management services for message-activated applications.

CCE-93629-4
Remote Access Quarantine Agent Removes validated remote access clients from the quarantine network.

CCE-94150-0
Microsoft network server: Digitally sign communications (always) This policy setting determines if the server side SMB service is required to perform SMB packet signing. Enable this policy setting in a mixed environment to prevent downstream clients from using the workstation as a network server.

CCE-93901-7
Configure local setting override for schedule scan day This policy setting configures a local override for the configuration of scheduled scan day. This setting can only be set by Group Policy. If you enable this setting, the local preference setting will take priority over Group Policy. If you d ...

CCE-93122-0
DCOM Server Process Launcher Provides launch functionality for DCOM services.

CCE-93353-1
Devices: Restrict CD-ROM access to locally logged-on user only This policy setting determines whether a CD-ROM is accessible to both local and remote users simultaneously. If you enable this policy setting, only the interactively logged-on user is allowed to access removable CD-ROM media. When this ...

CCE-93652-6
Resultant Set of Policy Provider Provides a network service that processes requests to simulate application of Group Policy settings for a target user or computer in various situations and computes the Resultant Set of Policy settings.

CCE-93554-4
Configure Watson events This policy setting allows you to configure whether or not Watson events are sent. If you enable or do not configure this setting, Watson events will be sent. If you disable this setting, Watson events will not be sent.

CCE-93291-3
Turn off Resultant Set of Policy logging This setting allows you to enable or disable Resultant Set of Policy (RSoP) logging on a client computer. RSoP logs information on Group Policy settings that have been applied to the client. This information includes details such as which Group Policy objec ...

CCE-93118-8
Apply policy to removable media Extends the disk quota policies in this folder to NTFS file system volumes on removable media. If you disable this setting or do not configure it, the disk quota policies established in this folder apply to fixed-media NTFS volumes only. Note: When this setting is a ...

CCE-94049-4
File Server Storage Reports Manager Provides services for configuration, scheduling, and generation of storage reports.

CCE-99778-3
This subcategory reports when a user attempts to log on to the system. These events occur on the accessed computer. For interactive logons, the generation of these events occurs on the computer that is logged on to. If a network logon takes place to access a share, these events generate on the compu ...

CCE-93589-0
RPC Endpoint Mapper Resolves RPC interfaces identifiers to transport endpoints. If this service is stopped or disabled, programs using Remote Procedure Call (RPC) services will not function properly.

CCE-93719-3
Kerberos Key Distribution Center The Kerberos Key Distribution Center service enables users to log on to the network and be authenticated by the Kerberos version 5 (v5) authentication protocol. As in other implementations of the Kerberos protocol, the Kerberos Key Distribution Center (KDC) is a sin ...

CCE-93630-2
Workstation Creates and maintains client network connections to remote servers using the SMB protocol. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.

CCE-93007-3
COM+ System Application Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.

CCE-93915-7
Block Level Backup Engine Service Engine to perform block level backup and recovery of data. This is a component of the Windows Server Backup feature.

CCE-94027-0
Turn off Help and Support Center Microsoft Knowledge Base search Specifies whether users can perform a Microsoft Knowledge Base search from the Help and Support Center. The Knowledge Base is an online source of technical support information and self-help tools for Microsoft products and is searche ...

CCE-93434-9
Enable RPC Endpoint Mapper Client Authentication This policy setting controls whether RPC clients authenticate with the Endpoint Mapper Service when the call they are making contains authentication information. The Endpoint Mapper Service on computers running Windows NT4 (all service packs) canno ...

CCE-94080-9
Volume Shadow Copy Manages and implements Volume Shadow Copies used for backup and other purposes. If this service is stopped, shadow copies will be unavailable for backup and the backup may fail. If this service is disabled, any services that explicitly depend on it will fail to start.

CCE-99756-9
This policy setting allows you to specify which boot-start drivers are initialized based on a classification determined by an Early Launch Antimalware boot-start driver. The Early Launch Antimalware boot-start driver can return the following classifications for each boot-start driver: - Good: T ...

CCE-93794-6
Turn Off Cache Power Mode Turns off the power save mode on the hybrid hard disks in the system. If you enable this policy, the disks will not be put into NV cache power save mode and no power savings would be achieved. If you disable this policy setting, then the hard disks are put into a NV cach ...

CCE-99712-2
This policy setting allows you to turn on or turn off Offer (Unsolicited) Remote Assistance on this computer. If you enable this policy setting, users on this computer can get help from their corporate technical support staff using Offer (Unsolicited) Remote Assistance. If you disable this policy ...

CCE-93696-3
Distributed Scan Server service Enables scanned documents to be sent from scanners to the scan server and routes them to the correct destinations.

CCE-93763-1
Device Setup Manager Enables the detection, download and installation of device-related software. If this service is disabled devices may be configured with outdated software and may not work correctly.

CCE-94093-2
Message Queuing Triggers The Message Queuing Triggers service provides a rule-based system to monitor messages that arrive in a Message Queuing service queue and, when the conditions of a rule are satisfied, invoke a COM component or a stand-alone executable program to process the message. The Mess ...

CCE-93598-1
Turn off non-volatile cache feature This policy setting turns off all support for the non-volatile (NV) cache on all hybrid hard disks in the system. To check if you have hybrid hard disks in the system, from Device Manager, right-click the disk drive and select Properties. The NV cache can be used ...

CCE-93180-8
Special Administration Console Helper Allows administrators to remotely access a command prompt using Emergency Management Services.

CCE-94191-4
Plug and Play Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.

CCE-94005-6
WDigest Authentication (disabling may require KB2871997) When WDigest authentication is enabled, Lsass.exe retains a copy of the user's plaintext password in memory, where it can be at risk of theft. Microsoft recommends disabling WDigest authentication unless it is needed. If this setting is no ...

CCE-93906-6
Configure local setting override for the scan type to use for a scheduled scan This policy setting configures a local override for the configuration of the scan type to use during a scheduled scan. This setting can only be set by Group Policy. If you enable this setting, the local preference sett ...

CCE-94138-5
Function Discovery Provider Host Host process for Function Discovery providers.

CCE-99734-6
This subcategory reports each event of user account management, such as when a user account is created, changed, or deleted; a user account is renamed, disabled, or enabled; or a password is set or changed. If you enable this Audit policy setting, administrators can track events to detect malicious, ...

CCE-93674-0
Do not allow smart card device redirection This policy setting allows you to control the redirection of smart card devices in a Remote Desktop Services session. If you enable this policy setting, Remote Desktop Services users cannot use a smart card to log on to a Remote Desktop Services session. ...

CCE-93114-7
CD and DVD: Deny read access This policy setting denies read access to the CD and DVD removable storage class. If you enable this policy setting, read access will be denied to this removable storage class. If you disable or do not configure this policy setting, read access will be allowed to this ...

CCE-99845-0
Local Administrator Password Solution (LAPS) tool is free and supported software that allows an organization to automatically set randomized and unique local Administrator account passwords on domain-attached workstations and member servers. The passwords are stored in a confidential attribute of th ...

CCE-99747-8
This subcategory reports changes in security state of the system, such as when the security subsystem starts and stops. Events for this subcategory include: ? 4608: Windows is starting up. ? 4609: Windows is shutting down. ? 4616: The system time was changed. ? 4621: Administrator recovered system f ...

CCE-93247-5
Configure Scenario Execution Level If you enable this policy setting, the Diagnostic Policy Service (DPS) will detect, troubleshoot and attempt to resolve automatically any heap corruption problems. If you disable this policy setting, Windows will not be able to detect, troubleshoot and attempt to ...

CCE-93478-6
Troubleshooting: Allow users to access online troubleshooting content on Microsoft servers from the Troubleshooting Control Panel (via the Windows Online Troubleshooting Service - WOTS) This policy setting allows users who are connected to the Internet to access and search troubleshooting content t ...

CCE-94116-1
Simple TCP/IP Services Simple TCP/IP Services implements support for the Echo, Discard, Character Generator, Daytime, and Quote of the Day protocols. Echo (port 7, RFC 862) This protocol echoes back data from any messages it receives on this server port. Echo can be useful as a network debugging an ...

CCE-93750-8
Distributed Link Tracking Client Maintains links between NTFS files within a computer or across computers in a network.

CCE-93197-2
Always use custom logon background Ignores Windows Logon Background. If you enable this policy setting, the logon screen will always attempt to load a custom background instead of the Windows-branded logon background. If you disable or do not configure this policy setting, Windows will use the ...

CCE-93656-7
Spot Verifier Verifies potential file system corruptions.

CCE-93295-4
Audit: Audit the use of Backup and Restore privilege This policy setting determines whether to audit the use of all user privileges, including Backup and Restore, when the Audit privilege use setting is in effect. If you enable both policies, an audit event will be generated for every file that is ...

CCE-94143-5
Smart Card Manages access to smart cards read by this computer. If this service is stopped, this computer will be unable to read smart cards. If this service is disabled, any services that explicitly depend on it will fail to start.

CCE-99725-4
This policy setting specifies whether users can participate in the Help Experience Improvement program. The Help Experience Improvement program collects information about how customers use Windows Help so that Microsoft can improve it. If you enable this policy setting, users cannot participate in ...

CCE-93972-8
Tape Drives: Deny execute access This policy setting denies execute access to the Tape Drive removable storage class. If you enable this policy setting, execute access will be denied to this removable storage class. If you disable or do not configure this policy setting, execute access will be al ...

CCE-93042-0
Turn on session logging This policy setting allows you to turn logging on or off. Log files are located in the user's Documents folder under Remote Assistance. If you enable this policy setting, log files will be generated. If you disable this policy setting, log files will not be generated. If ...

CCE-94178-1
Wired AutoConfig This service performs IEEE 802.1X authentication on Ethernet interfaces.

CCE-93776-3
Shell Hardware Detection Provides notifications for AutoPlay hardware events.

CCE-93634-4
File Replication Allows files to be automatically copied and maintained simultaneously on multiple servers. If this service is stopped, file replication will not occur and servers will not synchronize. If this service is disabled, any services that explicitly depend on it will fail to start. This s ...

CCE-94121-1
Optimize drives Helps the computer run more efficiently by optimizing files on storage drives.

CCE-93416-6
Log event when quota limit is exceeded This policy setting determines whether the system records an event in the local Application log when users reach their disk quota limit on a volume, and prevents users from changing the logging setting. If you enable this policy setting, the system records ...

CCE-99801-3
Encryption Oracle Remediation This policy setting applies to applications using the CredSSP component (for example: Remote Desktop Connection). Some versions of the CredSSP protocol are vulnerable to an encryption oracle attack against the client. This policy controls compatibility with vulnerable ...

CCE-93741-7
MSS: (AutoShareServer) Enable Administrative Shares (recommended except for highly secure environments) This entry appears as MSS: (AutoShareServer) Enable Administrative Shares (not recommended except for highly secure environments) in the SCE. For additional information, see the Microsoft Knowle ...

CCE-93260-8
COM+ Event System Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is ...

CCE-93491-9
null

CCE-93393-7
Lsass.exe audit mode You can configure this setting to enable the auditing of Lsass.exe so that you can evaluate feasibility of enabling LSA protection. You can use the audit mode to identify LSA plug-ins and drivers that will fail to load in LSA Protection mode. While in the audit mode, the syste ...

CCE-93798-7
Do not enumerate connected users on domain-joined computers This policy setting prevents connected users from being enumerated on domain-joined computers. If you enable this policy setting, the Logon UI will not enumerate any connected users on domain-joined computers. If you disable or do n ...

CCE-94156-7
MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning The registry value entry WarningLevel was added to the template file in the HKEY_LOCAL_MACHINE\ SYSTEM\CurrentControlSet\Services\Eventlog\Security\ registry key. The entry appears as MSS ...

CCE-99680-1
Unnecessary services increase the attack surface of a system. Some of these services may not support required levels of authentication or encryption. Fix: Uninstall the "FTP Server" role. Start "Server Manager". Select the server with the role. Scroll down to "ROLES AND ...

CCE-93510-6
Configure local setting override to turn off Intrusion Prevention System This policy setting configures a local override for the configuration of network protection against exploits of known vulnerabilities. This setting can only be set by Group Policy. If you enable this setting, the local prefer ...

CCE-93643-5
Download roaming profiles on primary computers only This policy setting controls on a per-computer basis whether roaming profiles are downloaded on a user's primary computers only. This policy setting is useful to improve logon performance and to increase security for user data on computers where t ...

CCE-99836-9
This policy setting allows you to audit attempts to access files and folders on a shared folder. The Detailed File Share setting logs an event every time a file or folder is accessed, whereas the File Share setting only records one event for any connection established between a client and file share ...

CCE-99791-6
This subcategory reports when a file share is accessed. By itself, this policy setting will not cause auditing of any events. It determines whether to audit the event of a user who accesses a file share object that has a specified system access control list (SACL), effectively enabling auditing to t ...

CCE-94134-4
Windows Audio Manages audio for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start

CCE-93184-0
Extensible Authentication Protocol The Extensible Authentication Protocol (EAP) service provides network authentication in such scenarios as 802.1x wired and wireless, VPN, and Network Access Protection (NAP). EAP also provides application programming interfaces (APIs) that are used by network acc ...

CCE-93425-7
Server for NFS Enables a Windows based computer to act as an NFS Server.

CCE-93678-1
Prevent display of the user interface for critical errors This policy setting prevents the display of the user interface for critical errors. If you enable this policy setting, Windows Error Reporting prevents the display of the user interface for critical errors. If you disable or do not configu ...

CCE-93327-5
Disallow user override of locale settings This policy prevents the user from customizing their locale by changing their user overrides. Any existing overrides in place when this policy is enabled will be frozen. To remove existing user overrides, first reset the user(s) values to the defaults and ...

CCE-94210-2
KDC Proxy Server service (KPS) KDC Proxy Server service runs on edge servers to proxy Kerberos protocol messages to domain controllers on the corporate network.

CCE-93887-8
Apply UAC restrictions to local accounts on network logons This setting controls whether local accounts can be used for remote administration via network logon (e.g., NET USE, connecting to C$, etc.). Local accounts are at high risk for credential theft when the same account and password is configu ...

CCE-94053-6
Local Session Manager Core Windows Service that manages local user sessions. Stopping or disabling this service will result in system instability.

CCE-93483-6
Simple Mail Transport Protocol (SMTP) The Simple Mail Transfer Protocol (SMTP) service is an e-mail submission and relay agent. It can accept and queue e-mail messages for remote destinations and establish connections to other computers at specified intervals. Windows-based domain controllers use t ...

CCE-99782-5
This subcategory reports changes in authorization policy including permissions (DACL) changes. Events for this subcategory include: - 4704: A user right was assigned. - 4705: A user right was removed. - 4706: A new trust was created to a domain. - 4707: A trust to a domain was remove ...

CCE-99729-6
This subcategory reports the results of validation tests on credentials submitted for a user account logon request. These events occur on the computer that is authoritative for the credentials. For domain accounts, the domain controller is authoritative, whereas for local accounts, the local compute ...

CCE-93746-6
Windows notices inactivity of a logon session, and if the amount of inactive time exceeds the inactivity limit, then the screen saver will run, locking the session. Countermeasure: Configure this policy setting to 900 seconds (15 minutes) so that the risk of a user's desktop session being hijac ...

CCE-99707-2
This subcategory reports each event of distribution group management, such as when a distribution group is created, changed, or deleted or when a member is added to or removed from a distribution group. If you enable this Audit policy setting, administrators can track events to detect malicious, acc ...

CCE-99662-9
Telnet Client is used to connect to remote machine by using the Telnet protocol. Telnet Client allows a computer to connect to a remote Telnet server and run applications on that server. Once logged on, a user is given a command prompt that can be used as if it had been opened locally on the Telnet ...

CCE-99827-8
Configures the SMB v1 client driver's start type. To disable client-side processing of the SMBv1 protocol, select the "Enabled" radio button, then select "Disable driver" from the dropdown. WARNING: DO NOT SELECT THE "DISABLED" RADIO BUTTON UNDER ANY CIRCUMSTANCES! Fo ...

CCE-93626-0
Display instructions in shutdown scripts as they run This policy setting displays the instructions in shutdown scripts as they run. Shutdown scripts are batch files of instructions that run when the user restarts the system or shuts it down. By default, the system does not display the instructio ...

CCE-94151-8
Detect compatibility issues for applications and drivers This policy setting configures the Program Compatibility Assistant (PCA) to diagnose failures with application and driver compatibility. If you enable this policy setting, the PCA is configured to detect failures during application instal ...

CCE-93942-1
Server For NIS Server for NIS (UNIX-RPC)

CCE-93711-0
Windows Update Enables the detection, download, and installation of updates for Windows and other programs. If this service is disabled, users of this computer will not be able to use Windows Update or its automatic updating feature, and programs will not be able to use the Windows Update Agent (WU ...

CCE-93506-4
Configure local setting override to turn on real-time protection This policy setting configures a local override for the configuration to turn on real-time protection. This setting can only be set by Group Policy. If you enable this setting, the local preference setting will take priority over Gro ...

CCE-93252-5
System cryptography: Force strong key protection for user keys stored on the computer This policy setting determines whether users' private keys (such as their S-MIME keys) require a password to be used. If you configure this policy setting so that users must provide a password?distinct from their ...

CCE-99805-4
Support for device authentication using certificate will require connectivity to a DC in the device account domain which supports certificate authentication for computer accounts. This policy setting allows you to set support for Kerberos to attempt authentication using the certificate for the dev ...

CCE-94186-4
Turn off access to the Store This policy setting specifies whether to use the Store service for finding an application to open a file with an unhandled file type or protocol association. When a user opens a file type or protocol that is not associated with any applications on the computer, the u ...

CCE-93363-0
Allow time zone redirection This policy setting determines whether the client computer redirects its time zone settings to the Remote Desktop Services session. If you enable this policy setting, clients that are capable of time zone redirection send their time zone information to the server. The s ...

CCE-94088-2
Hyper-V Networking Management Service Provides Hyper-V Networking WMI management.

CCE-93408-3
Turn off access to all Windows Update features This setting allows you to remove access to Windows Update. If you enable this setting, all Windows Update features are removed. This includes blocking access to the Windows Update Web site at http://windowsupdate.microsoft.com, from the Windows Updat ...

CCE-93733-4
Themes Provides user experience theme management.

CCE-93274-9
Net.Pipe Listener Adapter Receives activation requests over the net.pipe protocol and passes them to WPAS. .net framework 3.0 & Windows Process Activation Service.

CCE-94209-4
Remote Desktop Services Allows users to connect interactively to a remote computer. Remote Desktop and Terminal Server depend on this service. To prevent remote use of this computer, clear the checkboxes on the Remote tab of the System properties control panel item.

CCE-93635-1
Virtual Disk Provides management services for disks, volumes, file systems, and storage arrays.

CCE-93590-8
Active Directory Domain Services AD DS Domain Controller service. If this service is stopped, users will be unable to log on to the network.

CCE-93492-7
Configure local setting override for monitoring for incoming and outgoing file activity This policy setting configures a local override for the configuration of monitoring for incoming and outgoing file activity. This setting can only be set by Group Policy. If you enable this setting, the local p ...

CCE-93613-8
Redirect folders on primary computers only This policy setting controls whether folders are redirected on a user's primary computers only. This policy setting is useful to improve logon performance and to increase security for user data on computers where the user might not want to download private ...

CCE-93920-7
Do not allow drive redirection This policy setting prevents users from sharing the local drives on their client computers to Terminal Servers that they access. Mapped drives appear in the session folder tree in Windows Explorer in the following format: \\TSClient\<driveletter>$ If local drives are ...

CCE-93198-0
Network Security: Allow PKU2U authentication requests to this computer to use online identities Windows 7 and Windows Server 2008 R2 introduce an extension to the Negotiate authentication package, Spnego.dll. In previous versions of Windows, Negotiate decides whether to use Kerberos or NTLM for aut ...

CCE-93296-2
Require strict target SPN match on remote procedure calls When an application attempts to make a remote procedure call (RPC) to this server with a NULL value for the service principal name (SPN), computers running Windows 7 will attempt to use Kerberos by generating an SPN. This policy setting allo ...

CCE-94142-7
Device Association Service Enables pairing between the system and wired or wireless devices.

CCE-93417-4
Print Spooler Loads files to memory for later printing

CCE-93470-3
Prevent Roaming Profile changes from propagating to the server This setting determines if the changes a user makes to their roaming profile are merged with the server copy of their profile. By default, when a roaming profile user logs on to a computer, their roaming profile is copied down to the l ...

CCE-94177-3
Windows Font Cache Service Optimizes performance of applications by caching commonly used font data. Applications will start this service if it is not already running. It can be disabled, though doing so will degrade application performance.

CCE-93319-2
WPD Devices: Deny read access This policy setting denies read access to removable disks, which may include media players, cellular phones, auxiliary displays, and CE devices. If you enable this policy setting, read access will be denied to this removable storage class. If you disable or do not co ...

CCE-93043-8
Configure local setting override for monitoring file and program activity on your computer This policy setting configures a local override for the configuration of monitoring for file and program activity on your computer. This setting can only be set by Group Policy. If you enable this setting, t ...

CCE-93487-7
TCP/IP Print Server The TCP/IP Print Server service enables TCP/IP-based printing by using the Line Printer Daemon protocol. The TCP/IP Print Server service on the print server receives documents from native Line Printer Remote (LPR) utilities running on UNIX computers.

CCE-93848-0
Log event when quota warning level is exceeded This policy setting determines whether the system records an event in the Application log when users reach their disk quota warning level on a volume. If you enable this policy setting, the system records an event. If you disable this policy setting ...

CCE-99786-6
This subcategory reports events generated by the Kerberos Authentication Server. These events occur on the computer that is authoritative for the credentials. Events for this subcategory include: - 4768: A Kerberos authentication ticket (TGT) was requested. - 4771: Kerberos pre-authentication failed ...

CCE-93389-5
Enforce disk quota limit Determines whether disk quota limits are enforced and prevents users from changing the setting. If you enable this setting, disk quota limits are enforced. If you disable this setting, disk quota limits are not enforced. When you enable or disable the setting, the system d ...

CCE-99751-0
Specifies whether the Order Prints Online task is available from Picture Tasks in Windows folders. The Order Prints Online Wizard is used to download a list of providers and allow users to order prints online. If you enable this setting, the task Order Prints Online is removed from Picture Tasks i ...

CCE-93585-8
This policy setting controls the behavior of application installation detection for the computer. The options are: - Enabled: (Default for home) When an application installation package is detected that requires elevation of privilege, the user is prompted to enter an administrative user name ...

CCE-93946-2
Turn off System Restore Allows you to disable System Restore. System Restore enables users, in the event of a problem, to restore their computers to a previous state without losing personal data files. By default, System Restore is turned on for the boot volume. If you enable this setting, System ...

CCE-93158-4
Lock Enhanced Storage when the computer is locked This policy will enable the Enhanced Storage device to be locked when the computer is locked. This policy is supported in Windows Enterprise and Business SKUs only. If you enable this policy setting, the Enhanced Storage device will remain locked ...

CCE-93911-6
Create a system restore point This policy setting allows you to create a system restore point on the computer on a daily basis prior to cleaning. If you enable this setting, a system restore point will be created. If you disable or do not configure this setting, a system restore point will n ...

CCE-94129-4
Intersite Messaging The Intersite Messaging service enables message exchanges between computers that run Windows Server sites. This service is used for mail-based replication between sites. Active Directory includes support for replication between sites through SMTP over IP transport. SMTP support ...

CCE-93430-7
Do not log users on with temporary profiles This policy will automatically log off a user when Windows cannot load their profile. If Windows cannot access the user profile folder or the profile contains errors that prevent it from loading, Windows logs on the user with a temporary profile. This p ...

CCE-99809-6
This policy setting determines whether published User Activities can be uploaded. If you enable this policy setting, activities of type User Activity are allowed to be uploaded. If you disable this policy setting, activities of type User Activity are not allowed to be uploaded. Deletion of activitie ...

CCE-94084-1
Credential Manager Provides secure storage and retrieval of credentials to users, applications and security service packages.

CCE-94097-3
Quality Windows Audio Video Experience Quality Windows Audio Video Experience (qWave) is a networking platform for Audio Video (AV) streaming applications on IP home networks. qWave enhances AV streaming performance and reliability by ensuring network quality-of-service (QoS) for AV applications. I ...

CCE-93278-0
MSS: (AutoReboot) Allow Windows to automatically restart after a system crash (recommended except for highly secure environments) This entry appears as MSS: (AutoReboot) Allow Windows to automatically restart after a system crash (recommended except for highly secure environments) in the SCE. This ...

CCE-94160-9
Domain controller: LDAP server signing requirements This policy setting determines whether the Lightweight Directory Access Protocol (LDAP) server requires LDAP clients to negotiate data signing.

CCE-99742-9
This subcategory reports changes in audit policy including SACL changes. Events for this subcategory include: ? 4715: The audit policy (SACL) on an object was changed. ? 4719: System audit policy was changed. ? 4902: The Per-user audit policy table was created. ? 4904: An attempt was made to registe ...

CCE-93496-8
Net.Tcp Listener Adapter Receives activation requests over the net.tcp protocol and passes them to WPAS. .net framework 3.0 & Windows Process Activation Service.

CCE-93617-9
Turn off background refresh of Group Policy Prevents Group Policy from being updated while the computer is in use. This setting applies to Group Policy for computers, users, and domain controllers. If you enable this setting, the system waits until the current user logs off the system before updat ...

CCE-93123-8
Windows Driver Foundation - User-mode Driver Framework Manages user-mode driver host processes.

CCE-93902-5
Configure local setting override for maximum percentage of CPU utilization This policy setting configures a local override for the configuration of maximum percentage of CPU utilization during scan. This setting can only be set by Group Policy. If you enable this setting, the local preference sett ...

CCE-93670-8
Task Scheduler Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start.

CCE-99720-5
This policy setting allows you to turn on or turn off Solicited (Ask for) Remote Assistance on this computer. If you enable this policy setting, users on this computer can use email or file transfer to ask someone for help. Also, users can use instant messaging programs to allow connections to this ...

CCE-93110-5
Do not display Manage Your Server page at logon This policy setting allows you to turn off the automatic display of the Manage Your Server page. If you enable this policy setting, the Manage Your Server page is not displayed each time an administrator logs on to the server. If you disable or do ...

CCE-93572-6
RemoteApp and Desktop Connection Management Manages the assignment of remoteApp and desktop connection resources to users

CCE-93728-4
Cryptographic Services Provides four management services: Catalog Database Service, which confirms the signatures of Windows files and allows new programs to be installed; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; Automatic ...

CCE-93959-5
Turn off Windows Customer Experience Improvement Program The Windows Customer Experience Improvement Program will collect information about your hardware configuration and how you use our software and services to identify trends and usage patterns. We will not collect your name, address, or any oth ...

CCE-93012-3
Windows Internal Database VSS Writer Provides the interface to backup and restore Windows Internal Database through the Windows VSS infrastructure.

CCE-94173-2
Computer Browser Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start.

CCE-93826-6
Use mandatory profiles on the RD Session Host server This policy setting allows you to specify whether Remote Desktop Services uses a mandatory profile for all users connecting remotely to the RD Session Host server. If you enable this policy setting, Remote Desktop Services uses the path specifie ...

CCE-99777-5
This subcategory reports when a user logs off from the system. These events occur on the accessed computer. For interactive logons, the generation of these events occurs on the computer that is logged on to. If a network logon takes place to access a share, these events generate on the computer that ...

CCE-93376-2
Printer browsing Announces the presence of shared printers to print browse master servers for the domain. If you enable this setting, the print spooler announces shared printers to the print browse master servers. If you disable this setting, shared printers are not announced to print browse mas ...

CCE-93145-1
This policy setting determines whether a domain member can periodically change its computer account password. If you enable this policy setting, the domain member will be prevented from changing its computer account password. If you disable this policy setting, the domain member can change its compu ...

CCE-93422-4
Microsoft .NET Framework NGEN v2.0.50727_I64 Microsoft .NET Framework NGEN

CCE-93008-1
SNMP Trap Receives trap messages generated by local or remote Simple Network Management Protocol (SNMP) agents and forwards the messages to SNMP management programs running on this computer. If this service is stopped, SNMP-based programs on this computer will not receive SNMP trap messages. If thi ...

CCE-93818-3
Leave Windows Installer and Group Policy Software Installation Data Determines whether the system retains a roaming user?s Windows Installer and Group Policy based software installation data on their profile deletion. By default User profile deletes all information related to a roaming user (which ...

CCE-99744-5
This subcategory reports each event of security group management, such as when a security group is created, changed, or deleted or when a member is added to or removed from a security group. If you enable this Audit policy setting, administrators can track events to detect malicious, accidental, and ...

CCE-93916-5
Do not process the legacy run list This policy setting causes the run list, which is a list of programs that Windows runs automatically when it starts, to be ignored. The customized run lists for Windows Vista are stored in the registry at the following locations: - HKEY_LOCAL_MACHINE\Software\Micr ...

CCE-93479-4
Allow desktop composition for remote desktop sessions This policy setting allows you to specify whether desktop composition is allowed for remote desktop sessions. This policy setting does not apply to RemoteApp sessions. If you enable this policy setting, desktop composition will be allowed for ...

CCE-93061-0
Configure local administrator merge behavior for lists This policy setting controls whether or not complex list settings configured by a local administrator are merged with Group Policy settings. This setting applies to lists such as threats and Exclusions. If you enable or do not configure this s ...

CCE-93795-3
Kerberos client support for claims, compound authentication and Kerberos armoring This policy setting controls whether a device will request claims and compound authentication for Dynamic Access Control and Kerberos armoring using Kerberos authentication with domains that support these features. ...

CCE-94113-8
SQL Server VSS Writer Provides the interface to the backup/restore Windows Internal Database through the Windows VSS infrastructure.

CCE-93400-0
Include command line in process creation events This policy setting determines what information is logged in security audit events when a new process has been created. This setting only applies when the Audit Process Creation policy is enabled. If you enable this policy setting the command line ...

CCE-93653-4
Certificate Propagation Propagates certificates from smart cards.

CCE-99722-1
This subcategory reports when an AD DS object is accessed. Only objects with SACLs cause audit events to be generated, and only when they are accessed in a manner that matches their SACL. These events are similar to the directory service access events in previous versions of Windows Server. This sub ...

CCE-93938-9
Turn off Windows Network Connectivity Status Indicator active tests This policy setting turns off the active tests performed by the Windows Network Connectivity Status Indicator (NCSI) to determine whether your computer is connected to the Internet or to a more limited network. As part of determin ...

CCE-93226-9
Net.Tcp Port Sharing Service The Net.Tcp Port Sharing Service provides the ability for multiple user processes to share TCP ports over the net.tcp protocol. This service supports the .NET Framework 3.0 Windows Communication Foundation (WCF), which provides a new TCP-based network protocol (net.tcp: ...

CCE-93760-7
Diagnostic Policy Service The Diagnostic Policy Service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, diagnostics will no longer function. If this service is disabled, any services that explicitly depend on it will fail to start.

CCE-99779-1
This subcategory reports the creation of a process and the name of the program or user that created it. Note: These events now get audited earlier than in previous versions of Windows. The creation of smss.exe and other early processes is now audited. Default settings that cannot be altered un ...

CCE-93903-3
Configure local setting override for scheduled quick scan time This policy setting configures a local override for the configuration of scheduled quick scan time. This setting can only be set by Group Policy. If you enable this setting, the local preference setting will take priority over Group Po ...

CCE-93213-7
This policy prevents automatic copying of user input methods to the system account for use on the sign-in screen. The user is restricted to the set of input methods that are enabled in the system account. Note this does not affect the availability of user input methods on the lock screen or with t ...

CCE-93070-1
Pre-populate printer search location text Enables the physical Location Tracking setting for Windows printers. Use Location Tracking to design a location scheme for your enterprise and assign computers and printers to locations in the scheme. Location Tracking overrides the standard method used to ...

CCE-93884-5
Remote Desktop Session Broker Enables a user connection request to be routed to the appropriate Remote Desktop Session Host server in a cluster. If this service is stopped, connection requests will be routed to the first available server.

CCE-93609-6
Change Group Policy processing to run asynchronously when a slow network connection is detected. This policy directs Group Policy processing to skip processing any client side extension that requires synchronous processing (that is, whether computers wait for the network to be fully initialized dur ...

CCE-93115-4
Request compound authentication This policy setting allows you to configure a domain controller to request compound authentication. Note: For a domain controller to request compound authentication, the policy 'KDC support for claims, compound authentication, and Kerberos armoring' must be config ...

CCE-93017-2
Configure Security Policy for Scripted Diagnostics Determines whether scripted diagnostics will execute diagnostic packages that are signed by untrusted publishers. If you enable this policy setting, the scripted diagnostics execution engine will validate the signer of any diagnostic package and o ...

CCE-93786-2
Redirect only the default client printer This policy setting allows you to specify whether the default client printer is the only printer redirected in Remote Desktop Services sessions. If you enable this policy setting, only the default client printer is redirected in Remote Desktop Services sess ...

CCE-99757-7
When you enable this setting, planned password expiration longer than password age dictated by &quot;Password Settings&quot; policy is NOT allowed. When such expiration is detected, password is changed immediately and password expiration is set according to policy. When you disable or not confi ...

CCE-93751-6
Application Host Helper Service Provides administrative services for IIS, for example configuration history and Application Pool account mapping. If this service is stopped, configuration history and locking down files or directories with Application Pool specific Access Control Entries will not wo ...

CCE-93564-3
Turn on catch-up quick scan This policy setting allows you to configure catch-up scans for scheduled quick scans. A catch-up scan is a scan that is initiated because a regularly scheduled scan was missed. Usually these scheduled scans are missed because the computer was turned off at the scheduled ...

CCE-93190-7
Do not forcefully unload the users registry at user logoff Microsoft Windows will always unload the users registry, even if there are any open handles to the per-user registry keys at user logoff. Using this policy setting, an administrator can negate this behavior, preventing Windows from forceful ...

CCE-94202-9
Devices: Restrict floppy access to locally logged-on user only This policy setting determines whether removable floppy media are accessible to both local and remote users simultaneously. If you enable this policy setting, only the interactively logged-on user is allowed to access removable floppy m ...

CCE-93137-8
User Account Control: Virtualize file and registry write failures to per-user locations This policy setting controls whether application write failures are redirected to defined registry and file system locations. This policy setting mitigates applications that run as administrator and write run-ti ...

CCE-93599-9
Turn off Group Policy Client Service AOAC optimization This policy setting prevents the Group Policy Client Service from stopping when idle.

CCE-94104-7
KtmRm for Distributed Transaction Coordinator Coordinates transactions between MSDTC and the Kernel Transaction Manager (KTM).

CCE-93871-2
Specify the maximum depth to scan archive files This policy setting allows you to configure the maximum directory depth level into which archive files such as .ZIP or .CAB are unpacked during scanning. The default directory depth level is 0. If you enable this setting, archive files will be scan ...

CCE-99700-7
This policy setting controls whether or not errors are reported to Microsoft. Error Reporting is used to report information about a system or application that has failed or has stopped responding and is used to improve the quality of the product. If you enable this policy setting, users are not gi ...

CCE-93311-9
Windows Event Collector This service manages persistent subscriptions to events from remote sources that support WS-Management protocol. This includes Windows Vista event logs, hardware and IPMI-enabled event sources. The service stores forwarded events in a local Event Log. If this service is stop ...

CCE-94011-4
Removable Disks: Deny write access This policy setting denies write access to removable disks. If you enable this policy setting, write access will be denied to this removable storage class. If you disable or do not configure this policy setting, write access will be allowed to this removable sto ...

CCE-93426-5
Prompt user when a slow network connection is detected This policy setting provides users with the ability to download their roaming profile, even when a slow network connection with their roaming profile server is detected. If you enable this policy setting, users will be allowed to define whethe ...

CCE-99846-8
This policy allows you to audit the group membership information in the user logon token. Events in this subcategory are generated on the computer on which a logon session is created. For an interactive logon, the security audit event is generated on the computer that the user logged on to. For a ne ...

CCE-93622-9
Display Error Notification This policy setting controls whether users are shown an error dialog box that lets them report an error. If you enable this policy setting, users are notified in a dialog box that an error has occurred, and can display more details about the error. If the Configure Err ...

CCE-93742-5
Override print driver execution compatibility setting reported by print driver This policy setting determines whether the print spooler will override the Driver Isolation compatibility reported by the print driver. This enables executing print drivers in an isolated process, even if the driver does ...

CCE-93995-9
Turn off downloading of print drivers over HTTP This policy setting controls whether the computer can download print driver packages over HTTP. To set up HTTP printing, printer drivers that are not available in the standard operating system installation might need to be downloaded over HTTP.

CCE-94068-4
Run Windows PowerShell scripts first at computer startup, shutdown This policy setting determines whether Windows PowerShell scripts will run before non-PowerShell scripts during computer startup and shutdown. By default, PowerShell scripts run after non-PowerShell scripts. If you enable this po ...

CCE-99681-9
Unnecessary services increase the attack surface of a system. Some of these services may not support required levels of authentication or encryption or may provide unauthorized access to the system. Fix: Uninstall the &quot;Fax Server&quot; role. Start &quot;Server Manager&quot;. Select the serve ...

CCE-93524-7
Disallow changing of geographic location This policy prevents users from changing their user geographical location (GeoID). If this policy is Enabled, then the user cannot change their geographical location (GeoID) If the policy is Disabled or Not Configured, then the user may select any GeoID. ...

CCE-93150-1
User Account Control: Admin Approval Mode for the Built-in Administrator account This policy setting controls the behavior of Admin Approval Mode for the built-in Administrator account. The options are: - Enabled: The built-in Administrator account uses Admin Approval Mode. By default, any operat ...

CCE-93657-5
Windows Internal Database Provides internal relational database services for use by Windows Server features and roles

CCE-99713-0
This policy setting controls how the RPC server runtime handles unauthenticated RPC clients connecting to RPC servers. This policy setting impacts all RPC applications. In a domain environment this policy setting should be used with caution as it can impact a wide range of functionality including g ...

CCE-94144-3
User Account Control: Switch to the secure desktop when prompting for elevation This policy setting controls whether the elevation request prompt is displayed on the interactive user's desktop or the secure desktop. The options are: - Enabled: (Default) All elevation requests go to the secure des ...

CCE-93052-9
Display additional text to clients when they need to perform an action This policy setting allows you to configure whether or not to display additional text to clients when they need to perform an action. The text displayed is a custom administrator-defined string. For example, the phone number to ...

CCE-99726-2
This subcategory reports changes to objects in Active Directory Domain Services (AD DS). The types of changes that are reported are create, modify, move, and undelete operations that are performed on an object. DS Change auditing, where appropriate, indicates the old and new values of the changed pr ...

CCE-93439-8
Turn on protocol recognition This policy setting allows you to configure protocol recognition for network protection against exploits of known vulnerabilities. If you enable or do not configure this setting, protocol recognition will be enabled. If you disable this setting, protocol recogniti ...

CCE-93537-9
Allow definition updates from Microsoft Update This policy setting allows you to enable download of definition updates from Microsoft Update even if the Automatic Updates default server is configured to another download source such as Windows Update. If you enable this setting, definition update ...

CCE-93185-7
Routing and Remote Access Offers routing services to businesses in local area and wide area network environments.

CCE-93600-5
Turn off Windows Installer RDS Compatibility This policy setting specifies whether Windows Installer RDS Compatibility runs on a per user basis for fully installed applications. Windows Installer allows one instance of the msiexec process to run at a time. By default, Windows Installer RDS Compatib ...

CCE-93502-3
Configure local setting override for scanning all downloaded files and attachments This policy setting configures a local override for the configuration of scanning for all downloaded files and attachments. This setting can only be set by Group Policy. If you enable this setting, the local prefere ...

CCE-93172-5
Automatic reconnection Specifies whether to allow Remote Desktop Connection clients to automatically reconnect to sessions on an RD Session Host server if their network link is temporarily lost. By default, a maximum of twenty reconnection attempts are made at five second intervals. If the status ...

CCE-93533-8
Turn on heuristics This policy setting allows you to configure heuristics. Suspicious detections will be suppressed right before reporting to the engine client. Turning off heuristics will reduce the capability to flag new threats. It is recommended that you do not turn off heuristics. If you en ...

CCE-94122-9
Shutdown: Clear virtual memory pagefile This policy setting determines whether the virtual memory pagefile is cleared when the system is shut down. When this policy setting is enabled, the system pagefile is cleared each time that the system shuts down properly. If you enable this security setting, ...

CCE-99802-1
Remote host allows delegation of non-exportable credentials When using credential delegation, devices provide an exportable version of credentials to the remote host. This exposes users to the risk of credential theft from attackers on the remote host. If you enable this policy setting, the host s ...

CCE-93755-7
Telephony Provides Telephony API (TAPI) support for programs that control telephony devices on the local computer and, through the LAN, on servers that are also running the service.

CCE-94157-5
Remote Procedure Call (RPC) Locator Manages the RPC name service database.

CCE-93292-1
Windows Event Log This service manages events and event logs. It supports logging events, querying events, subscribing to events, archiving event logs, and managing event metadata. It can display events in both XML and plain text format. Stopping this service may compromise security and reliability ...

CCE-94100-5
Windows License Monitoring Service This service monitors the Windows software license state.

CCE-94090-8
Message Queuing The Message Queuing service is a messaging infrastructure and development tool that can be used to create distributed messaging applications for Windows. Such applications can communicate across heterogeneous networks and send messages between computers that may be temporarily unabl ...

CCE-93511-4
Windows Search Provides content indexing and property caching for file, email and other content (via extensibility APIs). The service responds to file and email notifications to index modified content. If the service is stopped or disabled, the Explorer will not be able to display virtual folder ...

CCE-93973-6
Run logon scripts synchronously Directs the system to wait for the logon scripts to finish running before it starts the Windows Explorer interface program and creates the desktop. If you enable this setting, Windows Explorer does not start until the logon scripts have finished running. This settin ...

CCE-99704-9
This subcategory reports the loading of extension code such as authentication packages by the security subsystem. Events for this subcategory include: ? 4610: An authentication package has been loaded by the Local Security Authority. ? 4611: A trusted logon process has been registered with the Local ...

CCE-93413-3
Configure Direct Access connections as a fast network connection This policy setting allows an administrator to define the Direct Access connection to be considered a fast network connection for the purposes of applying and updating Group Policy. When Group Policy detects the bandwidth speed o ...

CCE-99837-7
This policy setting allows you to audit events generated by Kerberos authentication ticket-granting ticket (TGT) requests submitted for user accounts. If you configure this policy setting, an audit event is generated after a Kerberos authentication TGT is requested for a user account. Success audit ...

CCE-93777-1
File Server Resource Manager Provides services for quota and file screen management.

CCE-93217-8
Determine if interactive users can generate Resultant Set of Policy data This policy setting controls the ability of users to view their Resultant Set of Policy (RSoP) data. By default, interactively logged on users can view their own Resultant Set of Policy (RSoP) data. If you enable this po ...

CCE-93546-0
Allow real-time definition updates based on reports to Microsoft MAPS This policy setting allows you to enable real-time definition updates in response to reports sent to Microsoft MAPS. If the service reports a file as an unknown and Microsoft MAPS finds that the latest definition update has defin ...

CCE-93712-8
Network Connectivity Assistant Provides DirectAccess status notification for UI components

CCE-93253-3
MSS: (Hidden) Hide Computer From the Browse List (not recommended except for highly secure environments) The registry value entry Hidden was added to the template file in the HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Lanmanserver\Parameters\ registry key. The entry appears as MSS: (Hidde ...

CCE-93155-0
Interactive logon: Smart card removal behavior This policy setting determines what happens when the smart card for a logged-on user is removed from the smart card reader.

CCE-93649-2
Use RD Connection Broker load balancing This policy setting allows you to specify whether to use the RD Connection Broker load balancing feature to balance the load between servers in an RD Session Host server farm. If you enable this policy setting, RD Connection Broker redirects users who do no ...

CCE-93832-4
Disable revocation checking for the SSL certificate of KDC proxy servers This policy setting allows you to disable revocation check for the SSL certificate of the KDC proxy server being connected to. If you enable this policy setting, revocation check for the SSL certificate of the KDC proxy ser ...

CCE-93734-2
MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing) The registry value entry DisableIPSourceRouting was added to the template file in the HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\ registry key. The entry appears as MSS: (D ...

CCE-93965-2
Enable/Disable PerfTrack This policy setting specifies whether to enable or disable tracking of responsiveness events. If you enable this policy setting, responsiveness events are processed and aggregated. The aggregated data will be transmitted to Microsoft through SQM. if you disable this polic ...

CCE-94054-4
Secure Socket Tunneling Protocol Service Provides support for the Secure Socket Tunneling Protocol (SSTP) to connect to remote computers using VPN. If this service is disabled, users will not be able to use SSTP to access remote servers.

CCE-99717-1
The registry value entry NoNameReleaseOnDemand was added to the template file in the HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Netbt\ Parameters\ registry key. The entry appears as MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS ser ...

CCE-93177-4
Windows Store Service (WSService) Provides infrastructure support for Windows Store. This service is started on demand and if disabled applications bought using Windows Store will not behave correctly.

CCE-93484-4
Wait for remote user profile Directs the system to wait for the remote copy of the roaming user profile to load, even when loading is slow. Also, the system waits for the remote copy when the user is notified about a slow connection, but does not respond in the time allowed. This setting and relat ...

CCE-99828-6
Disabling this setting disables server-side processing of the SMBv1 protocol. (Recommended.) Enabling this setting enables server-side processing of the SMBv1 protocol. (Default.) Changes to this setting require a reboot to take effect. For more information, see https://support.microsoft.com/kb/2 ...

CCE-93627-8
Do not display Server Manager automatically at logon This policy setting allows you to turn off the automatic display of Server Manager at logon. If you enable this policy setting, Server Manager is not displayed automatically when an administrator logs on to the server. If you disable this polic ...

CCE-99783-3
This subcategory reports changes in policy rules used by the Microsoft Protection Service (MPSSVC.exe). This service is used by Windows Firewall and by Microsoft OneCare. Events for this subcategory include: - 4944: The following policy was active when the Windows Firewall started. - 4945: A ...

CCE-93756-5
Network Store Interface Service This service delivers network notifications (e.g. interface addition/deleting etc) to user mode clients. Stopping this service will cause loss of network connectivity. If this service is disabled, any other services that explicitly depend on this service will fail to ...

CCE-93921-5
Turn on behavior monitoring This policy setting allows you to configure behavior monitoring. If you enable or do not configure this setting, behavior monitoring will be enabled. If you disable this setting, behavior monitoring will be disabled.

CCE-93199-8
Logon information is required to unlock a locked computer. For domain accounts, the Interactive logon: Require Domain Controller authentication to unlock workstation setting determines whether it is necessary to contact a domain controller to unlock a computer. If you enable this setting, a domain c ...

CCE-93658-3
System Event Notification Service Monitors system events and notifies subscribers to COM+ Event System of these events.

CCE-99806-2
Enumeration policy for external DMA-capable devices incompatible with DMA remapping. This policy only takes effect when Kernel DMA Protection is enabled and supported by the system. Note: this policy does not apply to 1394, PCMCIA or ExpressCard devices. Fix: (1) GPO: Computer Configuration\Admin ...

CCE-93858-9
Configure local setting override for the removal of items from Quarantine folder This policy setting configures a local override for the configuration of the number of days items should be kept in the Quarantine folder before being removed. This setting can only be set by Group Policy. If you enab ...

CCE-93725-0
MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended) The registry value entry AutoAdminLogon was added to the template file in the HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ registry key. The entry appears as MSS: (AutoAdminLogon) Enable Automatic Logon (not ...

CCE-94089-0
Cluster Service Cluster Service controls server cluster operations and manages the cluster database. A cluster is a collection of independent computers that is as easy to use as a single computer. Managers see it as a single system, programmers see it as a single system, and users see it as a singl ...

CCE-93240-0
Allow audio and video playback redirection This policy setting allows you to specify whether users can redirect the remote computer's audio and video output in a Remote Desktop Services session. Users can specify where to play the remote computer's audio output by configuring the remote audio sett ...

CCE-94130-2
Windows Remote Management (WS-Management) Windows Remote Management (WinRM) service implements the WS-Management protocol for remote management. WS-Management is a standard web services protocol used for remote software and hardware management. The WinRM service listens on the network for WS-Manage ...

CCE-93142-8
Power Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability.

CCE-93503-1
Require use of fast startup This policy setting controls the use of fast startup. If you enable this policy setting, the system requires hibernate to be enabled. If you disable or do not configure this policy setting, the local setting is used.

CCE-93031-3
Superfetch Maintains and improves system performance over time.

CCE-93209-5
Enable LSA Protection Use this setting to configure additional protection for the Local Security Authority (LSA) process to prevent code injection that could compromise credentials. On x86-based or x64-based devices that use Secure Boot and UEFI, a UEFI variable is set in the UEFI firmware when ...

CCE-93591-6
Human Interface Device Access Enables generic input access to Human Interface Devices (HID), which activates and maintains the use of predefined hot buttons on keyboards, remote controls, and other multimedia devices. If this service is stopped, hot buttons controlled by this service will no longer ...

CCE-94067-6
Do not allow v4 printer drivers to show printer extensions This policy determines if v4 printer drivers are allowed to run printer extensions. V4 printer drivers may include an optional, customized user interface known as a printer extension. These extensions may provide access to more d ...

CCE-93978-5
Turn Off Boot and Resume Optimizations Turns off the boot and resume optimizations for the hybrid hard disks in the system. If you enable this policy setting, the system does not use the non-volatile (NV) cache to optimize boot and resume. If you disable this policy setting, the system uses the N ...

CCE-99708-0
This subcategory reports when a special logon is used. A special logon is a logon that has administrator-equivalent privileges and can be used to elevate a process to a higher level. Events for this subcategory include: ? 4964 : Special groups have been assigned to a new logon. Refer to the Microso ...

CCE-93493-5
Peer Networking Identity Manager Provides Identity services for Peer Networking.

CCE-93845-6
Enforce Removal of Remote Desktop Wallpaper Specifies whether desktop wallpaper is displayed to remote clients connecting via Remote Desktop Services. You can use this setting to enforce the removal of wallpaper during a Remote Desktop Services session. By default, Windows XP Professional displays ...

CCE-93614-6
Restrict Remote Desktop Services users to a single Remote Desktop Services session This policy setting allows you to restrict users to a single remote Remote Desktop Services session. If you enable this policy setting, users who log on remotely using Remote Desktop Services will be restricted to a ...

CCE-93066-9
Define proxy server for connecting to the network This policy setting allows you to configure the named proxy that should be used when the client attempts to connect to the network for definition updates and MAPS reporting. If the named proxy fails or if there is no proxy specified, the following s ...

CCE-94117-9
AD RMS Logging Service The Active Directory Rights Management Service (AD RMS) logging service runs on each server in an AD RMS cluster and sends logging information to the logging database. This information is used by AD RMS to generate reports from within the Active Directory Rights Management Se ...

CCE-93716-9
This policy setting controls whether User Interface Accessibility (UIAccess or UIA) programs can automatically disable the secure desktop for elevation prompts used by a standard user. - Enabled: UIA programs, including Windows Remote Assistance, automatically disable the secure desktop for elevati ...

CCE-99654-6
SMBv1 is a legacy protocol that uses the MD5 algorithm as part of SMB. MD5 is known to be vulnerable to a number of attacks such as collision and preimage attacks as well as not being FIPS compliant. Disabling SMBv1 support may prevent access to file or print sharing resources with systems or devic ...

CCE-94072-6
Net.Msmq Listener Adapter Receives activation requests over the net.msmq and msmq.formatname protocols and passes them to the Windows Process Activation Service.

CCE-93257-4
DFS Namespace Integrates disparate file shares into a single, logical namespace and manages these logical volumes.

CCE-93159-2
Always show desktop on connection This policy setting determines whether the desktop is always displayed after a client connects to a remote computer or an initial program can run. It can be used to require that the desktop be displayed after a client connects to a remote computer, even if an initi ...

CCE-93200-4
Do not allow password authentication of Enhanced Storage devices This policy setting configures whether or not a password can be used to unlock an Enhanced Storage device. If you enable this policy setting, a password cannot be used to unlock an Enhanced Storage device. If you disable or do not c ...

CCE-99774-2
Determines when registry policies are updated. This setting affects all policies in the Administrative Templates folder and any other policies that store values in the registry. It overrides customized settings that the program implementing a registry policy set when it was installed. If you enab ...

CCE-93791-2
IPsec Policy Agent Internet Protocol security (IPsec) supports network-level peer authentication, data origin authentication, data integrity, data confidentiality (encryption), and replay protection. This service enforces IPsec policies created through the IP Security Policies snap-in or the comma ...

CCE-94170-8
Problem Reports and Solutions Control Panel Support This service provides support for viewing, sending and deletion of system-level problem reports for the Problem Reports and Solutions control panel.

CCE-93738-3
Remote Access Connection Manager Manages dial-up and virtual private network (VPN) connections from this computer to the Internet or other remote networks. If this service is disabled, any services that explicitly depend on it will fail to start.

CCE-94050-2
WMI Performance Adapter Provides performance library information from Windows Management Instrumentation (WMI) providers to clients on the network. This service only runs when Performance Data Helper is activated.

CCE-93956-1
Turn off Event Viewer 'Events.asp' links Specifies whether 'Events.asp' hyperlinks are available for events within the Event Viewer application. The Event Viewer normally makes all HTTP(S) URLs into hot links that activate the Internet browser when clicked. In addition, 'More Information' is place ...

CCE-93222-8
Hyper-V Image Management Service Provides Image Management servicing for Hyper-V.

CCE-93801-9
Do not allow supported Plug and Play device redirection This policy setting allows you to control the redirection of supported Plug and Play devices, such as Windows Portable Devices, to the remote computer in a Remote Desktop Services session. By default, Remote Desktop Services allows redirectio ...

CCE-99752-8
This subcategory reports changes in authentication policy. Events for this subcategory include: ? 4706: A new trust was created to a domain. ? 4707: A trust to a domain was removed. ? 4713: Kerberos policy was changed. ? 4716: Trusted domain information was modified. ? 4717: System security access w ...

CCE-93355-6
Allow only Windows Vista or later connections This policy setting enables Remote Assistance invitations to be generated with improved encryption so that only computers running this version (or later versions) of the operating system can connect. This policy setting does not affect Remote Assistance ...

CCE-93880-3
Do not throttle additional data This policy setting determines whether Windows Error Reporting (WER) sends additional, second-level report data even if a CAB file containing data about the same event types has already been uploaded to the server. If you enable this policy setting, WER does not t ...

CCE-93409-1
IP Helper Provides automatic IPv6 connectivity over an IPv4 network. If this service is stopped, the machine will only have IPv6 connectivity if it is connected to a native IPv6 network.

CCE-93605-4
Remote Desktop Configuration Remote Desktop Configuration service (RDCS) is responsible for all Terminal Services and Remote Desktop related configuration and session maintenance activities that require SYSTEM context. These include per-session temporary folders, TS themes, and TS certificates.

CCE-93782-1
Network access: Sharing and security model for local accounts This policy setting determines how network logons that use local accounts are authenticated. The Classic option allows precise control over access to resources, including the ability to assign different types of access to different users ...

CCE-93111-3
Do not display network selection UI This policy setting allows you to control whether anyone can interact with available networks UI on the logon screen. If you enable this policy setting, the PC's network connectivity state cannot be changed without signing into Windows. If you disable or do ...

CCE-94108-8
Hide entry points for Fast User Switching By enabling the policy, Administrators hide the Switch user button in the Logon UI, the Start menu and the Task Manager.

CCE-93244-2
Portable Device Enumerator Service Enforces group policy for removable mass-storage devices. Enables applications such as Windows Media Player and Image Import Wizard to transfer and synchronize content using removable mass-storage devices.

CCE-94085-8
Diagnostic Service Host The Diagnostic Service Host service enables problem detection, troubleshooting and resolution for Windows components. If this service is stopped, some diagnostics will no longer function. If this service is disabled, any services that explicitly depend on it will fail to st ...

CCE-99730-4
This policy setting allows you to set the encryption types that Kerberos is allowed to use. This policy is supported on at least Windows 7 or Windows Server 2008 R2. This policy setting allows you to set the encryption types that Kerberos is allowed to use.

CCE-93925-6
Turn on process scanning whenever real-time protection is enabled This policy setting allows you to configure process scanning when real-time protection is turned on. This helps to catch malware which could start when real-time protection is turned off. If you enable or do not configure this set ...

CCE-93048-7
Microsoft Support Diagnostic Tool: Restrict tool download Restricts the tool download policy for Microsoft Support Diagnostic Tool. Microsoft Support Diagnostic Tool (MSDT) gathers diagnostic data for analysis by support professionals. For some problems, MSDT may prompt the user to download addit ...

CCE-94206-0
Microsoft Software Shadow Copy Provider Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this service is stopped, software-based volume shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start.

CCE-94098-1
Performance Logs & Alerts Performance Logs and Alerts Collects performance data from local or remote computers based on preconfigured schedule parameters, then writes the data to a log or triggers an alert. If this service is stopped, performance information will not be collected. If this service i ...

CCE-93440-6
DCOM: Machine Access Restrictions in Security Descriptor Definition Language (SDDL) syntax This policy setting determines which users or groups might access DCOM application remotely or locally. This setting is used to control the attack surface of the computer for DCOM applications. You can use ...

CCE-94161-7
webclient The WebClient service allows Win32 applications to access documents on the Internet. The service extends the network capability of Windows; it allows standard Win32 applications to create, read, and write files on Internet file servers through the use of WebDAV, a file-access protocol tha ...

CCE-99743-7
This subcategory reports on other system events. Events for this subcategory include: ? 5024 : The Windows Firewall Service has started successfully. ? 5025 : The Windows Firewall Service has been stopped. ? 5027 : The Windows Firewall Service was unable to retrieve the security policy from the loca ...

CCE-93342-4
Allow audio recording redirection This policy setting allows you to specify whether users can record audio to the remote computer in a Remote Desktop Services session. Users can specify whether to record audio to the remote computer by configuring the remote audio settings on the Local Resources t ...

CCE-93912-4
Scan network files This policy setting allows you to configure scanning for network files. It is recommended that you do not enable this setting. If you enable this setting, network files will be scanned. If you disable or do not configure this setting, network files will not be scanned.

CCE-93266-5
Windows CardSpace Securely enables the creation, management, and disclosure of digital identities.

CCE-93814-2
Delete cached copies of roaming profiles Determines whether the system saves a copy of a user?s roaming profile on the local computer's hard drive when the user logs off. This setting, and related settings in this folder, together describe a strategy for managing user profiles residing on remote s ...

CCE-94196-3
Turn on PIN sign-in This policy setting allows you to control whether a domain user can sign in using a PIN. If you enable this policy setting, a domain user can set up and sign in with a PIN. If you disable or don't configure this policy setting, a domain user can't set up and use a PIN. ...

CCE-93947-0
Microsoft Support Diagnostic Tool: Turn on MSDT interactive communication with Support Provider Microsoft Support Diagnostic Tool (MSDT) gathers diagnostic data for analysis by support professionals. If you leave this policy setting enabled, Users will be able to use MSDT to collect and send diagn ...

CCE-93445-5
Force selected system UI language to overwrite the user UI language This is a setting for computers with more than one UI language installed. If you enable this setting, the UI language of Windows menus and dialogs language for systems with more than one language will follow the language specified ...

CCE-99710-6
This policy setting turns off toast notifications on the lock screen. If you enable this policy setting, applications will not be able to raise toast notifications on the lock screen. If you disable or do not configure this policy setting, toast notifications on the lock screen are enabled and can ...

CCE-93939-7
Hide previous versions list for local files This policy setting lets you hide the list of previous versions of files that are on local disks. The previous versions could come from the on-disk restore points or from backup media. If you enable this policy setting, users cannot list or restore pre ...

CCE-93761-5
Deny log on as a service This security setting determines which service accounts are prevented from registering a process as a service. This policy setting supersedes the Log on as a service policy setting if an account is subject to both policies.Note: This security setting does not apply to the S ...

CCE-93084-2
Turn on Smart Card Plug and Play service This policy setting allows you to control whether Smart Card Plug and Play is enabled. If you enable or do not configure this policy setting, Smart Card Plug and Play will be enabled and the system will attempt to install a Smart Card device driver when a c ...

CCE-93280-6
Prevent embedded UI This policy setting controls the ability to prevent embedded UI. If you enable this policy setting, no packages on the system can run embedded UI. If you disable or do not configure this policy setting, embedded UI is allowed to run.

CCE-93312-7
Turn Off Hybrid Sleep (On Battery) Disables Hybrid Sleep. If you enable this policy setting, a hiberfile is not generated when the system transitions to sleep (Stand By). If you do not configure this policy setting, users can see and change this setting.

CCE-93543-7
Do not display 'Install Updates and Shut Down' option in Shut Down Windows dialog box This policy setting allows you to manage whether the Install Updates and Shut Down option is displayed in the Shut Down Windows dialog box. This policy setting works in conjunction with the following Do not adjust ...

CCE-99830-2
This policy setting lets you configure Windows spotlight on the lock screen. If you enable this policy setting, &quot;Windows spotlight&quot; will be set as the lock screen provider and users will not be able to modify their lock screen. &quot;Windows spotlight&quot; will display daily images from ...

CCE-94016-3
Restrict unpacking and installation of gadgets that are not digitally signed. This policy setting allows you to restrict the installation of unsigned gadgets. Desktop gadgets can be deployed as compressed files, either digitally signed or unsigned. If you enable this setting, gadgets that have no ...

CCE-93071-9
License server security group This policy setting allows you to specify the RD Session Host servers to which a Remote Desktop license server will offer Remote Desktop Services client access licenses (RDS CALs). You can use this policy setting to control which RD Session Host servers are issued RDS ...

CCE-93116-2
Turn on dynamic Content URI Rules for Windows store apps This policy setting lets you turn on Content URI Rules to supplement the static Content URI Rules that were defined as part of the app manifest and apply to all Windows Store apps that use the enterpriseAuthentication capability on a computer ...

CCE-93018-0
Turn Off UDP On Client This policy setting specifies whether the UDP protocol will be used to access servers via Remote Desktop Protocol. If you enable this policy setting, Remote Desktop Protocol traffic will only use the TCP protocol. If you disable or do not configure this policy setting, ...

CCE-99843-5
This policy setting lets you turn off cloud consumer account state content in all Windows experiences. If you enable this policy, Windows experiences that use the cloud consumer account state content client component, will instead present the default fallback content. If you disable or do not co ...

CCE-93458-8
Do not allow locations on removable drives to be added to libraries This policy setting configures whether or not locations on removable drives can be added to libraries. If you enable this policy setting, locations on removable drives cannot be added to libraries. In addition, locations ...

CCE-99669-4
This policy setting determines the period of time (in days) during which a user's ticket-granting ticket (TGT) can be renewed. To prevent replay attacks, the Kerberos authentication protocol uses time stamps as part of its protocol definition. For time stamps to work properly, the clocks of the clie ...

CCE-94114-6
Do not allow manual configuration of discovered targets If enabled then discovered targets may not be manually configured. If disabled then discovered targets may be manually configured. Note: if enabled there may be cases where this will break VDS.

CCE-93236-8
Allow Basic authentication This policy setting allows you to manage whether the Windows Remote Management (WinRM) client uses Basic authentication. If you enable this policy setting, the WinRM client will use Basic authentication. If WinRM is configured to use HTTP transport, then the user name an ...

CCE-93650-0
Allow Basic authentication This policy setting allows you to manage whether the Windows Remote Management (WinRM) service accepts Basic authentication from a remote client. If you enable this policy setting, the WinRM service will accept Basic authentication from a remote client. If you disable o ...

CCE-93093-3
Back up log automatically when full This policy setting controls Event Log behavior when the log file reaches its maximum size and takes effect only if the 'Retain old events' policy setting is enabled. If you enable this policy setting and the 'Retain old events' policy setting is enabled, the ...

CCE-93138-6
LPD Service Enables client computers to print to the Line Printer Daemon (LPD) service on this server using TCP/IP and the Line Printer Remote (LPR) protocol.

CCE-99723-9
This policy setting allows you to prevent Windows Media Player from downloading codecs. If you enable this policy setting, the Player is prevented from automatically downloading codecs to your computer. In addition, the Download codecs automatically check box on the Player tab in the Player is not ...

CCE-99821-1
Enable this policy to specify when to receive Feature Updates. Defer Updates | This enables devices to defer taking the next Feature Update available to your channel for up to 14 days for all the pre-release channels and up to 365 days for the Semi-Annual Channel. Or, if the device is updating from ...

CCE-93191-5
Turn off IDN encoding Specifies whether the DNS client should convert internationalized domain names (IDNs) to Punycode when the computer is on non-domain networks with no WINS servers configured. If this policy setting is enabled, IDNs are not converted to Punycode. If this policy setting is ...

CCE-93454-7
Disable help tips Disables help tips that Windows shows to the user. By default, Windows will show the user help tips until the user has successfully completed the scenarios. If this setting is enabled, Windows will not show any help tips to the user. If this setting is disabled or not con ...

CCE-93685-6
Do not automatically start Windows Messenger initially Windows Messenger is automatically loaded and running when a user logs on to a Windows XP computer. You can use this setting to stop Windows Messenger from automatically being run at logon. If you enable this setting, Windows Messenger will no ...

CCE-93356-4
Disable remote Desktop Sharing Disables the remote desktop sharing feature of NetMeeting. Users will not be able to set it up or use it for controlling their computers remotely.

CCE-93467-9
Turn on logging This policy setting turns on logging. If you enable or do not configure this policy setting, then events can be written to this log. If the policy setting is disabled, then no new events can be logged. Events can always be read from the log, regardless of this policy setting.

CCE-94127-8
Microsoft File Server Shadow Copy Agent Service Manages shadow copy of file shares taken by the VSS file server agent. If this service is stopped, file share shadow copies cannot be managed. If this service is disabled, any services that explicitly depend on it will fail to start.

CCE-99856-7
This policy setting controls whether user have access to the Windows Package Manager. Windows Package Manager is a package manager solution that consists of a command line tool and set of services for installing applications on Microsoft Windows Server 2019 (or newer). The recommended state for thi ...

CCE-93334-1
Prevent Windows from sending an error report when a device driver requests additional software during installation This policy allows you to prevent Windows from sending an error report when a device driver requests additional software during installation. If you enable this policy setting, Window ...

CCE-94034-6
Set PNRP cloud to resolve only This policy setting limits a node to resolving, but not publishing, names in a specific Peer Name Resolution Protocol (PNRP) cloud. This policy setting forces computers to act as clients in peer-to-peer (P2P) scenarios. For example, a client computer can detect other ...

CCE-99714-8
Antivirus programs are mandatory in many environments and provide a strong defense against attack. The Notify antivirus programs when opening attachments setting allows you to manage how registered antivirus programs are notified. When enabled, this policy setting configures Windows to call the reg ...

CCE-93151-9
Data Deduplication Service The Data Deduplication service enables the deduplication and compression of data on selected volumes in order to optimize disk space used. If this service is stopped, optimization will no longer occur but access to already optimized data will continue to function.

CCE-94189-8
Turn off access to the OEM and Microsoft branding section Removes access to the performance center control panel OEM and Microsoft branding links. If you enable this setting, the OEM and Microsoft web links within the performance control panel page will not be displayed. The administrative tools w ...

CCE-93512-2
Allow Remote Shell Access This policy setting allows you to manage configuration of remote access to all supported shells to execute scripts and commands.

CCE-93186-5
Require a PIN to access data on devices running Microsoft firmware This policy setting requires users to enter a default personal identification number (PIN) to unlock and access data on the device after a specified period of inactivity (time-out period). This setting applies to Windows SideShow-co ...

CCE-93645-0
Turn off Multicast Name Resolution Local Link Multicast Name Resolution (LLMNR) is a secondary name resolution protocol. Queries are sent over the Local Link, a single subnet, from a client machine using Multicast to which another client on the same link, which also has LLMNR enabled, can respond. ...

CCE-99834-4
This policy setting sets the Attack Surface Reduction rules. Attack surface reduction helps prevent actions and apps that are typically used by exploit- seeking malware to infect machines. Fix: (1) GPO: Computer Configuration\Policies\Administrative Templates\Windows Components\Windows Defender An ...

CCE-93961-1
Disallow run-once backups This policy setting allows you to manage whether run-once backups of a machine can be run or not. If you enable this policy setting, machine administrator/backup operator cannot use Windows Server Backup to run non-scheduled run-once backups. If you disable or do not con ...

CCE-93449-7
Disallow Negotiate authentication This policy setting allows you to manage whether the Windows Remote Management (WinRM) client will not use Negotiate authentication. If you enable this policy setting, the WinRM client will not use Negotiate authentication. If you disable or do not configure this ...

CCE-93885-2
Prohibit Access of the Windows Connect Now wizards This policy setting prohibits access to Windows Connect Now (WCN) wizards. If this policy setting is enabled, the wizards are disabled and users will have no access to any of the wizard tasks. All the configuration related tasks, including ?Set up ...

CCE-93787-0
Do not allow changes to initiator iqn name If enabled then do not allow the initiator iqn name to be changed. If disabled then the initiator iqn name may be changed.

CCE-99749-4
This policy setting determines whether to require domain users to elevate when setting a network's location. If you enable this policy setting, domain users must elevate when setting a network's location. If you disable or do not configure this policy setting, domain users can set a network's loca ...

CCE-94069-2
Encrypt the Offline Files cache This setting determines whether offline files are encrypted. Offline files reside on a user's hard drive, not the network, and they are stored in a local cache on the computer. Encrypting this cache enhances security on a local computer. If the cache on the local co ...

CCE-93850-6
Turn off SwitchBack Compatibility Engine The policy controls the state of the Switchback compatibility engine in the system. Switchback is a mechanism that provides generic compatibility mitigations to older applications by providing older behavior to old applications and new behavior to new appl ...

CCE-99812-0
This policy setting blocks the Connected User Experience and Telemetry service from automatically using an authenticated proxy to send data back to Microsoft on Windows 10. If you disable or do not configure this policy setting, the Connected User Experience and Telemetry service will automatically ...

CCE-93525-4
Sign-in last interactive user automatically after a system-initiated restart This policy setting controls whether a device will automatically sign-in the last interactive user after Windows Update restarts the system. If you enable or do not configure this policy setting, the device securely sav ...

CCE-93195-6
Turn off downloading of game information Manages download of game box art and ratings from the Windows Metadata Services. If you enable this setting, game information including box art and ratings will not be downloaded. If you disable or do not configure this setting, game information will be d ...

CCE-93293-9
Turn off numerical sorting in File Explorer This policy setting allows you to have file names sorted literally (as in Windows 2000 and earlier) rather than in numerical order. If you enable this policy setting, File Explorer will sort file names by each digit in a file name (for example, 111 < 22 ...

CCE-93654-2
Modify an object label This privilege determines which user accounts can modify the integrity label of objects, such as files, registry keys, or processes owned by other users. Processes running under a user account can modify the label of an object owned by that user to a lower level without this ...

CCE-93097-4
Allow development of Windows Store apps without installing a developer license Allows or denies development of Windows Store applications without installing a developer license. If you enable this setting and enable the 'Allow all trusted apps to install' Group Policy, you can develop Wi ...

CCE-99780-9
This policy setting specifies the maximum size of the log file in kilobytes. If you enable this policy setting, you can configure the maximum log file size to be between 1 megabyte (1,024 kilobytes) and 2 terabytes (2,147,483,647 kilobytes) in kilobyte increments. If you disable or do not configure ...

CCE-93854-8
Proxy definitions are authoritative Turns off Windows Network Isolation's automatic proxy discovery in the domain corporate environment. If you enable this policy setting, it turns off Windows Network Isolation's automatic proxy discovery in the domain corporate environment. Only proxies configu ...

CCE-99825-2
This policy setting allows you to control the network connectivity state in standby on modern standby-capable systems. If you enable this policy setting, network connectivity will be maintained in standby. If you disable this policy setting, network connectivity in standby is not guaranteed. This ...

CCE-93689-8
Do not allow web search Enabling this policy removes the option of searching the Web from Windows Desktop Search. When this policy is disabled or not configured, the Web option is available and users can search the Web via their default browser search engine.

CCE-93974-4
Do not allow compression on all NTFS volumes Compression can add to the processing overhead of filesystem operations. Enabling this setting will prevent access to and creation of compressed files.

CCE-93721-9
Access this computer from the network This policy setting allows other users on the network to connect to the computer and is required by various network protocols that include Server Message Block (SMB)?based protocols, NetBIOS, Common Internet File System (CIFS), and Component Object Model Plus ( ...

CCE-93876-1
Block Firefox Web Browser This policy setting allows you to manage whether a user can run the Firefox web browser or not. This policy sets AppLocker rules to prevent users from running the Firefox web browser. If you enable this setting, users will be unable to run the Firefox web browser. If ...

CCE-94047-8
Allow only system backup This policy setting allows you to manage whether backups of only system volumes is allowed or both OS and data volumes can be backed up. If you enable this policy setting, machine administrator/backup operator can backup only volumes hosting OS components and no data only ...

CCE-93040-4
Hide previous versions of files on backup location This policy setting lets you hide entries in the list of previous versions of a file in which the previous version is located on backup media. Previous versions can come from the on-disk restore points or the backup media. If you enable this pol ...

CCE-99660-3
To ensure users do not experience denial of service when performing certificate-based authentication to DoD websites due to the system chaining to a root other than DoD Root CAs, the US DoD CCEB Interoperability Root CA cross-certificates must be installed in the Untrusted Certificate Store. This re ...

CCE-93632-8
Windows Firewall: Private: Apply local connection security rules This setting controls whether local administrators are allowed to create connection security rules that apply together with connection security rules configured by Group Policy.

CCE-93316-8
Turn off sensors This policy setting turns off the sensor feature for this computer. If you enable this policy setting, the sensor feature will be turned off, and all programs on this computer will not be able to use the sensor feature. If you disable or do not configure this poli ...

CCE-94123-7
Adjust memory quotas for a process This policy setting allows a user to adjust the maximum amount of memory that is available to a process. The ability to adjust memory quotas is useful for system tuning, but it can be abused. In the wrong hands, it could be used to launch a denial of service (DoS) ...

CCE-93743-3
Allow Automatic Sleep with Open Network Files (Plugged In) Allow Automatic Sleep with Open Network Files. If you enable this policy setting, the computer will automatically sleep when network files are open. If you disable this policy setting, the computer will not automatically sleep whe ...

CCE-93391-1
Windows Firewall: Domain: Logging: Log successful connections Use this option to log when Windows Firewall with Advanced Security allows an inbound connection. The log records why and when the connection was formed. Look for entries with the word ALLOW in the action column of the log.

CCE-94025-4
Force the reading of all certificates from the smart card This policy setting allows you to manage the reading of all certificates from the smart card for logon. During logon Windows will by default only read the default certificate from the smart card unless it supports retrieval of all certifica ...

CCE-93569-2
Create symbolic links This policy setting determines which users can create symbolic links. In Windows Vista, existing NTFS file system objects, such as files and folders, can be accessed by referring to a new kind of file system object called a symbolic link. A symbolic link is a pointer (much lik ...

CCE-93107-1
Turn off Automatic Download and Install of updates Enables or disables the automatic download and installation of app updates. If you enable this setting, the automatic download and installation of app updates is turned off. If you disable this setting, the automatic download and installation ...

CCE-93735-9
Prevent license upgrade This policy setting allows you to specify which version of Remote Desktop Services client access license (RDS CAL) a Remote Desktop Services license server will issue to clients connecting to RD Session Host servers running other Windows-based operating systems. A license s ...

CCE-94099-9
Turn Off Low Battery User Notification Disables a user notification when the battery capacity remaining equals the low battery notification level. If you enable this policy, Windows will not show a notification when the battery capacity remaining equals the low battery notification level. To conf ...

CCE-99793-2
This policy setting determines the amount of diagnostic and usage data reported to Microsoft. A value of 0 indicates that no telemetry data from OS components is sent to Microsoft. Setting a value of 0 is applicable to enterprise and server devices only. Setting a value of 0 for other devices is equ ...

CCE-93494-3
Allow the Network Access Protection client to support the 802.1x Enforcement Client component This policy setting allows the Network Access Protection (NAP) client to support the Windows XP version of the 802.1x Enforcement Client component. If you enable this policy setting, NAP allows the Window ...

CCE-93023-0
Do not allow adding new targets via manual configuration If enabled then new targets may not be manually configured by entering the target name and target portal; already discovered targets may be manually configured. If disabled then new and already discovered targets may be manually configured. ...

CCE-99838-5
Enables or disables the retrieval of online tips and help for the Settings app. If disabled, Settings will not contact Microsoft content services to retrieve tips and help content. Fix: (1) GPO: Computer Configuration\Administrative Templates\Control Panel\Allow Online Tips (2) REG: HKEY_LOCAL_ ...

CCE-94197-1
Act as part of the operating system When configuring a user right in the SCM enter a comma delimited list of accounts. Accounts can be either local or located in Active Directory, they can be groups, users, or computers.

CCE-93757-3
Do not allow additional session logins If enabled then only those sessions that are established via a persistent login will be established and no new persistent logins may be created. If disabled then additional persistent and non persistent logins may be established.

CCE-93988-4
Turn off PNRP cloud creation This policy setting enables or disables PNRP cloud creation. PNRP is a distributed name resolution protocol allowing Internet hosts to publish peer names with a corresponding Internet Protocol version 6 (IPv6) address. Other hosts can then resolve the name, retrieve th ...

CCE-94140-1
Control Event Log behavior when the log file reaches its maximum size This policy setting controls Event Log behavior when the log file reaches its maximum size. If you enable this policy setting and a log file reaches its maximum size, new events are not written to the log and are lost. If y ...

CCE-93975-1
Contact PDC on logon failure Defines whether a domain controller (DC) should attempt to verify with the PDC the password provided by a client if the DC failed to validate the password. Contacting the PDC is useful in case the client?s password was recently changed and did not propagate to the DC y ...

CCE-93419-0
Do not allow manual configuration of target portals If enabled then new target portals may not be added and thus new targets discovered on those portals; existing target portals may not be removed. If disabled then new target portals may be added and thus new targets discovered on those portals; ex ...

CCE-93820-9
Remote Desktop Services UserMode Port Redirector Allows the redirection of Printers/Drives/Ports for RDP connections

CCE-99816-1
Allow search and Cortana to search cloud sources like OneDrive and SharePoint Fix: (1) GPO: Computer Configuration\Administrative Templates\Windows Components\Search\Allow Cloud Search (2) REG: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Search!AllowCloudSearch

CCE-93045-3
User Interface Specifies whether an entry for DirectAccess connectivity appears when the user clicks the Networking notification area icon. Set this to Disabled to prevent user confusion when you are just using DirectAccess to remotely manage DirectAccess client computers from your intranet and ...

CCE-99771-8
This policy setting lets you capture the input and output of Windows PowerShell commands into text-based transcripts. If you enable this policy setting, Windows PowerShell will enable transcripting for Windows PowerShell, the Windows PowerShell ISE, and any other applications that leverage the Win ...

CCE-93143-6
Disable indexer backoff If enabled, the search indexer backoff feature will be disabled. Indexing will continue at full speed even when system activity is high. If disabled, backoff logic will be used to throttle back indexing activity when system activity is high. Default is disabled.

CCE-99718-9
This policy setting prevents the user from having enclosures (file attachments) downloaded from a feed to the user's computer. If you enable this policy setting, the user cannot set the Feed Sync Engine to download an enclosure through the Feed property page. A developer cannot change the download ...

CCE-94055-1
Deny log on as a batch job This policy setting determines which accounts will not be able to log on to the computer as a batch job. A batch job is not a batch (.bat) file, but rather a batch-queue facility. Accounts that use the Task Scheduler to schedule jobs need this user right. When configurin ...

CCE-93846-4
Block Google Chrome Web Browser This policy setting allows you to manage whether a user can run the Google Chrome web browser or not. This policy sets AppLocker rules to prevent users from running the Firefox web browser. If you enable this setting, users will be unable to run the Google Chrome ...

CCE-93032-1
Create a token object This policy setting allows a process to create an access token, which may provide elevated rights to access sensitive data. When configuring a user right in the SCM enter a comma delimited list of accounts. Accounts can be either local or located in Active Directory, they can ...

CCE-93383-8
Turn on Accounting for WSRM This setting turns the Accounting feature On or Off. If you enable this setting, Windows System Resource Manager (WSRM) will start accounting various usage statistics of the processes. If you disable this setting, WSRM will stop logging usage statistics of processes. ...

CCE-93165-9
Prohibit installing or uninstalling color profiles This policy setting affects the ability of users to install or uninstall color profiles. If you enable this policy setting, users will not be able to install new color profiles or uninstall previously installed color profiles. If you disable or d ...

CCE-93067-7
Allow Integrated Unblock screen to be displayed at the time of logon This policy setting lets you determine whether the integrated unblock feature will be available in the logon User Interface (UI). In order to use the integrated unblock feature your smart card must support this feature. Please c ...

CCE-94033-8
Allow Automatic Updates immediate installation Specifies whether Automatic Updates should automatically install certain updates that neither interrupt Windows services nor restart Windows. If the status is set to Enabled, Automatic Updates will immediately install these updates once they are downl ...

CCE-99762-7
This policy setting lets you opt-out of sending KMS client activation data to Microsoft automatically. Enabling this setting prevents this computer from sending data to Microsoft regarding its activation state. If you disable or do not configure this policy setting, KMS client activation data w ...

CCE-99651-2
Title: Local volumes must be formatted using NTFS. Description: The ability to set access permissions and auditing is critical to maintaining the security and proper access controls of a system. To support this, volumes must be formatted using the NTFS file system. Check Text: Run &quot;Compute ...

CCE-93361-4
Allow users to patch elevated products This policy setting allows users to patch elevated products. If you enable this policy setting, all users are permitted to install patches, even when the installation program is running with elevated system privileges. Patches are updates or upgrades that r ...

CCE-93187-3
Prohibit connection to roaming Mobile Broadband networks This policy setting prevents clients from connecting to Mobile Broadband networks when the client is registered on a roaming provider network. If this policy setting is enabled, all automatic and manual connection attempts to roamin ...

CCE-99677-7
Unnecessary services increase the attack surface of a system. Some of these services may not support required levels of authentication or encryption or may provide unauthorized access to the system. Fix: Uninstall the &quot;Peer Name Resolution Protocol&quot; feature. Start &quot;Server Manager&qu ...

CCE-93935-5
Enable use of BitLocker authentication requiring preboot keyboard input on slates This policy setting allows users to enable authentication options that require user input from the pre-boot environment even if the platform indicates lack of pre-boot input capability. The Windows on-screen touch ...

CCE-93619-5
Windows Firewall: Public: Logging: Name Use this option to specify the path and name of the file in which Windows Firewall will write its log information.

CCE-94073-4
Allow domain users to log on using biometrics This policy setting determines whether domain users can log on or elevate User Account Control (UAC) permissions using biometrics. By default, domain users cannot use biometrics to log on. If you enable this policy setting, domain users can log on to a ...

CCE-93321-8
Prevent enabling lock screen slide show Disables the lock screen slide show settings in PC Settings and prevents a slide show from playing on the lock screen. By default, users can enable a slide show that will run after they lock the machine. If you enable this setting, users will no longer ...

CCE-93112-1
Prevent indexing public folders Enable this policy to prevent indexing public folders in Microsoft Office Outlook. When this policy is disabled or not configured, the user has the option to index cached public folders in Outlook. Public folders are only indexed when using Outlook 2003 or later. The ...

CCE-93979-3
Turn off the ability to back up data files This setting lets you disable the data file backup functionality. If this setting is enabled, users cannot back up data files. If this setting is disabled or not configured, users can back up data files.

CCE-94171-6
Hyper-V Time Synchronization Service Synchronizes the system time of this virtual machine with the system time of the physical computer.

CCE-93232-7
Disallow Negotiate authentication This policy setting allows you to manage whether the Windows Remote Management (WinRM) service will not accept Negotiate authentication from a remote client. If you enable this policy setting, the WinRM service will not accept Negotiate authentication from a remot ...

CCE-93948-8
Turn on Security Center (Domain PCs only) This policy setting specifies whether Security Center is turned on or off for computers that are joined to an Active Directory domain. When Security Center is turned on, it monitors essential security settings and notifies the user when the computer might b ...

CCE-93485-1
Force automatic setup for all users This policy setting specifies whether Work Folders should be set up automatically for all users of the affected computer. If you enable this policy setting, Work Folders will be set up automatically for all users of the affected computer. This prevents u ...

CCE-99788-2
This policy setting allows an organization to prevent its devices from showing feedback questions from Microsoft. If you enable this policy setting, users will no longer see feedback notifications through the Windows Feedback app. If you disable or do not configure this policy setting, use ...

CCE-94051-0
Minimum password length This policy setting determines the least number of characters that make up a password for a user account. There are many different theories about how to determine the best password length for an organization, but perhaps 'pass phrase' is a better term than 'password.' In Mic ...

CCE-99668-6
Determines whether the Kerberos Key Distribution Center (KDC) validates every request for a session ticket against the user rights policy of the target computer. Validation of each request for a session ticket is optional because the extra step takes time and may slow network access to services. By ...

CCE-93450-5
Turn off automatic wake This policy setting turns off the option to periodically wake the computer to update information on Windows SideShow-compatible devices. If you enable this policy setting, the option to automatically wake the computer will not be available in the Windows SideShow Control Pa ...

CCE-93352-3
Disallow Digest authentication This policy setting allows you to manage whether the Windows Remote Management (WinRM) client will not use Digest authentication. If you enable this policy setting, the WinRM client will not use Digest authentication. If you disable or do not configure this policy s ...

CCE-99851-8
This policy setting limits the type of dumps that can be collected when more information is needed to troubleshoot a problem.&#8239;Dumps are only sent when the device has been configured to send optional diagnostic data. By enabling this setting, Windows Error Reporting is limited to sending kerne ...

CCE-99655-3
Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Audit logs are necessary to provide a trail of evidence in case the system or network is compromised. ...

CCE-93815-9
Configure Reliability WMI Providers This policy controls the Windows Management Instrumentation (WMI) providers Win32_ReliabilityStabilityMetrics and Win32_ReliabilityRecords. If this setting is disabled, the Reliability Monitor will not display system reliability information nor will WMI capa ...

CCE-93330-9
Set IP Stateless Autoconfiguration Limits State This policy setting allows you to configure IP Stateless Autoconfiguration Limits. If you enable or do not configure this policy setting, IP Stateless Autoconfiguration Limits will be enabled and system will limit the number of autoconfigured addre ...

CCE-93508-0
Allow BITS Peercaching This policy setting determines if the Background Intelligent Transfer Service (BITS) Peercaching feature is enabled on a specific computer. By default, the files in a BITS job are downloaded only from the origin server specified by the job's owner. If BITS Peercaching is ...

CCE-93468-7
Enable Windows NTP Server Specifies whether the Windows NTP Server is enabled. Enabling the Windows NTP Server allows your computer to service NTP requests from other machines.

CCE-93072-7
Do not use NetBIOS-based discovery for domain controller location when DNS-based discovery fails This policy setting allows you to control the domain controller (DC) location algorithm. By default, the DC location algorithm prefers DNS-based discovery if the DNS domain name is known. If DNS-based d ...

CCE-93117-0
Do not allow changes to initiator CHAP secret If enabled then do not allow the initiator CHAP secret to be changed. If disabled then the initiator CHAP secret may be changed.

CCE-94124-5
Windows Firewall: Public: Allow unicast response This option is useful if you need to control whether this computer receives unicast responses to its outgoing multicast or broadcast messages.

CCE-93664-1
Turn off Federation Service This policy setting prevents a Federation Service in Active Directory Federation Services (AD FS) from being installed or run. If you enable this policy setting, installation of a Federation Service fails. If a Federation Service has already been installed, all requests ...

CCE-94026-2
Prevent installation of removable devices This policy setting allows you to prevent Windows from installing removable devices. A device is considered removable when the driver for the device to which it is connected indicates that the device is removable. For example, a Universal Serial Bus (USB) d ...

CCE-93433-1
Prevent the usage of OneDrive for file storage This policy setting lets you prevent apps and features from working with files on OneDrive. If you enable this policy setting: * Users can?t access OneDrive from the OneDrive app and file picker. * Windows Store apps can?t access OneDrive using th ...

CCE-93335-8
Prevent device metadata retrieval from the Internet This policy setting allows you to prevent Windows from retrieving device metadata from the Internet. If you enable this policy setting, Windows does not retrieve device metadata for installed devices from the Internet. This policy setti ...

CCE-93566-8
Data Deduplication Volume Shadow Copy Service Data Deduplication VSS writer guided backup applications to back up volumes with deduplication.

CCE-93699-7
Block clean-up of unused language packs This policy setting controls whether the LPRemove task will run to clean up language packs installed on a machine but are not used by any users on that machine. If you enable this policy setting, language packs that are installed as part of the s ...

CCE-99657-9
Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Audit logs are necessary to provide a trail of evidence in case the system or network is compromised. ...

CCE-93192-3
Allow enhanced PINs for startup This policy setting allows you to configure whether or not enhanced startup PINs are used with BitLocker. Enhanced startup PINs permit the use of characters including uppercase and lowercase letters, symbols, numbers, and spaces. This policy setting is applied whe ...

CCE-93019-8
Disallow Autoplay for non-volume devices This policy setting disallows AutoPlay for MTP devices like cameras or phones. If you enable this policy setting, AutoPlay is not allowed for MTP devices like cameras or phones. If you disable or do not configure this policy setting ...

CCE-93914-0
Show sleep in the power options menu Shows or hides sleep from the power options menu. If you enable this policy setting, the sleep option will be shown in the Power Options menu (as long as it is supported by the machine's hardware). If you disable this policy setting, the sleep option will ...

CCE-93771-4
Allow remote access to the Plug and Play interface This policy setting allows you to allow or deny remote access to the Plug and Play interface. If you enable this policy setting, remote connections to the Plug and Play interface are allowed. If you disable or do not configure this p ...

CCE-99831-0
If you enable this policy, Windows spotlight features like lock screen spotlight, suggested apps in Start menu or Windows tips will no longer suggest apps and content from third-party software publishers. Users may still see suggestions and tips to make them more productive with Microsoft features a ...

CCE-93006-5
Create a pagefile This policy setting allows users to change the size of the pagefile. By making the pagefile extremely large or extremely small, an attacker could easily affect the performance of a compromised computer. When configuring a user right in the SCM enter a comma delimited list of acco ...

CCE-94017-1
Prefer Local Names Allowed Specifies whether the user has Connect and Disconnect options for the DirectAccess entry when the user clicks the Networking notification area icon. To restore the DirectAccess rules to the NRPT and resume normal DirectAccess functionality, the user clicks Connect. ...

CCE-93420-8
Allow CredSSP authentication This policy setting allows you to manage whether the Windows Remote Management (WinRM) service accepts CredSSP authentication from a remote client. If you enable this policy setting, the WinRM service will accept CredSSP authentication from a remote client. ...

CCE-93259-0
Take ownership of files or other objects This policy setting allows users to take ownership of files, folders, registry keys, processes, or threads. This user right bypasses any permissions that are in place to protect objects to give ownership to the specified user. When configuring a user right ...

CCE-93575-9
Do not allow encryption on all NTFS volumes Encryption can add to the processing overhead of filesystem operations. Enabling this setting will prevent access to and creation of encrypted files

CCE-99844-3
This policy setting allows you to configure script scanning. If you enable or do not configure this setting, script scanning will be enabled. If you disable this setting, script scanning will be disabled. Fix: (1) GPO: Computer Configuration\Administrative Templates\Windows Components\Microso ...

CCE-93918-1
Enumerate administrator accounts on elevation By default, all administrator accounts are displayed when you attempt to elevate a running application.

CCE-94070-0
Approved Installation Sites for ActiveX Controls The ActiveX Installer Service is the solution to delegate the install of per-machine ActiveX controls to a Standard User in the enterprise. The list of Approved ActiveX Install sites contains the host URL and the policy settings for each host URL. W ...

CCE-93895-1
Prioritize all digitally signed drivers equally during the driver ranking and selection process This policy setting allows you to determine how drivers signed by a Microsoft Windows Publisher certificate are ranked with drivers signed by other valid Authenticode signatures during the driver selecti ...

CCE-93379-6
Allow signature keys valid for Logon This policy setting lets you allow signature key-based certificates to be enumerated and available for logon. If you enable this policy setting then any certificates available on the smart card with a signature only key will be listed on the logon screen. If y ...

CCE-99724-7
This policy setting allows the configuration of wireless settings using Windows Connect Now (WCN). The WCN Registrar enables the discovery and configuration of devices over Ethernet (UPnP), over In-band 802.11 Wi-Fi, through the Windows Portable Device API (WPD), and via USB Flash drives. Additiona ...

CCE-93455-4
Turn on extensive logging for Active Directory Domain Services domain controllers that are running Server for NIS This policy setting allows an administrator to configure extensive logging for computers that are running Server for Network Information Service (NIS). If you enable th ...

CCE-93357-2
Windows Firewall: Private: Logging: Log dropped packets Use this option to log when Windows Firewall with Advanced Security discards an inbound packet for any reason. The log records why and when the packet was dropped. Look for entries with the word DROP in the action column of the log.

CCE-93905-8
Block launching desktop apps associated with a file. This policy setting allows you to minimize the risk involved when a packaged app launches the default app for a file. Because desktop apps run at a higher integrity level than packaged apps, there is a risk that a packaged app could compromise th ...

CCE-93633-6
Force shutdown from a remote system This policy setting allows users to shut down Windows Vista?based computers from remote locations on the network. Anyone who has been assigned this user right can cause a denial of service (DoS) condition, which would make the computer unavailable to service user ...

CCE-99800-5
This policy setting blocks applications from using the network to send notifications to update tiles, tile badges, toast, or raw notifications. This policy setting turns off the connection between Windows and the Windows Push Notification Service (WNS). This policy setting also stops applications fr ...

CCE-93076-8
Allow time invalid certificates This policy setting permits those certificates to be displayed for logon that are either expired or not yet valid. Under previous versions of Microsoft Windows, certificates were required to contain a valid time and not be expired. The certificate must still be acc ...

CCE-94022-1
Allow users to log on using biometrics This policy setting determines whether users can log on or elevate User Account Control (UAC) permissions using biometrics. By default, local users will be able to log on to the local computer, but the 'Allow domain users to log on using biometrics' policy se ...

CCE-93788-8
Apply the default account picture to all users This policy setting allows an administrator to standardize the account pictures for all users on a system to the default account picture. One application for this policy setting is to standardize the account pictures to a company logo. Note: The def ...

CCE-93668-2
Change the time zone This setting determines which users can change the time zone of the computer. This ability holds no great danger for the computer and may be useful for mobile workers. When configuring a user right in the SCM enter a comma delimited list of accounts. Accounts can be either loc ...

CCE-99857-5
This policy setting controls whether or not users can override the SHA256 security validation in the Windows Package Manager settings. Users should not have the ability to override SHA256 security validation. The recommended state for this setting is: Disabled . Fix: (1) GPO: Computer Configurati ...

CCE-99759-3
This policy setting allows you to manage the behavior of Windows SmartScreen. Windows SmartScreen helps keep PCs safer by warning users before running unrecognized programs downloaded from the Internet. Some information is sent to Microsoft about files and programs run on PCs with this feature enabl ...

CCE-94035-3
Notify user of successful smart card driver installation This policy setting allows you to control whether a confirmation message is displayed when a smart card device driver is installed. If you enable or do not configure this policy setting, a confirmation message will be displayed when a smart ...

CCE-93548-6
Turn off File History This policy setting allows you to turn off File History. If you enable this policy setting, File History cannot be activated to create regular, automatic backups. If you disable or do not configure this policy setting, File History can be activated to create regular, aut ...

CCE-93294-7
Windows Firewall: Domain: Allow unicast response This option is useful if you need to control whether this computer receives unicast responses to its outgoing multicast or broadcast messages.

CCE-93611-2
Turn off Windows Mail application Denies or allows access to the Windows Mail application. If you enable this setting, access to the Windows Mail application is denied. If you disable or do not configure this setting, access to the Windows Mail application is allowed.

CCE-93646-8
Enable NTFS pagefile encryption Encrypting the page file prevents malicious users from reading data that has been paged to disk, but also adds processing overhead for filesystem operations. Enabling this setting will cause the page files to be encrypted.

CCE-93971-0
Prevent plaintext PINs from being returned by Credential Manager This policy setting prevents plaintext PINs from being returned by Credential Manager. If you enable this policy setting, Credential Manager does not return a plaintext PIN. If you disable or do not configure this policy setting, ...

CCE-94133-6
Windows Firewall: Private: Logging: Name Use this option to specify the path and name of the file in which Windows Firewall will write its log information.

CCE-99737-9
This policy setting specifies the maximum size of the log file in kilobytes. If you enable this policy setting, you can configure the maximum log file size to be between 1 megabyte (1024 kilobytes) and 2 terabytes (2147483647 kilobytes) in kilobyte increments. If you disable or do not configure th ...

CCE-93779-7
Windows Firewall: Public: Inbound connections This setting determines the behavior for inbound connections that do not match an inbound firewall rule. The default behavior is to block connections unless there are firewall rules to allow the connection.

CCE-94013-0
Turn Off Adaptive Display Timeout (On Battery) Manages how Windows controls the setting that specifies how long a computer must be inactive before Windows turns off the computer?s display. When this policy is enabled, Windows automatically adjusts the setting based on what users do with their ke ...

CCE-93842-3
Turn off Multicast Bootstrap This setting disables PNRP protocol from advertising the computer or from searching other computers on the local subnet in the site local cloud. The Peer Name Resolution Protocol (PNRP) allows for distributed resolution of a name to an IPV6 address and port number. One ...

CCE-93579-1
Turn off legacy remote shutdown interface This policy controls the legacy remote shutdown interface (named pipe). The named pipe remote shutdown interface is needed in order to shutdown this system from a remote Windows XP or Windows Server 2003 system. If this setting is enabled, the system does ...

CCE-93877-9
Prevent indexing files in offline files cache If enabled, files on network shares made available offline are not indexed. Otherwise they are indexed. Disabled by default.

CCE-99848-4
Disabling this setting turns off search highlights in the taskbar search box and in search home. Enabling or not configuring this setting turns on search highlights in the taskbar search box and in search home. Fix: (1) GPO: Computer Configuration/Administrative Templates/Windows Components/Search/ ...

CCE-93206-1
Allow indexing of encrypted files This policy setting allows encrypted items to be indexed. If you enable this policy setting, indexing will attempt to decrypt and index the content (access restrictions will still apply). If you disable this policy setting, the search service components (including ...

CCE-93620-3
Windows Firewall: Public: Logging: Log dropped packets Use this option to log when Windows Firewall with Advanced Security discards an inbound packet for any reason. The log records why and when the packet was dropped. Look for entries with the word DROP in the action column of the log.

CCE-99813-8
This policy setting allows backup and restore of cellular text messages to Microsofts cloud services. Fix: (1) GPO: Computer Configuration\Administrative Templates\Windows Components\Messaging\Allow Message Service Cloud Sync (2) REG: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Messag ...

CCE-93063-6
Allow ECC certificates to be used for logon and authentication This policy setting allows you to control whether elliptic curve cryptography (ECC) certificates on a smart card can be used to log on to a domain. If you enable this policy setting, ECC certificates on a smart card can be used to log ...

CCE-93940-5
Turn off heap termination on corruption Disabling heap termination on corruption can allow certain legacy plug-in applications to function without terminating Explorer immediately, although Explorer may still terminate unexpectedly later.

CCE-93402-6
Turn Off Hybrid Sleep (Plugged In) Disables Hybrid Sleep. If you enable this policy setting, a hiberfile is not generated when the system transitions to sleep (Stand By). If you do not configure this policy setting, users can see and change this setting.

CCE-99826-0
This policy setting allows you to control the network connectivity state in standby on modern standby-capable systems. If you enable this policy setting, network connectivity will be maintained in standby. If you disable this policy setting, network connectivity in standby is not guaranteed. This ...

CCE-99728-8
This policy setting specifies the maximum size of the log file in kilobytes. If you enable this policy setting, you can configure the maximum log file size to be between 1 megabyte (1024 kilobytes) and 2 terabytes (2147483647 kilobytes) in kilobyte increments. If you disable or do not configure th ...

CCE-93228-5
Set the default source path for Update-Help This policy setting allows you to set the default value of the SourcePath parameter on the Update-Help cmdlet. If you enable this policy setting, the Update-Help cmdlet will use the specified value as the default value for the SourcePath parameter. Thi ...

CCE-93459-6
Turn off desktop gadgets This policy setting allows you to turn off desktop gadgets. Gadgets are small applets that display information or utilities on the desktop. If you enable this setting, desktop gadgets will be turned off. If you disable or do not configure this setting, desktop gadgets wi ...

CCE-93731-8
Prevent creation of a system restore point during device activity that would normally prompt creation of a restore point This policy setting allows you to prevent Windows from creating a system restore point during device activity that would normally prompt Windows to create a system restore point. ...

CCE-93183-2
Require a Password When a Computer Wakes (On Battery) Specifies whether or not the user is prompted for a password when the system resumes from sleep.

CCE-93299-6
Turn off shell protocol protected mode This policy setting allows you to configure the amount of functionality that the shell protocol can have. When using the full functionality of this protocol, applications can open folders and launch files. The protected mode reduces the functionality of this p ...

CCE-93460-4
Prevent restoring previous versions from backups This policy setting lets you suppress the Restore button in the previous versions property page when the user has selected a previous version of a local file, in which the previous version is stored on a backup. If you enable this policy setting, ...

CCE-94185-6
Windows Firewall: Domain: Logging: Log dropped packets Use this option to log when Windows Firewall with Advanced Security discards an inbound packet for any reason. The log records why and when the packet was dropped. Look for entries with the word DROP in the action column of the log.

CCE-93638-5
Turn Off user-installed desktop gadgets This policy setting allows you to turn off desktop gadgets that have been installed by the user. If you enable this setting, Windows will not run any user-installed gadgets. If you disable or do not configure this setting, Windows will run user-installed ga ...

CCE-93843-1
Allow members of the Everyone group to run applications that are located in the Program Files folder This setting allows members of the Everyone group to run applications that are located in (or beneath) the Program Files folder. If you enable this setting, members of the Everyone group will be ...

CCE-93691-4
Prevent automatically adding shared folders to the index Enable this policy to prevent Windows Search from automatically adding shared folders to the index. If enabled, Windows Search will not automatically add shares created on the computer to the scope of the index. If not configured or disable ...

CCE-99817-9
Allow suggested apps in Windows Ink Workspace Fix: (1) GPO: Computer Configuration\Administrative Templates\Windows Components\Windows Ink Workspace\Allow suggested apps in Windows Ink Workspace (2) REG: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\WindowsInkWorkspace!AllowSuggestedAppsInWindo ...

CCE-93878-7
Enable client-side targeting Specifies the target group name or names that should be used to receive updates from an intranet Microsoft update service. If the status is set to Enabled, the specified target group information is sent to the intranet Microsoft update service which uses it to determin ...

CCE-93998-3
Set SYSVOL share compatibility This policy setting controls whether or not the SYSVOL share created by the Net Logon service on a domain controller (DC) should support compatibility in file sharing semantics with earlier applications. When this setting is enabled, the SYSVOL share will honor fil ...

CCE-93495-0
Turn On Compatibility HTTP Listener This policy setting enables or disables an HTTP listener created for backward compatibility purposes in the Windows Remote Management (WinRM) service. When certain port 80 listeners are migrated to WinRM 2.0, the listener port number changes ...

CCE-99839-3
This policy setting determines whether Windows is allowed to download fonts and font catalog data from an online font provider. If you enable this policy setting, Windows periodically queries an online font provider to determine whether a new font catalog is available. Windows may also download fo ...

CCE-94065-0
Windows To Go Default Startup Options This policy setting controls whether the PC will boot to Windows To Go if a USB device containing a Windows To Go workspace is connected, and controls whether users can make changes using the Windows To Go Startup Options Control Panel item. If you enable th ...

CCE-93941-3
Turn off smart multi-homed name resolution Specifies that a multi-homed DNS client should optimize name resolution across networks. The setting improves performance by issuing parallel DNS, link local multicast name resolution (LLMNR) and NetBIOS over TCP/IP (NetBT) queries across all networks. In ...

CCE-93710-2
Turn off smart protocol reordering Specifies that the DNS client should prefer responses from link local name resolution protocols on non-domain networks over DNS responses when issuing queries for flat names. Examples of link local name resolution protocols include link local multicast name resolu ...

CCE-93612-0
Allow log on through Remote Desktop Services This policy setting determines which users or groups have the right to log on as a Terminal Services client. Remote desktop users require this user right. If your organization uses Remote Assistance as part of its help desk strategy, create a group and a ...

CCE-99652-0
Some protocols and services do not support required security features, such as encrypting passwords or traffic. Fix: Uninstall &quot;TFTP Client&quot; from the system. Run &quot;Programs and Features&quot;. Select &quot;Turn Windows Features on or off&quot;. De-select &quot;TFTP Client&quot;.

CCE-94176-5
Manage auditing and security log This policy setting determines which users can change the auditing options for files and directories and clear the Security log. When configuring a user right in the SCM enter a comma delimited list of accounts. Accounts can be either local or located in Active Dir ...

CCE-99772-6
This policy setting enables logging of all PowerShell script input to the Microsoft-Windows-PowerShell/Operational event log. If you enable this policy setting, Windows PowerShell will log the processing of commands, script blocks, functions, and scripts - whether invoked interactively, or through a ...

CCE-93736-7
Log on as a batch job When configuring a user right in the SCM enter a comma delimited list of accounts. Accounts can be either local or located in Active Directory, they can be groups, users, or computers.

CCE-99674-4
This policy setting allows users to have their feeds authenticated using the Basic authentication scheme over an unencrypted HTTP connection. If you enable this policy setting, the RSS Platform will authenticate to servers using the Basic authentication scheme in combination with an insecure HTTP c ...

CCE-94056-9
Windows Firewall: Domain: Display a notification Select this option to have Windows Firewall with Advanced Security display notifications to the user when a program is blocked from receiving inbound connections. Note When the Apply local firewall rules setting is configured to No, Microsoft recom ...

CCE-99785-8
Manages a Windows app's ability to share data between users who have installed the app. If you enable this policy, a Windows app can share app data with other instances of that app. Data is shared through the SharedLocal folder. This folder is available through the Windows.Storage API. If y ...

CCE-93954-6
Do not allow Sound Recorder to run Specifies whether Sound Recorder can run. Sound Recorder is a feature of Microsoft Windows Vista that can be used to record sound from an audio input device where the recorded sound is encoded and saved as an audio file. If you enable this policy setting, Sound ...

CCE-94021-3
Turn off Windows SideShow This policy setting turns off Windows SideShow. If you enable this policy setting, the Windows SideShow Control Panel will be disabled and data from Windows SideShow-compatible gadgets (applications) will not be sent to connected devices. If you disable or do not config ...

CCE-99750-2
This policy setting sets the default behavior for Autorun commands. Autorun commands are generally stored in autorun.inf files. They often launch the installation program or other routines. Prior to Windows Vista, when media containing an autorun command is inserted, the system ...

CCE-93020-6
Replace addresses in conflicts Specifies whether dynamic updates should overwrite existing resource records that contain conflicting IP addresses. This policy setting is designed for computers that register address (A) resource records in DNS zones that do not use Secure Dynamic Updates. Secure Dy ...

CCE-94154-2
Require a Password When a Computer Wakes (Plugged In) Specifies whether or not the user is prompted for a password when the system resumes from sleep.

CCE-93580-9
Maximum password age This policy setting defines how long a user can use their password before it expires. Values for this policy setting range from 0 to 999 days. If you set the value to 0, the password will never expire. The default value for this policy setting is 42 days. Because attackers can ...

CCE-93509-8
Do not adjust default option to 'Install Updates and Shut Down' in Shut Down Windows dialog box This policy setting allows you to manage whether the 'Install Updates and Shut Down' option is allowed to be the default choice in the Shut Down Windows dialog. Note that this policy setting has no impac ...

CCE-93211-1
Control Event Log behavior when the log file reaches its maximum size This policy setting controls Event Log behavior when the log file reaches its maximum size. If you enable this policy setting and a log file reaches its maximum size, new events are not written to the log and are lost. If y ...

CCE-94181-5
Windows Firewall: Block IP protocol number 41 Use this outbound rule to block IP protocol number 41.

CCE-93113-9
Set BranchCache Distributed Cache mode This policy setting specifies whether the client computer should use the Distributed Cache mode. This BranchCache mode enables a client computer to retrieve content that has been downloaded and cached by other client computers in the branch office. To access c ...

CCE-99763-5
This policy setting allows users to use tools to view the performance of different system processes, which could be abused to allow attackers to determine a system's active processes and provide insight into the potential attack surface of the computer. Countermeasure: Ensure that only the loca ...

CCE-93727-6
Allow Standby States (S1-S3) When Sleeping (On Battery) Dictates whether or not Windows is allowed to use standby states when sleeping the computer. When this policy is enabled, Windows may use standby states to sleep the computer. If this policy is disabled, the only sleep state a compute ...

CCE-93246-7
Turn On Compatibility HTTPS Listener This policy setting enables or disables an HTTPS listener created for backward compatibility purposes in the Windows Remote Management (WinRM) service. When certain port 443 listeners are migrated to WinRM 2.0, the listener port number chang ...

CCE-93958-7
Device compatibility settings Device compatibility settings.

CCE-93331-7
Return domain controller address type This policy setting detremines the type of IP address that is returned for a domain controller. The DC Locator APIs return the IP address of the DC with the other parts of information. Before the support of IPv6, the returned DC IP address was IPv4. But with th ...

CCE-93825-8
Turn off Multicast Bootstrap This setting disables PNRP protocol from advertising the computer or from searching other computers on the local subnet in the link local cloud. The Peer Name Resolution Protocol (PNRP) allows for distributed resolution of a name to an IPV6 address and port number. One ...

CCE-94096-5
Allow all trusted apps to install This policy setting allows you to manage the installation of app packages that do not originate from the Windows Store. If you enable this policy setting, you can install any trusted app package. A trusted app package is one that is signed with a certificate cha ...

CCE-93442-2
Windows Firewall: Block UDP port 3544 Use this outbound rule to block UDP port 3544.

CCE-93847-2
Disallow Kerberos authentication This policy setting allows you to manage whether the Windows Remote Management (WinRM) client will not use Kerberos authentication directly. If you enable this policy setting, the Windows Remote Management (WinRM) client will not use Kerberos authentication directl ...

CCE-93135-2
Turn off Microsoft Peer-to-Peer Networking Services This setting turns off Microsoft Peer-to-Peer Networking Services in its entirety, and will cause all dependent applications to stop working. Peer-to-Peer protocols allow for applications in the areas of RTC, collaboration, content distribution a ...

CCE-94106-2
Turn on recommended updates via Automatic Updates Specifies whether Automatic Updates will deliver both important as well as recommended updates from the Windows Update update service. When this policy is enabled, Automatic Updates will install recommended updates as well as important updates from ...

CCE-99665-2
This policy setting specifies value for Configure Windows NTP Client\NtpServer setting.The Domain Name System (DNS) name or IP address of an NTP time source. This value is in the form of &quot;dnsName,flags&quot; where flags is a hexadecimal bitmask of the flags for that host. For more information, ...

CCE-94061-9
Disallow network as backup target This policy setting allows you to manage whether backups of a machine can run to a network share or not. If you enable this policy setting, machine administrator/backup operator cannot use Windows Server Backup to run backups to a network share. If you disable or ...

CCE-93268-1
Hyper-V Heartbeat Service Monitors the state of this virtual machine by reporting a heartbeat at regular intervals. This service helps you identify running virtual machines that have stopped responding.

CCE-94008-0
Do not allow the computer to act as a BITS Peercaching server This setting specifies whether the computer will act as a BITS peercaching server. By default, when BITS peercaching is enabled, the computer acts as both a peercaching server (offering files to its peers) and a peercaching client (downl ...

CCE-94194-8
Prevent Internet Explorer security prompt for Windows Installer scripts This policy setting allows Web-based programs to install software on the computer without notifying the user. If you disable or do not configure this policy setting, by default, when a script hosted by an Internet browser tr ...

CCE-99656-1
Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Audit logs are necessary to provide a trail of evidence in case the system or network is compromised. ...

CCE-93473-7
Use automated site coverage by the DC Locator DNS SRV Records This policy setting determines the maximum retry interval allowed when applications performing periodic searches for Domain Controllers (DCs) are unable to find a DC. For example, the retry intervals may be set at 10 minutes, then 20 ...

CCE-93891-0
Subnet definitions are authoritative Turns off Windows Network Isolation's automatic discovery of private network hosts in the domain corporate environment. If you enable this policy setting, it turns off Windows Network Isolation's automatic discovery of private network hosts in the domain cor ...

CCE-93100-6
Save documents and pictures to the local PC by default This policy setting lets you select the local PC as the default save location. It does not prevent apps and users from saving files on OneDrive. If you enable this policy setting, files will be saved locally by default. Users will still b ...

CCE-94119-5
Allow Secure Boot for integrity validation This policy setting allows you to configure whether Secure Boot will be allowed as the platform integrity provider for BitLocker operating system drives. Secure Boot ensures that the PC's pre-boot environment only loads firmware that is digitally signed ...

CCE-93486-9
Prohibit rollback Prohibits Windows Installer from generating and saving the files it needs to reverse an interrupted or unsuccessful installation. This setting prevents Windows Installer from recording the original state of the system and sequence of changes it makes during installation. It also ...

CCE-99789-0
This policy setting determines whether users can access the Insider build controls in the Advanced Options for Windows Update. These controls are located under &quot;Get Insider builds,&quot; and enable users to make their devices available for downloading and installing Windows preview software. ...

CCE-93388-7
Allow signed updates from an intranet Microsoft update service location This policy setting allows you to manage whether Automatic Updates accepts updates signed by entities other than Microsoft when the update is found on an intranet Microsoft update service location. If you enable this policy s ...

CCE-93705-2
Allow certificates with no extended key usage certificate attribute This policy setting lets you allow certificates without an Extended Key Usage (EKU) set to be used for logon. In versions of Windows prior to Windows Vista, smart card certificates that are used for logon require an enhanced key u ...

CCE-93936-3
Prevent the wizard from running. By default, Add features to Windows 8 is available for all administrators. If you enable this policy setting, the wizard will not run. If you disable this policy setting or set it to Not Configured, the wizard will run.

CCE-93682-3
Allow cryptography algorithms compatible with Windows NT 4.0 This setting controls whether the Net Logon service will allow the use of older cryptography algorithms that are used in Windows NT 4.0. The cryptography algorithms used in Windows NT 4.0 and earlier are not as secure as newer algorithms ...

CCE-93451-3
Turn off Connect to a Network Projector Disables the Connect to a Network Projector wizard so that users cannot connect to a network projector. If you enable this policy, users cannot use the Connect to a Network Projector wizard to connect to a projector. If you disable this policy or do not con ...

CCE-93803-5
Delete data from devices running Microsoft firmware when a user logs off from the computer. This policy setting deletes all data stored on Windows SideShow-compatible devices (running Microsoft firmware) when a user logs off from the computer. This is a security precaution but it significantly limi ...

CCE-99754-4
This setting allows you to configure the EMET system-wide Structured Exception Handler Overwrite Protection (SEHOP) mitigation setting. This feature is designed to block exploits that use the Structured Exception Handler (SEH) overwrite technique. This protection mechanism is provided at run-time. T ...

CCE-99852-6
This policy setting removes the Spotlight collection setting in Personalization, rendering the user unable to select and subsequentyly download daily images from Microsoft to desktop. If you enable this policy, &quot;Spotlight collection&quot; will not be available as an option in Personalization se ...

CCE-93584-1
Prevent backing up to optical media (CD/DVD) This setting lets you prevent users from selecting optical media (CD/DVD) for storing backups. If this setting is enabled, users will be blocked from selecting optical media as a backup location. If this setting is disabled or not configured, users can ...

CCE-93024-8
Prohibit connection to non-domain networks when connected to domain authenticated network This policy setting prevents computers from connecting to both a domain based network and a non-domain based network at the same time. If this policy setting is enabled, the computer responds to ...

CCE-93238-4
Disallow standard users from changing the PIN or password This policy setting allows you to configure whether or not standard users are allowed to change BitLocker volume PINs, provided they are able to provide the existing PIN first. This policy setting is applied when you turn on BitLocker. ...

CCE-99658-7
To ensure secure DoD websites and DoD-signed code are properly validated, the system must trust the DoD Root Certificate Authorities (CAs). The DoD root certificates will ensure the trust chain is established for server certificates issued from the DoD CAs. Fix: Install the DoD Root CA certificate ...

CCE-99721-3
This policy setting allows you to manage whether Windows marks file attachments from Internet Explorer or Microsoft Outlook? Express with information about their zone of origin (such as restricted, Internet, intranet, or local). This policy setting requires that files be downloaded to NTFS disk part ...

CCE-93095-8
Turn off Program Compatibility Assistant This policy controls the state of the Program Compatibility Assistant in the system. The PCA monitors user initiated programs for known compatibility issues at run time. Whenever a potential issue with an application is detected, the PCA will prompt t ...

CCE-93301-0
Set PNRP cloud to resolve only This policy setting limits a node to resolving, but not publishing, names in a specific Peer Name Resolution Protocol (PNRP) cloud. This policy setting forces computers to act as clients in peer-to-peer (P2P) scenarios. For example, a client computer can detect other ...

CCE-94147-6
Set Window Scaling Heuristics State This policy setting allows you to configure Window Scaling Heuristics. Window Scaling Heuristics is an algorithm to identify connectivity and throughput problems caused by many Firewalls and other middle boxes that don't interpret Window Scaling option correctly. ...

CCE-93456-2
Allow .rdp files from unknown publishers This policy setting allows you to specify whether users can run unsigned Remote Desktop Protocol (.rdp) files and .rdp files from unknown publishers on the client computer. If you enable or do not configure this policy setting, users can run unsigned .rdp f ...

CCE-93687-2
Windows Firewall: Private: Logging: Size limit (KB) Use this option to specify the size limit of the file in which Windows Firewall will write its log information.

CCE-93772-2
Allow network unlock at startup This policy setting controls whether a BitLocker-protected computer that is connected to a trusted wired Local Area Network (LAN) and joined to a domain can create and use Network Key Protectors on TPM-enabled computers to automatically unlock the operating system dr ...

CCE-93532-0
Prompt for credentials on the client computer This policy setting determines whether a user will be prompted on the client computer to provide credentials for a remote connection to an RD Session Host server. If you enable this policy setting, a user will be prompted on the client computer-instead ...

CCE-93817-5
Turn off access to the performance center core section Removes access to the performance center control panel page. If you enable this setting, some settings within the performance control panel page will not be displayed. The administrative tools will not be affected. If you disable or do not ...

CCE-93665-8
Enforce password history This policy setting determines the number of renewed, unique passwords that have to be associated with a user account before you can reuse an old password. The value for this policy setting must be between 0 and 24 passwords. The default value for Windows Vista is 0 passwor ...

CCE-93105-5
Turn on Software Notifications This policy setting allows you to control whether users see detailed enhanced notification messages about featured software from the Microsoft Update service. Enhanced notification messages convey the value and promote the installation and use of optional software. Th ...

CCE-93336-6
Minimize the number of simultaneous connections to the Internet or a Windows Domain This policy setting prevents computers from establishing multiple simultaneous connections to either the Internet or to a Windows domain. If this policy setting is enabled, when the computer has at le ...

CCE-99854-2
This policy setting controls whether Windows attempts to connect with the OneSettings service. If you enable this policy, Windows will not attempt to connect with the OneSettings Service. If you disable or don't configure this policy setting, Windows will periodically attempt to connect with the O ...

CCE-93861-3
Prevent the computer from joining a homegroup By default, users can add their computer to a homegroup on a home network. If you enable this policy setting, a user on this computer will not be able to add this computer to a homegroup. This setting does not affect other network sharing features. I ...

CCE-99769-2
This policy setting allows you to join Microsoft MAPS. Microsoft MAPS is the online community that helps you choose how to respond to potential threats. The community also helps stop the spread of new malicious software infections. You can choose to send basic or additional information about detec ...

CCE-93345-7
Enable indexing of online delegate mailboxes Enabling this policy allows indexing of items for online delegate mailboxes on a Microsoft Exchange server. This policy affects only delegate mailboxes that are online. Microsoft Outlook 2007 allows users to cache portions of delegate mailboxes locally ( ...

CCE-93225-1
Make Family Safety control panel visible on a Domain This policy setting allows you to configure the Family Safety feature. If you enable this policy setting, the Family Safety control panel is visible on a domain joined computer. If you disable or do not configure this policy setting, the Fa ...

CCE-93541-1
Windows Firewall: Private: Logging: Log successful connections Use this option to log when Windows Firewall with Advanced Security allows an inbound connection. The log records why and when the connection was formed. Look for entries with the word ALLOW in the action column of the log.

CCE-99832-8
This policy setting lets you prevent Windows from using diagnostic data to provide tailored experiences to the user. If you enable this policy setting, Windows will not use diagnostic data from this device (this data may include browser, app and feature usage, depending on the &quot;diagnostic data ...

CCE-93212-9
Windows Firewall: Private: Outbound connections This setting determines the behavior for outbound connections that do not match an outbound firewall rule. The default behavior is to allow connections unless there are firewall rules that block the connection. Important If you set Outbound connect ...

CCE-93323-4
Prevent Windows Media DRM Internet Access Prevents Windows Media Digital Rights Management (DRM) from accessing the Internet (or intranet). When enabled, Windows Media DRM is prevented from accessing the Internet (or intranet) for license acquisition and security upgrades. When this policy is ena ...

CCE-94214-4
Remove browse dialog box for new source Prevents users from searching for installation files when they add features or components to an installed program. This setting disables the Browse button beside the 'Use feature from' list in the Windows Installer dialog box. As a result, users must select ...

CCE-94018-9
Allow Automatic Sleep with Open Network Files (On Battery) Allow Automatic Sleep with Open Network Files. If you enable this policy setting, the computer will automatically sleep when network files are open. If you disable this policy setting, the computer will not automatically sleep whe ...

CCE-93149-3
Microsoft Key Distribution Service This service is used to protect data through the Group Data Protection API. It is also used to support a number of system features including BitLocker on clustered volumes, Managed Service Accounts, and secure DNS. If this service is stopped, those features will n ...

CCE-99810-4
This policy setting allow the use of Camera devices on the machine. If you enable or do not configure this policy setting, Camera devices will be enabled. If you disable this property setting, Camera devices will be disabled. Fix: (1) GPO: Computer Configuration\Administrative Templates\Windo ...

CCE-93403-4
Prevent the display of advanced indexing options for Windows Search in the Control Panel This policy setting hides or displays the Advanced Options dialog for Search and Indexing Options in the Control Panel. If you enable this policy setting, the Advanced Options dialog for Search and Indexing ...

CCE-93305-1
Hyper-V Virtual Machine Management Service Management service for Hyper-V, provides service to run multiple virtual machines.

CCE-99823-7
Enable or disable detection for potentially unwanted applications. You can choose to block, audit, or allow when potentially unwanted software is being downloaded or attempts to install itself on your computer. Enabled: Specify the mode in the Options section: -Block: Potentially unwanted software ...

CCE-93558-5
Turn off location scripting This policy setting turns off scripting for the location feature. If you enable this policy setting, scripts for the location feature will not run. If you disable or do not configure this policy setting, all location scripts will run.

CCE-94045-2
Turn off Active Help Specifies whether active content links in trusted assistance content are rendered. By default, the Help viewer renders trusted assistance content with active elements such as ShellExecute links and Guided Help links. If you enable this policy, such links are not rendered. The ...

CCE-99703-1
This policy setting specifies the maximum size of the log file in kilobytes. If you enable this policy setting, you can configure the maximum log file size to be between 1 megabyte (1024 kilobytes) and 2 terabytes (2147483647 kilobytes) in kilobyte increments. If you disable or do not configure th ...

CCE-93501-5
Prohibit non-administrators from applying vendor signed updates This setting controls the ability of non-administrators to install updates that have been digitally signed by the application vendor. Non-administrator updates provide a mechanism for the author of an application to create digitally s ...

CCE-93140-2
Deny access to this computer from the network This policy setting prohibits users from connecting to a computer from across the network, which would allow users to access and potentially modify data remotely. In high security environments, there should be no need for remote users to access data on ...

CCE-94058-5
Prevent indexing Microsoft Office Outlook Enable this policy to prevent indexing of any Microsoft Outlook items. The default is to automatically index Outlook items. If this policy is enabled then the user's Outlook items will not be added to the index and the user will not see them in search resul ...

CCE-93109-7
Turn on economical application of administratively assigned Offline Files This policy setting allows you to turn on economical application of administratively assigned Offline Files. If you enable or do not configure this policy setting, only new files and folders in administratively assigned fold ...

CCE-93994-2
Turn off Steps Recorder This policy setting controls the state of Steps Recorder. Steps Recorder keeps a record of steps taken by the user. The data generated by Steps Recorder can be used in feedback systems such as Windows Error Reporting to help developers understand and fix problems. The dat ...

CCE-93207-9
Set Netlogon share compatibility This policy setting controls whether or not the Netlogon share created by the Net Logon service on a domain controller (DC) should support compatibility in file sharing semantics with earlier applications. If you enable this policy setting, the Netlogon share wil ...

CCE-93669-0
Windows Firewall: Private: Allow unicast response This option is useful if you need to control whether this computer receives unicast responses to its outgoing multicast or broadcast messages.

CCE-94023-9
DirectAccess Passive Mode Specifies whether NCA service runs in Passive Mode or not. Set this to Disabled to keep NCA probing actively all the time. If this setting is not configured, NCA probing is in active mode by default.

CCE-99858-3
This policy setting controls whether users can install packages from a website that is using the ms-appinstaller protocol. The ms-appinstaller protocol allows users to install an application by clicking a link on a website. The recommended state for this setting is: Disabled . Fix: (1) GPO: Compu ...

CCE-93447-1
Allow Applications to Prevent Automatic Sleep (On Battery) Allow applications and services to prevent automatic sleep. If you enable this policy setting, any application, service or device driver may prevent Windows from automatically transitioning to sleep after a period of user inactivity. ...

CCE-94036-1
Disallow standby sleep states (S1-S3) when starting from a Windows to Go workspace Specifies whether the PC can use standby sleep states (S1-S3) when starting from a Windows To Go workspace. If you enable this setting, Windows, when started from a Windows To Go workspace, can't use standby state ...

CCE-99716-3
This policy setting allows you to turn off the Autoplay feature. Autoplay begins reading from a drive as soon as you insert media in the drive. As a result, the setup file of programs and the music on audio media start immediately. Prior to Windows XP SP2, Autoplay is disabled ...

CCE-93865-4
Block Internet Explorer Web Browser This policy setting allows you to manage whether a user can run the Firefox web browser or not. This policy sets AppLocker rules to prevent users from running the Internet Explorer web browser. If you enable this setting, users will be unable to run the Intern ...

CCE-93767-2
Enable Windows NTP Client Specifies whether the Windows NTP Client is enabled. Enabling the Windows NTP Client allows your computer to synchronize its computer clock with other NTP servers. You may want to disable this service if you decide to use a third-party time provider.

CCE-99671-0
This security setting determines the maximum amount of time (in minutes) that a granted session ticket can be used to access a particular service. The setting must be greater than ten minutes and less than or equal to the setting for Maximum lifetime for user ticket. By default, this value is set to ...

CCE-93229-3
Turn off Inventory Collector This policy setting controls the state of the Inventory Collector. The Inventory Collector inventories applications, files, devices, and drivers on the system and sends the information to Microsoft. This information is used to help diagnose compatibility probl ...

CCE-93412-5
IDN mapping Specifies whether the DNS client should convert internationalized domain names (IDNs) to the Nameprep form, a canonical Unicode representation of the string. If this policy setting is enabled, IDNs are converted to the Nameprep form. If this policy setting is disabled, or if this ...

CCE-93349-9
Report when logon server was not available during user logon This policy controls whether the logged on user should be notified if the logon server could not be contacted during logon and he has been logged on using previously stored account information. If enabled, a notification popup will be di ...

CCE-93830-8
Allow unencrypted traffic This policy setting allows you to manage whether the Windows Remote Management (WinRM) service sends and receives unencrypted messages over the network. If you enable this policy setting, the WinRM client sends and receives unencrypted messages over the network. If you d ...

CCE-93282-2
Use DNS name resolution with a single-label domain name instead of NetBIOS name resolution to locate the DC This policy setting specifies whether the computers to which this setting is applied attempt DNS name resolution of a single-label domain names. By default, when a computer (or the DC Loca ...

CCE-93086-7
Allow Applications to Prevent Automatic Sleep (Plugged In) Allow applications and services to prevent automatic sleep. If you enable this policy setting, any application, service or device driver may prevent Windows from automatically transitioning to sleep after a period of user inactivity. ...

CCE-99738-7
This policy setting changes the operational behavior of the Responder network protocol driver. The Responder allows a computer to participate in Link Layer Topology Discovery requests so that it can be discovered and located on the network. It also allows a computer to participate in Quality-of-Ser ...

CCE-93171-7
Prefer link local responses over DNS when received over a network with higher precedence Specifies that responses from link local name resolution protocols received over a network interface that is higher in the binding order are preferred over DNS responses from network interfaces lower in the bin ...

CCE-93216-0
Prevent indexing e-mail attachments Enable this policy setting to prevent the indexing of the content of e-mail attachments. If enabled, indexing service components (including non-Microsoft components) are expected not to index e-mail attachments. Consider enabling this policy if you are concerned ...

CCE-94014-8
Do not allow the computer to act as a BITS Peercaching client This setting specifies whether the computer will act as a BITS peercaching client. By default, when BITS peercaching is enabled, the computer acts as both a peercaching server (offering files to its peers) and a peercaching client (downl ...

CCE-93073-5
Prevent installation of devices not described by other policy settings This policy setting allows you to prevent the installation of devices that are not specifically described by any other policy setting. If you enable this policy setting, Windows is prevented from installing, or updating the dev ...

CCE-94169-0
Allow the use of biometrics If you enable (or do not configure) this policy setting, the Windows Biometric Service will be available, and users will be able to run applications that use biometrics on Windows. If you want to enable the ability to log on with biometrics, you must also configure the ' ...

CCE-99849-2
This policy setting controls whether Windows records attempts to download configuration settings from the OneSettings service to the EventLog. If you enable this policy, Windows will record attempts to download configuration settings from the OneSettings service to the Microsoft\Windows\Privacy-Audi ...

CCE-93789-6
Windows Firewall: Domain: Logging: Name Use this option to specify the path and name of the file in which Windows Firewall will write its log information.

CCE-93380-4
Turn off shared components This policy setting controls the ability to turn off shared components. If you enable this policy setting, no packages on the system get the shared component functionality enabled by the msidbComponentAttributesShared attribute in the Component Table. If you disable ...

CCE-93621-1
Prevent users from using Windows Installer to install updates and upgrades This policy setting prevents users from using Windows Installer to install patches. If you enable this policy setting, users are prevented from using Windows Installer to install patches. Patches are updates or upgrades t ...

CCE-93852-2
Allow members of the Everyone group to run applications that are located in the Windows folder This setting allows members of the Everyone group to run applications that are located in (or beneath) the Windows folder. If you enable this setting, members of the Everyone group will be able to run ...

CCE-94112-0
Verify old and new Folder Redirection targets point to the same share before redirecting This policy setting allows you to prevent data loss when you change the target location for Folder Redirection, and the new and old targets point to the same network share, but have different network paths. ...

CCE-99814-6
This setting controls whether users can provide Microsoft accounts for authentication for applications or services. If this setting is enabled, all applications and services on the device are prevented from using Microsoft accounts for authentication. This applies both to existing users of a device ...

CCE-93754-0
Hyper-V Data Exchange Service Provides a mechanism to exchange data between the virtual machine and the operating system running on the physical computer.

CCE-93528-8
Turn on certificate propagation from smart card This policy setting allows you to manage the certificate propagation that occurs when a smart card is inserted. If you enable or do not configure this policy setting then certificate propagation will occur when you insert your smart card. If you dis ...

CCE-93167-5
Do not send a Windows error report when a generic driver is installed on a device This policy setting allows you to specify whether to send a Windows error report when a generic driver is installed on a device. If you enable this policy setting, a Windows error report is not sent when a generic dr ...

CCE-94031-2
Turn on extensive logging for Password Synchronization This policy setting allows an administrator to turn on extensive logging for Password Synchronization. If you enable this policy setting, all affected computers that are running Password Synchronization log intermediate steps for pas ...

CCE-99760-1
This policy setting allows you to configure a time limit for disconnected Remote Desktop Services sessions. You can use this policy setting to specify the maximum amount of time that a disconnected session is kept active on the server. By default, Remote Desktop Services allows users to disconn ...

CCE-93154-3
Generate security audits This policy setting determines which users or processes can generate audit records in the Security log. When configuring a user right in the SCM enter a comma delimited list of accounts. Accounts can be either local or located in Active Directory, they can be groups, user ...

CCE-93831-6
Allow administrators to override Device Installation Restriction policies This policy setting allows you to determine whether members of the Administrators group can install and update the drivers for any device, regardless of other policy settings. If you enable this policy setting, members of th ...

CCE-93639-3
Turn on root certificate propagation from smart card This policy setting allows you to manage the root certificate propagation that occurs when a smart card is inserted. If you enable or do not configure this policy setting then root certificate propagation will occur when you insert your smart ca ...

CCE-93176-6
Prevent backing up to local disks This setting lets you prevent users from selecting a local disk (internal or external) for storing backups. If this setting is enabled, the user will be blocked from selecting a local disk as a backup location. If this setting is disabled or not configured, users ...

CCE-93835-7
Turn off Windows Location Provider This policy setting turns off the Windows Location Provider feature for this computer. If you enable this policy setting, the Windows Location Provider feature will be turned off, and all programs on this computer will not be able to use the Windows Loc ...

CCE-93078-4
Turn off Windows presentation settings This policy setting turns off Windows presentation settings. If you enable this policy setting, Windows presentation settings cannot be invoked. If you disable this policy setting, Windows presentation settings can be invoked. The presentation settings icon ...

CCE-94164-1
Debug programs This policy setting determines which user accounts will have the right to attach a debugger to any process or to the kernel, which provides complete access to sensitive and critical operating system components. Developers who are debugging their own applications do not need to be ass ...

CCE-93955-3
Allow CredSSP authentication This policy setting allows you to manage whether the Windows Remote Management (WinRM) client uses CredSSP authentication. If you enable this policy setting, the WinRM client will use CredSSP authentication. If you disable or do not configure this pol ...

CCE-93857-1
Allow user name hint This policy setting lets you determine whether an optional field will be displayed during logon and elevation that allows a user to enter his or her user name or user name and domain, thereby associating a certificate with that user. If you enable this policy setting then an o ...

CCE-93021-4
Turn off Windows Mobility Center This policy setting turns off Windows Mobility Center. If you enable this policy setting, the user is unable to invoke Windows Mobility Center. The Windows Mobility Center UI is removed from all shell entry points and the .exe file does not launch it. If you disab ...

CCE-99795-7
This policy setting determines if the SMB client will allow insecure guest logons to an SMB server. If you enable this policy setting or if you do not configure this policy setting, the SMB client will allow insecure guest logons. If you disable this policy setting, the SMB client will rej ...

CCE-94199-7
Prevent AutoPlay from remembering user choices. This policy setting allows you to prevent AutoPlay from remembering user's choice of what to do when a device is connected. If you enable this policy setting, AutoPlay prompts the user to choose what to do when a device is connected. ...

CCE-93515-5
Enable file synchronization on costed networks This policy setting determines whether offline files are synchronized in the background when it could result in extra charges on cell phone or broadband plans. If you enable this setting, synchronization can occur in the background when the user's n ...

CCE-93724-3
Windows Firewall: Domain: Outbound connections This setting determines the behavior for outbound connections that do not match an outbound firewall rule. In Windows Vista, the default behavior is to allow connections unless there are firewall rules that block the connection.

CCE-93141-0
Change the system time This policy setting determines which users and groups can change the time and date on the internal clock of the computers in your environment. Users who are assigned this user right can affect the appearance of event logs. When a computer?s time setting is changed, logged eve ...

CCE-99773-4
This policy setting configures secure access to UNC paths. If you enable this policy, Windows only allows access to the specified UNC paths after fulfilling additional security requirements. Specify hardened network paths. In the name field, type a fully-qualified UNC path for each network resour ...

CCE-93234-3
Prevent memory overwrite on restart This policy setting controls computer restart performance at the risk of exposing BitLocker secrets. This policy setting is applied when you turn on BitLocker. BitLocker secrets include key material used to encrypt data. This policy setting applies only when BitL ...

CCE-93550-2
Do not allow Windows Messenger to be run Allows you to disable Windows Messenger. If you enable this setting, Windows Messenger will not run. If you disable or do not configure this setting, Windows Messenger can be used. Note: If you enable this setting, Remote Assistance also cannot use Window ...

CCE-93038-8
Determines whether a user can install and configure the Network Bridge. Important: This settings is location aware. It only applies when a computer is connected to the same DNS domain network it was connected to when the setting was refreshed on that computer. If a computer is connected to a DNS do ...

CCE-93269-9
Do not allow Windows Media Center to run Specifies whether Windows Media Center can run. If you enable this setting, Windows Media Center will not run. If you disable or do not configure this setting, Windows Media Center can be run.

CCE-99666-0
The Maximum lifetime for user ticket policy setting determines the maximum amount of time (in hours) that a user's ticket-granting ticket can be used. When a user's ticket-granting ticket expires, a new one must be requested or the existing one must be renewed. The possible values for this Group Pol ...

CCE-93683-1
Do not allow Digital Locker to run Specifies whether Digital Locker can run. Digital Locker is a dedicated download manager associated with Windows Marketplace and a feature of Windows that can be used to manage and download products acquired and stored in the user's Windows Marketplace Digital Lo ...

CCE-93813-4
Windows Firewall: Public: Apply local firewall rules This setting controls whether local administrators are allowed to create local firewall rules that apply together with firewall rules configured by Group Policy.

CCE-93354-9
Do not allow the BITS client to use Windows Branch Cache This setting affects whether the BITS client is allowed to use Windows Branch Cache. If the Windows Branch Cache component is installed and enabled on a computer, then BITS jobs on that computer can use Windows Branch Cache by default. ...

CCE-93715-1
Remote Access Management service Logs, monitors, and manages DirectAccess and VPN connections to the server.

CCE-93968-6
Turn On Desktop Background Slideshow (On Battery) Specify if Windows should enable the desktop background slideshow. If you enable this policy setting, desktop background slideshow is enabled. If you disable this policy setting, the desktop background slideshow is disabled. if you do not c ...

CCE-99653-8
Windows PowerShell 5.0 added advanced logging features which can provide additional detail when malware has been run on a system. Disabling the Windows PowerShell 2.0 mitigates against a downgrade attack that evades the Windows PowerShell 5.0 script block logging feature. Fix: Disable &quot;Window ...

CCE-93256-6
Password must meet complexity requirements This policy setting checks all new passwords to ensure that they meet basic requirements for strong passwords. When this policy is enabled, passwords must meet the following minimum requirements: - Not contain the user's account name or parts of the user's ...

CCE-94182-3
Do not display the password reveal button This policy setting allows you to configure the display of the password reveal button in password entry user experiences. If you enable this policy setting, the password reveal button will not be displayed after a user types a password in the password en ...

CCE-99764-3
This policy setting determines whether users can log on as Terminal Services clients. After the baseline member server is joined to a domain environment, there is no need to use local accounts to access the server from the network. Domain accounts can access the server for administration and end-use ...

CCE-93608-8
Remove Program Compatibility Property Page This policy controls the visibility of the Program Compatibility property page shell extension. This shell extension is visible on the property context-menu of any program shortcut or executable file. The compatibility property page displays a list of op ...

CCE-94009-8
Turn off Application Compatibility Engine This policy controls the state of the application compatibility engine in the system. The engine is part of the loader and looks through a compatibility database every time an application is started on the system. If a match for the application is found i ...

CCE-93933-0
Reset platform validation data after BitLocker recovery This policy setting allows you to control whether or not platform validation data is refreshed when Windows is started following BitLocker recovery. If you enable this policy setting, platform validation data will be refreshed when Windows ...

CCE-93661-7
Disable delete notifications on all volumes Delete notification is a feature that notifies the underlying storage device of clusters that are freed due to a file delete operation. A value of 0, the default, will enable delete notifications for all volumes. A value of 1 will disable delete notific ...

CCE-93332-5
Prevent adding user-specified locations to the All Locations menu This policy setting allows you to enable or disable the Add/Remove location options on the All Locations menu as well as any defined locations that were made by a user. When this policy is not configured, the default behavior is to ...

CCE-93790-4
Allow users to use media source while elevated This policy setting allows users to install programs from removable media during privileged installations. If you enable this policy setting, all users are permitted to install programs from removable media, such as floppy disks and CD-ROMs, even wh ...

CCE-93101-4
Do not process incoming mailslot messages used for domain controller location based on NetBIOS domain names This policy setting allows you to control the processing of incoming mailslot messages by a local domain controller (DC). Note: To locate a remote DC based on its NetBIOS (single-label) doma ...

CCE-99679-3
Improper access permissions for directory data-related files could allow unauthorized users to read, modify, or delete directory data or audit trails. Fix: Maintain the permissions on NTDS database and log files as follows: NT AUTHORITY\SYSTEM:(I)(F) BUILTIN\Administrators:(I)(F) (I) - permission ...

CCE-93692-2
Control Event Log behavior when the log file reaches its maximum size This policy setting controls Event Log behavior when the log file reaches its maximum size. If you enable this policy setting and a log file reaches its maximum size, new events are not written to the log and are lost. If y ...

CCE-93839-9
Allow the use of remote paths in file shortcut icons This policy setting determines whether remote paths can be used for file shortcut (.lnk file) icons. If you enable this policy setting, file shortcut icons are allowed to be obtained from remote paths. If you disable or do not configure thi ...

CCE-94107-0
Allow or Disallow use of the Offline Files feature Determines whether the Offline Files feature is enabled. This setting also disables the 'Enable Offline Files' option on the Offline Files tab. This prevents users from trying to change the option while a setting controls it. Offline Files saves ...

CCE-93341-6
Allow remote server management through WinRM This policy setting allows you to manage whether the Windows Remote Management (WinRM) service automatically listens on the network for requests on the HTTP transport over the default HTTP port. If you enable this policy setting, the WinRM service aut ...

CCE-99840-1
This policy setting lets you turn off cloud optimized content in all Windows experiences. If you enable this policy, Windows experiences that use the cloud optimized content client component, will instead present the default fallback content. If you disable or do not configure this policy, Windows ...

CCE-94062-7
Turn off Application Telemetry The policy controls the state of the Application Telemetry engine in the system. Application Telemetry is a mechanism that tracks anonymous usage of specific Windows system components by applications. Turning Application Telemetry off by selecting 'enable' will stop ...

CCE-93804-3
Account lockout threshold This policy setting determines the number of failed logon attempts before a lock occurs. Authorized users can lock themselves out of an account by mistyping their password or by remembering it incorrectly, or by changing their password on one computer while logged on to an ...

CCE-94195-5
Allow NetBT queries for fully qualified domain names Specifies that NetBIOS over TCP/IP (NetBT) queries are issued for fully qualified domain names. If you enable this policy setting, NetBT queries will be issued for multi-label and fully qualified domain names such as 'www.example.com' in addi ...

CCE-93398-6
Disallow locally attached storage as backup target This policy setting allows you to manage whether backups of a machine can run to locally attached storage or not. If you enable this policy setting, machine administrator/backup operator cannot use Windows Server Backup to run backups to a locally ...

CCE-99799-9
Determines whether administrators can enable and configure the Internet Connection Sharing (ICS) feature of an Internet connection and if the ICS service can run on the computer. ICS lets administrators configure their system as an Internet gateway for a small network and provides network services, ...

CCE-93025-5
Primary DNS Suffix Devolution Determines whether the DNS client performs primary DNS suffix devolution in a name resolution process. When a user submits a query for a single-label name, such as 'example', a local DNS client attaches a suffix, such as 'microsoft.com', resulting in the query 'exampl ...

CCE-94075-9
Automatic Maintenance WakeUp Policy This policy setting allows you to configure Automatic Maintenance wake up policy. The maintenance wakeup policy specifies if Automatic Maintenance should make a wake request to the OS for the daily scheduled maintenance. Note, that if the OS power wa ...

CCE-93781-3
Windows Firewall: Public: Apply local connection security rules This setting controls whether local administrators are allowed to create connection security rules that apply together with connection security rules configured by Group Policy.

CCE-94040-3
Bypass traverse checking This policy setting allows users who do not have the Traverse Folder access permission to pass through folders when they browse an object path in the NTFS file system or the registry. This user right does not allow users to list the contents of a folder. When configuring a ...

CCE-93924-9
Show hibernate in the power options menu Shows or hides hibernate from the power options menu. If you enable this policy setting, the hibernate option will be shown in the Power Options menu (as long as it is supported by the machine's hardware). If you disable this policy setting, the hiber ...

CCE-93359-8
Windows Firewall: Public: Logging: Size limit (KB) Use this option to specify the size limit of the file in which Windows Firewall will write its log information.

CCE-94015-5
Set PNRP cloud to resolve only This policy setting limits a node to resolving, but not publishing, names in a specific Peer Name Resolution Protocol (PNRP) cloud. This policy setting forces computers to act as clients in peer-to-peer (P2P) scenarios. For example, a client computer can detect other ...

CCE-93577-5
Prohibit removal of updates This setting controls the ability for users or administrators to remove Windows Installer based updates. This setting should be used if you need to maintain a tight control over updates. One example is a lockdown environment where you want to ensure that updates once i ...

CCE-93324-2
Prevent enabling lock screen camera Disables the lock screen camera toggle switch in PC Settings and prevents a camera from being invoked on the lock screen. By default, users can enable invocation of an available camera on the lock screen. If you enable this setting, users will no longer be ...

CCE-99842-7
This policy enables the automatic learning component of input personalization that includes speech, inking, and typing. Automatic learning enables the collection of speech and handwriting patterns, typing history, contacts, and recent calendar information. It is required for the use of Cortana. ...

CCE-94211-0
Create global objects This policy setting determines whether users can create global objects that are available to all sessions. Users can still create objects that are specific to their own session if they do not have this user right. Users who can create global objects could affect processes that ...

CCE-93204-6
Remote Desktop Management Management Service for Remote Desktop Services

CCE-93106-3
Display information about previous logons during user logon This policy setting controls whether or not the system displays information about previous logons and logon failures to the user. For local user accounts and domain user accounts in Microsoft Windows Server 2008 functional level domains, ...

CCE-93805-0
Windows Firewall: Domain: Inbound connections This setting determines the behavior for inbound connections that do not match an inbound firewall rule. The default behavior is to block connections unless there are firewall rules to allow the connection.

CCE-93302-8
Turn on BranchCache This policy setting specifies whether BranchCache is enabled on the client computer. BranchCache reduces the utilization of the wide area network (WAN) links connecting branch offices to the data center or headquarters and increases access speeds for content that has already bee ...

CCE-94148-4
Always use automatic language detection when indexing content and properties This policy setting determines when Windows uses automatic language detection results, and when it relies on indexing history. If you enable this policy setting, Windows will always use automatic language detection to inde ...

CCE-93688-0
Enable / disable TXF deprecated features TXF deprecated features included savepoints, secondary RM, miniversion and roll forward. Please enable it if you want to use the APIs.

CCE-93181-6
Minimum password age This policy setting determines the number of days that you must use a password before you can change it. The range of values for this policy setting is between 1 and 999 days. (You may also set the value to 0 to allow immediate password changes.) The default value for this sett ...

CCE-93707-8
Do not allow manual configuration of iSNS servers If enabled then new iSNS servers may not be added and thus new targets discovered via those iSNS servers; existing iSNS servers may not be removed. If disabled then new iSNS servers may be added and thus new targets discovered via those iSNS servers ...

CCE-93457-0
Don't search the web or display web results in Search This policy setting allows you to control whether or not Search can perform queries on the web, and if the web results are displayed in Search. If you enable this policy setting, queries won't be performed on the web and web results won't be ...

CCE-93128-7
DS Role Server This service hosts the DS Role Server used for DC promotion, demotion, and cloning. If this service is disabled, these operations will fail.

CCE-93083-4
Allow users to browse for source while elevated This policy setting allows users to search for installation files during privileged installations. If you enable this policy setting, the Browse button in the 'Use feature from' dialog box is enabled. As a result, users can search for installation ...

CCE-93466-1
Enforce upgrade component rules This setting causes the Windows Installer to enforce strict rules for component upgrades - setting this may cause some updates to fail. If you enable this policy setting strict upgrade rules will be enforced by the Windows Installer. Upgrades can fail if they attemp ...

CCE-93368-9
Turn off Multicast Bootstrap This setting disables PNRP protocol from advertising the computer or from searching other computers on the local subnet in the global cloud. The Peer Name Resolution Protocol (PNRP) allows for distributed resolution of a name to an IPV6 address and port number. One of ...

CCE-93431-5
Don't search the web or display web results in Search over metered connections This policy setting allows you to control whether or not Search can perform queries on the web over metered connections, and if the web results are displayed in Search. If you enable this policy setting, queries won't ...

CCE-93248-3
Block launching desktop apps associated with a protocol This policy setting allows you to minimize the risk involved when a packaged app launches the default app for a protocol. Because desktop apps run at a higher integrity level than packaged apps, there is a risk that a protocol launched by a pa ...

CCE-94081-7
Allow log on locally This policy setting determines which users can interactively log on to computers in your environment. Logons that are initiated by pressing the CTRL+ALT+DEL key sequence on the client computer keyboard require this user right. Users who attempt to log on through Terminal Servic ...

CCE-99855-9
This policy setting controls whether user have access to the Windows Package Manager. Windows Package Manager is a package manager solution that consists of a command line tool and set of services for installing applications on Microsoft Windows Server 2019 (or newer). The recommended state for thi ...

CCE-93982-7
Disallow Kerberos authentication This policy setting allows you to manage whether the Windows Remote Management (WinRM) service will not accept Kerberos credentials over the network. If you enable this policy setting, the WinRM service will not accept Kerberos credentials over the network. If you ...

CCE-93333-3
Specify dynamic registration of the DC Locator DNS Records If you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.

CCE-93235-0
Windows Firewall: Domain: Apply local connection security rules This setting controls whether local administrators are allowed to create connection security rules that apply together with connection security rules configured by Group Policy.

CCE-99659-5
To ensure users do not experience denial of service when performing certificate-based authentication to DoD websites due to the system chaining to a root other than DoD Root CAs, the DoD Interoperability Root CA cross-certificates must be installed in the Untrusted Certificate Store. This requiremen ...

CCE-93092-5
Turn on the Windows to NIS password synchronization for users that have been migrated to Active Directory This policy setting allows an administrator to turn on the Windows to Network Information Service (NIS) password synchronization for UNIX-based user accounts that have been migrated to Active D ...

CCE-93346-5
Allow user control over installs This policy setting permits users to change installation options that typically are available only to system administrators. If you enable this policy setting, some of the security features of Windows Installer are bypassed. It permits installations to complete t ...

CCE-93640-1
Turn off PNRP cloud creation This policy setting enables or disables PNRP cloud creation. PNRP is a distributed name resolution protocol allowing Internet hosts to publish peer names with a corresponding Internet Protocol version 6 (IPv6) address. Other hosts can then resolve the name, retrieve th ...

CCE-94192-2
Windows Firewall: Private: Inbound connections This setting determines the behavior for inbound connections that do not match an inbound firewall rule. The default behavior is to block connections unless there are firewall rules to allow the connection.

CCE-93773-0
Prevent changing lock screen image Prevents users from changing the background image shown when the machine is locked. By default, users can change the background image shown when the machine is locked. If you enable this setting, the user will not be able to change their lock screen image, a ...

CCE-99833-6
This policy setting lets you turn off all Windows Spotlight features at once. If you enable this policy setting, Windows spotlight on lock screen, Windows tips, Microsoft consumer features and other related features will be turned off. You should enable this policy setting if your goal is to minimi ...

CCE-99735-3
This policy setting prohibits access to Windows Connect Now (WCN) wizards. If you enable this policy setting, the wizards are turned off and users have no access to any of the wizard tasks. All the configuration related tasks, including Set up a wireless router or access point and Add a wireless de ...

CCE-93840-7
Do not connect to any Windows Update Internet locations Even when Windows Update is configured to receive updates from an intranet update service, it will periodically retrieve information from the public Windows Update service to enable future connections to Windows Update, and other services like ...

CCE-93030-5
Windows Firewall: Public: Outbound connections This setting determines the behavior for outbound connections that do not match an outbound firewall rule. The default behavior is to allow connections unless there are firewall rules that block the connection. Important If you set Outbound connecti ...

CCE-93208-7
Turn off location This policy setting turns off the location feature for this computer. If you enable this policy setting, the location feature will be turned off, and all programs on this computer will not be able to use location information from the location feature. If you disa ...

CCE-99748-6
This policy setting changes the operational behavior of the Mapper I/O network protocol driver. LLTDIO allows a computer to discover the topology of a network it's connected to. It also allows a computer to initiate Quality-of-Service requests such as bandwidth estimation and network health analysi ...

CCE-93163-4
Increase a process working set This privilege determines which user accounts can increase or decrease the size of a process?s working set. The working set of a process is the set of memory pages currently visible to the process in physical RAM memory. These pages are resident and available for an a ...

CCE-93261-6
Deny write access to fixed drives not protected by BitLocker This policy setting determines whether BitLocker protection is required for fixed data drives to be writable on a computer. This policy setting is applied when you turn on BitLocker. If you enable this policy setting, all fixed data dr ...

CCE-93065-1
Turn off tracking of last play time of games in the Games folder Tracks the last play time of games in the Games folder. If you enable this setting the last played time of games will not be recorded in Games folder. This setting only affects the Games folder. If you disable or do not configure t ...

CCE-99811-2
This policy setting allows you to require a pin for pairing. If you set this to Never, a pin isnt required for pairing. If you set this to First Time, the pairing ceremony for new devices will always require a PIN. If you set this to Always, all pairings will require PIN. Fix: (1) GPO: Comput ...

CCE-93799-5
Back up log automatically when full This policy setting controls Event Log behavior when the log file reaches its maximum size and takes effect only if the 'Retain old events' policy setting is enabled. If you enable this policy setting and the 'Retain old events' policy setting is enabled, the ...

CCE-93960-3
Turn on the Ability for Applications to Prevent Sleep Transitions (On Battery) Enables applications and services to prevent the system from sleeping. If you enable this policy setting, an application or service may prevent the system from sleeping (Hybrid Sleep, Stand By, or Hibernate). If you di ...

CCE-93087-5
Turn off the Store application Denies or allows access to the Store application. If you enable this setting, access to the Store application is denied. Access to the Store is required for installing app updates. If you disable or don't configure this setting, access to the Store application i ...

CCE-93986-8
Register DNS records with connection-specific DNS suffix Warning: Enabling of this group setting is applied to all the network connections of multihomed computers to which this setting is applied. If this setting is not configured, it is not applied to any computers, and computers use their lo ...

CCE-93888-6
Enable indexing uncached Exchange folders Enabling this policy allows indexing of mail items on a Microsoft Exchange server when Microsoft Outlook is not running in cached mode. The default behavior for search is to not index uncached Exchange folders. Disabling this policy will block any indexing ...

CCE-93074-3
Turn off restore functionality This setting lets you disable file restore functionality. If this setting is enabled, the file restore program is disabled. If this setting is disabled or not configured, the file restore program is enabled and users can restore files.

CCE-93390-3
Hide previous versions list for remote files This policy setting lets you hide the list of previous versions of files that are on file shares. The previous versions come from the on-disk restore points on the file share. If you enable this policy setting, users cannot list or restore previous ve ...

CCE-93853-0
Turn off game updates Manages download of game update information from Windows Metadata Services. If you enable this setting, game update information will not be downloaded. If you disable or do not configure this setting, game update information will be downloaded from Windows Metadata Services ...

CCE-93666-6
Windows Firewall: Domain: Apply local firewall rules This setting controls whether local administrators are allowed to create local firewall rules that apply together with firewall rules configured by Group Policy.

CCE-94024-7
Disallow optical media as backup target This policy setting allows you to manage whether backups of a machine can run to an optical media or not. If you enable this policy setting, machine administrator/backup operator cannot use Windows Server Backup to run backups to an optical media. If you di ...

CCE-93568-4
Remove computer from docking station This policy setting allows the user of a portable computer to click Eject PC on the Start menu to undock the computer. When configuring a user right in the SCM enter a comma delimited list of accounts. Accounts can be either local or located in Active Directory ...

CCE-99859-1
This policy setting controls whether users can push Apps to the device from the Microsoft Store App running on other devices or the web. In a high security managed environment, application installations should be managed centrally by IT staff, not by end users. The recommended state for this setti ...

CCE-93337-4
Disable password strength validation for Peer Grouping By default, when a Peer Group is created that allows for password-authentication (or the password for such a Group is changed), Peer Grouping validates that the password meets the password complexity requirements for the local system. Thus, it ...

CCE-93239-2
Modify firmware environment values This policy setting allows users to configure the system-wide environment variables that affect hardware configuration. This information is typically stored in the Last Known Good Configuration. Modification of these values and could lead to a hardware failure tha ...

CCE-93194-9
Disable power management in connected standby mode This policy setting specifies that power management is disabled when the machine enters connected standby mode. If this policy setting is enabled, Windows Connection Manager does not manage adapter radios to reduce power consumption when ...

CCE-94037-9
Allow hibernate (S4) when starting from a Windows To Go workspace Specifies whether the PC can use the hibernation sleep state (S4) when started from a Windows To Go workspace. If you enable this setting, Windows, when started from a Windows To Go workspace, can hibernate the PC. If you disab ...

CCE-93720-1
Add workstations to domain This policy setting specifies which users can add computer workstations to a specific domain. For this policy setting to take effect, it must be assigned to the user as part of the Default Domain Controller Policy for the domain. A user who has been assigned this right ca ...

CCE-93119-6
Prevent clients from querying the index remotely If enabled, clients will be unable to query this computer's index remotely. Thus, when they are browsing network shares that are stored on this computer, they will not search them using the index. If disabled, client search requests will use this co ...

CCE-93644-3
Turn off Data Execution Prevention for Explorer Disabling data execution prevention can allow certain legacy plug-in applications to function without terminating Explorer.

CCE-93315-0
Enable throttling for online mail indexing When using Microsoft Office Outlook in online mode, you can enable this policy to control how fast online mail is indexed on a Microsoft Exchange server. The lower you set this policy, the lower the burden will be on the corresponding Microsoft Exchange se ...

CCE-93679-9
Do not allow passwords to be saved This policy setting helps prevent Terminal Services clients from saving passwords on a computer. Note If this policy setting was previously configured as Disabled or Not configured, any previously saved passwords will be deleted the first time a Terminal Service ...

CCE-99650-4
Title: Local volumes must be formatted using NTFS. Description: The ability to set access permissions and auditing is critical to maintaining the security and proper access controls of a system. To support this, volumes must be formatted using the NTFS file system. Check Text: Run &quot;Compute ...

CCE-93867-0
Do not allow connections without IPSec If enabled then only those connections that are configured for IPSec may be established. If disabled then connections that are configured for IPSec or connections not configured for IPSec may be established.

CCE-93418-2
Configure use of smart cards on fixed data drives This policy setting allows you to specify whether smart cards can be used to authenticate user access to the BitLocker-protected fixed data drives on a computer. If you enable this policy setting smart cards can be used to authenticate user acces ...

CCE-93769-8
Increase scheduling priority This policy setting determines whether users can increase the base priority class of a process. (It is not a privileged operation to increase relative priority within a priority class.) This user right is not required by administrative tools that are supplied with the o ...

CCE-99770-0
Specifies whether this computer will receive security updates and other important downloads through the Windows automatic updating service. Note: This policy does not apply to Windows RT. This setting lets you specify whether automatic updates are enabled on this computer. If the service is enable ...

CCE-99815-3
Enable or disable Microsoft Defender Exploit Guard network protection to prevent employees from using any application to access dangerous domains that may host phishing scams, exploit-hosting sites, and other malicious content on the Internet. Enabled: Specify the mode in the Options section: -Blo ...

CCE-94041-1
Prevent restoring local previous versions This policy setting lets you suppress the Restore button in the previous versions property page when the user has selected a previous version of a local file. If you enable this policy setting, the Restore button is disabled when the user selects a previ ...

CCE-99672-8
Many security services, especially authentication, rely on an accurate computer clock to perform their jobs. You should ensure computer time is accurate and that all servers in your organization use the same time source. The Windows Server 2003 W32Time service provides time synchronization for Windo ...

CCE-93529-6
Automatically workplace join client computers This setting lets you configure how domain joined client computers become workplace joined with domain users at your organization. If this setting is enabled, domain-joined client computers will automatically become workplace-joined upon domain user ...

CCE-93889-4
Try Next Closest Site The Domain Controller Locator (DC Locator) service is used by clients to find domain controllers for their Active Directory domain. The default behavior for DC Locator is to find a DC in the same site. If none are found in the same site, a DC in another site, which might be se ...

CCE-93079-2
Turn off the offer to update to the latest version of Windows Enables or disables the Store offer to update to the latest version of Windows. If you enable this setting, the Store application will not offer updates to the latest version of Windows. If you disable or do not configure this sett ...

CCE-93952-0
Update Top Level Domain Zones Specifies whether the computers to which this setting is applied may send dynamic updates to the zones named with a single label name, also known as top-level domain zones, for example, 'com'. If this setting is not configured, it is not applied to any computers, a ...

CCE-93386-1
Turn off PNRP cloud creation This policy setting enables or disables PNRP cloud creation. PNRP is a distributed name resolution protocol allowing Internet hosts to publish peer names with a corresponding Internet Protocol version 6 (IPv6) address. Other hosts can then resolve the name, retrieve th ...

CCE-93680-7
Turn off the communities features Windows Mail will not check your newsgroup servers for Communities support.

CCE-93022-2
Prevent access to 16-bit applications Specifies whether to prevent the MS-DOS subsystem (ntvdm.exe) from running on this computer. This setting affects the launching of 16-bit applications in the operating system. By default, the MS-DOS subsystem runs for all users on this computer. If the status ...

CCE-93351-5
Prevent indexing when running on battery power to conserve energy If enabled, the indexer pauses whenever the computer is running on battery. If disabled, the indexing follows the default behavior. Default is disabled.

CCE-93120-4
Allow Microsoft accounts to be optional This policy setting lets you control whether Microsoft accounts are optional for Windows Store apps that require an account to sign in. This policy only affects Windows Store apps that support it. If you enable this policy setting, Windows Store apps that ...

CCE-93297-0
Show lock in the user tile menu Shows or hides lock from the user tile menu. If you enable this policy setting, the lock option will be shown in the User Tile menu. If you disable this policy setting, the lock option will never be shown in the User Tile menu. If you do not configure this po ...

CCE-94187-2
Shut down the system This policy setting determines which users who are logged on locally to the computers in your environment can shut down the operating system with the Shut Down command. Misuse of this user right can result in a denial of service condition. When configuring a user right in the ...

CCE-99761-9
This policy setting allows you to specify the maximum amount of time that an active Remote Desktop Services session can be idle (without user input) before it is automatically disconnected. If you enable this policy setting, you must select the desired time limit in the Idle session limit drop- ...

CCE-93360-6
Windows Firewall: Public: Logging: Log successful connections Use this option to log when Windows Firewall with Advanced Security allows an inbound connection. The log records why and when the connection was formed. Look for entries with the word ALLOW in the action column of the log.

CCE-93538-7
Back up log automatically when full This policy setting controls Event Log behavior when the log file reaches its maximum size and takes effect only if the 'Retain old events' policy setting is enabled. If you enable this policy setting and the 'Retain old events' policy setting is enabled, the ...

CCE-93307-7
Synchronize directory service data This security setting determines which users and groups have the authority to synchronize all directory service data.

CCE-93601-3
Allow unencrypted traffic This policy setting allows you to manage whether the Windows Remote Management (WinRM) client sends and receives unencrypted messages over the network. If you enable this policy setting, the WinRM client sends and receives unencrypted messages over the network. If you di ...

CCE-93405-9
Prevent backing up to network location This setting lets you prevent users from selecting a network location for storing backups. If this setting is enabled, users will be blocked from selecting a network location as a backup location. If this setting is disabled or not configured, users can sele ...

CCE-93044-6
Prevent adding UNC locations to index from Control Panel Enabling this policy prevents users from adding UNC locations to the index from the Search and Indexing Options in Control Panel. Any UNC locations that have already been added to the index by the user will not be removed. When this policy ...

CCE-94010-6
Dynamic Update Determines if dynamic update is enabled. If you enable this setting, the computers to which this setting is applied may use dynamic DNS registration on each of their network connections, depending on the configuration of each individual network connection. For a dynamic DNS registr ...

CCE-93943-9
Filter duplicate logon certificates This policy settings lets you configure if all your valid logon certificates are displayed. During the certificate renewal period, a user can have multiple valid logon certificates issued from the same certificate template. This can cause confusion as to which ...

CCE-99819-5
Prevent users from making changes to the Exploit protection settings area in Windows Security. Enabled: Local users can not make changes in the Exploit protection settings area. Disabled: Local users are allowed to make changes in the Exploit protection settings area. Not configured: Same as D ...

CCE-93747-4
Windows Firewall: Private: Display a notification Select this option to have Windows Firewall with Advanced Security display notifications to the user when a program is blocked from receiving inbound connections. Note When the Apply local firewall rules setting is configured to No, Microsoft reco ...

CCE-94165-8
Control Event Log behavior when the log file reaches its maximum size This policy setting controls Event Log behavior when the log file reaches its maximum size. If you enable this policy setting and a log file reaches its maximum size, new events are not written to the log and are lost. If y ...

CCE-93164-2
Windows Firewall: Domain: Logging: Size limit (KB) Use this option to specify the size limit of the file in which Windows Firewall will write its log information.

CCE-93262-4
Configure use of smart cards on removable data drives This policy setting specifies whether a password is required to unlock BitLocker-protected removable data drives. If you choose to allow use of a password, you can require a password to be used, enforce complexity requirements, and configure a m ...

CCE-99796-5
This policy setting determines whether enhanced anti-spoofing is configured for devices which support it. If you do not configure this policy setting, users will be able to choose whether or not to use enhanced anti-spoofing on supported devices. If you enable this policy setting, Windows ...

CCE-93969-4
Reverse the subject name stored in a certificate when displaying This policy setting lets you reverse the subject name from how it is stored in the certificate when displaying it during logon. By default the user principal name (UPN) is displayed in addition to the common name to help ...

CCE-93671-6
Windows Firewall: Private: Apply local firewall rules This setting controls whether local administrators are allowed to create local firewall rules that apply together with firewall rules configured by Group Policy.

CCE-94019-7
Turn On Desktop Background Slideshow (Plugged In) Specify if Windows should enable the desktop background slideshow. If you enable this policy setting, desktop background slideshow is enabled. If you disable this policy setting, the desktop background slideshow is disabled. if you do not c ...

CCE-93320-0
Turn on the Ability for Applications to Prevent Sleep Transitions (Plugged In) Enables applications and services to prevent the system from sleeping. If you enable this policy setting, an application or service may prevent the system from sleeping (Hybrid Sleep, Stand By, or Hibernate). If you di ...

CCE-93573-4
Impersonate a client after authentication The policy setting allows programs that run on behalf of a user to impersonate that user (or another specified account) so that they can act on behalf of the user. If this user right is required for this kind of impersonation, an unauthorized user will not ...

CCE-94215-1
Profile single process This policy setting determines which users can use tools to monitor the performance of non-system processes. Typically, you do not need to configure this user right to use the Microsoft Management Console (MMC) Performance snap-in. However, you do need this user right if Syst ...

CCE-93475-2
Turn off access to the solutions to performance problems section Removes access to the performance center control panel solutions to performance problems. If you enable this setting, the solutions and issue section within the performance control panel page will not be displayed. The administrative ...

CCE-93377-0
Use DNS name resolution when a single-label domain name is used, by appending different registered DNS suffixes, if the AllowSingleLabelDnsDomain setting is not enabled. This policy setting specifies whether the computers to which this setting is applied attempts DNS name resolution of single-label ...

CCE-93102-2
Disallow WinRM from storing RunAs credentials This policy setting allows you to manage whether the Windows Remote Management (WinRM) service will not allow RunAs credentials to be stored for any plug-ins. If you enable this policy setting, the WinRM service will not allow the RunAsUser or RunAsP ...

CCE-93488-5
Turn off the ability to create a system image This setting lets you disable the creation of system images. If this setting is enabled, users cannot create system images. If this setting is disabled or not configured, users can create system images.

CCE-99676-9
Hides the Preview Pane in File Explorer. If you enable this policy setting, the Preview Pane in File Explorer is hidden and cannot be turned on by the user. If you disable, or do not configure this setting, the Preview Pane is hidden by default and can be displayed by the user. Fix: (1) GPO: ...

CCE-93836-5
Enable enforcement of Executable Rules This setting allows you to enable enforcement of AppLocker Executable Rules. If you enable this setting, the AppLocker Executable Rules are enforced. If you disable or do not configure this setting, the AppLocker Executable Rules are not enforced.

CCE-99787-4
This policy setting turns off experiences that help consumers make the most of their devices and Microsoft account. If you enable this policy setting, users will no longer see personalized recommendations from Microsoft and notifications about their Microsoft account. If you disable or do ...

CCE-99850-0
This policy setting controls whether additional diagnostic logs are collected when more information is needed to troubleshoot a problem on the device. Diagnostic logs are only sent when the device has been configured to send optional diagnostic data. By enabling this policy setting, diagnostic logs ...

CCE-93453-9
Turn Off Adaptive Display Timeout (Plugged In) Manages how Windows controls the setting that specifies how long a computer must be inactive before Windows turns off the computer?s display. When this policy is enabled, Windows automatically adjusts the setting based on what users do with their ke ...

CCE-93684-9
Prevent customization of indexed locations in Control Panel If enabled, Search and Indexing Options in Control Panel does not allow opening the Modify Locations dialog. Otherwise it can be opened. Disabled by default.

CCE-93586-6
Allow non-administrators to receive update notifications This policy setting allows you to control whether non-administrative users will receive update notifications based on the 'Configure Automatic Updates' policy setting. If you enable this policy setting, Windows Automatic Update and Mic ...

CCE-94183-1
Do not sync on metered connections Prevent syncing to and from this PC when on metered Internet connections. This turns off and disables 'sync your settings on metered connections' switch on the 'sync your settings' page in PC Settings. If you enable this policy setting, syncing on metered conn ...

CCE-93462-0
Turn off creation of System Restore Checkpoints System Restore enables users, in the event of a problem, to restore their computers to a previous state without losing personal data files. By default, the Windows Installer automatically creates a System Restore checkpoint each time an application is ...

CCE-99765-0
This security setting is used by Credential Manager during Backup and Restore. No accounts should have this user right, as it is only assigned to Winlogon. Users' saved credentials might be compromised if this user right is assigned to other entities. Countermeasure: Configure this user right s ...

CCE-93364-8
Save copies of transform files in a secure location on workstation This policy setting saves copies of transform files in a secure location on the local computer. Transform files consist of instructions to modify or customize a program during installation. If you enable this policy setting, t ...

CCE-93146-9
Allow Standby States (S1-S3) When Sleeping (Plugged In) Dictates whether or not Windows is allowed to use standby states when sleeping the computer. When this policy is enabled, Windows may use standby states to sleep the computer. If this policy is disabled, the only sleep state a compute ...

CCE-93827-4
Allow DNS Suffix Appending to Unqualified Multi-Label Name Queries Specifies whether the computers to which this setting is applied may attach suffixes to an unqualified multi-label name before sending subsequent DNS queries, if the original name query fails. A name containing dots, but not dot-te ...

CCE-93560-1
Windows Internet Name Service (WINS) Windows Internet Name Service (WINS) enables NetBIOS name resolution. The presence of the WINS server(s) is crucial for locating the network resources identified by using NetBIOS names. WINS servers are required unless all domains have been migrated to Active Di ...

CCE-93507-2
Prevent restoring remote previous versions This setting lets you suppress the Restore button in the previous versions property page when the user has selected a previous version of a file on a file share. If you enable this policy setting, the Restore button is disabled when the user selects a p ...

CCE-93231-9
Enable Automatic Hosted Cache Discovery by Service Connection Point This policy setting specifies whether client computers should attempt the automatic configuration of hosted cache mode by searching for hosted cache servers publishing service connection points that are associated with the client's ...

CCE-99841-9
Enable or disable file hash computation feature. Enabled: When this feature is enabled Microsoft Defender will compute hash value for files it scans. Disabled: File hash value is not computed Not configured: Same as Disabled. Fix: (1) GPO: Computer Configuration\Administrative Templates\Win ...

CCE-93035-4
Windows Firewall: Public: Display a notification Select this option to have Windows Firewall with Advanced Security display notifications to the user when a program is blocked from receiving inbound connections. Note When the Apply local firewall rules setting is configured to No, Microsoft recom ...

CCE-94063-5
Back up log automatically when full This policy setting controls Event Log behavior when the log file reaches its maximum size and takes effect only if the 'Retain old events' policy setting is enabled. If you enable this policy setting and the 'Retain old events' policy setting is enabled, the ...

CCE-93168-3
Allow deployment operations in special profiles This policy setting allows you to manage the deployment operations of app packages when the user is logged in under special profiles. Deployment operation refers to adding, registering, staging, updating or removing an app package. Special profi ...

CCE-99667-8
This policy setting determines whether the operating system stores passwords in a way that uses reversible encryption, which provides support for application protocols that require knowledge of the users password for authentication purposes. Passwords that are stored with reversible encryption are e ...

CCE-93849-8
Allow members of the local Administrators group to run all applications This setting allows members of the local Administrators group to run all applications on computers, regardless of their location. If you enable this setting, members of the Administrators group will be able to run applicatio ...

CCE-99865-8
This policy setting determines whether Redirection Guard is enabled for the print spooler. Redirection Guard can prevent file redirections from being used within the print spooler. The recommended state for this setting is: Enabled: Redirection Guard Enabled Fix: (1) GPO: Computer Configuration\Pol ...

CCE-93147-7
Network security: Do not store LAN Manager hash value on next password change This policy setting determines whether the LAN Manager (LM) hash value for the new password is stored when the password is changed. The LM hash is relatively weak and prone to attack compared to the cryptographically stro ...

CCE-99702-3
This policy setting determines whether an anonymous user can request security identifier (SID) attributes for another user, or use a SID to obtain its corresponding user name. Disable this policy setting to prevent unauthenticated users from obtaining user names that are associated with their respec ...

CCE-93148-5
Microsoft network server: Disconnect clients when logon hours expire This policy setting determines whether to disconnect users who are connected to the local computer outside their user account?s valid logon hours. It affects the SMB component. If you enable this policy setting, client sessions wi ...

CCE-94083-3
Devices: Allowed to format and eject removable media This policy setting determines who is allowed to format and eject removable media. You can use this policy setting to prevent unauthorized users from removing data on one computer to access it on another computer on which they have local administ ...

CCE-94205-2
This policy setting controls the behavior of the elevation prompt for administrators. The options are: - Elevate without prompting: Allows privileged accounts to perform an operation that requires elevation without requiring consent or credentials. Note: Use this option only in the most co ...

CCE-93582-5
User Account Control: Behavior of the elevation prompt for standard users This policy setting controls the behavior of the elevation prompt for standard users. The options are: - Prompt for credentials: When an operation requires elevation of privilege, the user is prompted to enter an administra ...

CCE-94149-2
Create permanent shared objects This user right is useful to kernel-mode components that extend the object namespace. However, components that run in kernel mode have this user right inherently. Therefore, it is typically not necessary to specifically assign this user right. When configuring a use ...

CCE-94188-0
Perform volume maintenance tasks This policy setting allows users to manage the system's volume or disk configuration, which could allow a user to delete a volume and cause data loss as well as a denial-of-service condition. When configuring a user right in the SCM enter a comma delimited list of ...

CCE-94216-9
Lock pages in memory This policy setting allows a process to keep data in physical memory, which prevents the system from paging the data to virtual memory on disk. If this user right is assigned, significant degradation of system performance can occur. When configuring a user right in the SCM ent ...

CCE-93313-5
Back up files and directories This policy setting allows users to circumvent file and directory permissions to back up the system. This user right is enabled only when an application (such as NTBACKUP) attempts to access a file or directory through the NTFS file system backup application programmin ...

CCE-99746-0
This policy setting specifies whether users can share files within their profile. By default users are allowed to share files within their profile to other users on their network after an administrator opts in the computer. An administrator can opt in the computer by using the sharing wizard to shar ...

CCE-99822-9
Enable this policy to specify when to receive quality updates. You can defer receiving quality updates for up to 30 days. To prevent quality updates from being received on their scheduled time, you can temporarily pause quality updates. The pause will remain in effect for 35 days or until you clea ...

CCE-93567-6
Replace a process level token This policy setting allows one process or service to start another service or process with a different security access token, which can be used to modify the security access token of that sub-process and result in the escalation of privileges. When configuring a user ...

CCE-93034-7
Always install with elevated privileges Directs Windows Installer to use system permissions when it installs any program on the system. This setting extends elevated privileges to all programs. These privileges are usually reserved for programs that have been assigned to the user (offered on the d ...

CCE-93594-0
Deny log on locally This security setting determines which users are prevented from logging on at the computer. This policy setting supersedes the Allow log on locally policy setting if an account is subject to both policies.Important:If you apply this security policy to the Everyone group, no one ...

CCE-99820-3
Enable this policy to manage which updates you receive prior to the update being released to the world. Dev Channel Ideal for highly technical users. Insiders in the Dev Channel will receive builds from our active development branch that is earliest in a development cycle. These builds are not matc ...

CCE-93283-0
Restore files and directories This policy setting determines which users can bypass file, directory, registry, and other persistent object permissions when restoring backed up files and directories on computers that run Windows Vista in your environment. This user right also determines which users ...

CCE-93809-2
Load and unload device drivers This policy setting allows users to dynamically load a new device driver on a system. An attacker could potentially use this capability to install malicious code that appears to be a device driver. This user right is required for users to add local printers or printer ...

CCE-94076-7
Enable computer and user accounts to be trusted for delegation This policy setting allows users to change the Trusted for Delegation setting on a computer object in Active Directory. Abuse of this privilege could allow unauthorized users to impersonate other users on the network. When configuring ...

CCE-99767-6
This policy setting enables or disables the Administrator account during normal operation. When a computer is booted into safe mode, the Administrator account is always enabled, regardless of how this setting is configured. Note: that this setting will have no impact when applied to the domain contr ...

CCE-94003-1
Accounts: Block Microsoft accounts This policy setting prevents users from adding new Microsoft accounts on this computer. If you select the 'Users can?t add Microsoft accounts' option, users will not be able to create new Microsoft accounts on this computer, switch a local account to a Microsoft ...

CCE-99869-0
This policy setting controls which port is used for RPC over TCP for incoming connections to the print spooler and outgoing connections to remote print spoolers. The recommended state for this setting is: Enabled: 0. Fix: (1) GPO: Computer Configuration\Policies\Administrative Templates\Printers\Co ...

CCE-94132-8
Network access: Let Everyone permissions apply to anonymous users This policy setting determines what additional permissions are assigned for anonymous connections to the computer. If you enable this policy setting, anonymous Windows users are allowed to perform certain activities, such as enumerat ...

CCE-93637-7
Interactive logon: Do not display last user name This policy setting determines whether the account name of the last user to log on to the client computers in your organization will be displayed in each computer's respective Windows logon screen. Enable this policy setting to prevent intruders from ...

CCE-93694-8
Network access: Restrict anonymous access to Named Pipes and Shares When enabled, this policy setting restricts anonymous access to only those shares and pipes that are named in the Network access: Named pipes that can be accessed anonymously and Network access: Shares that can be accessed anonymou ...

CCE-93027-1
Network access: Remotely accessible registry paths This policy setting determines which registry paths will be accessible after referencing the WinReg key to determine access permissions to the paths. Note: This setting does not exist in Windows XP. There was a setting with that name in Windows XP, ...

CCE-99864-1
This policy setting controls which protocol and protocol settings to use for outgoing Remote Procedure Call (RPC) connections to a remote print spooler. The recommended state for this setting is: Enabled: RPC over TCP Fix: (1) GPO: Computer Configuration\Policies\Administrative Templates\Printers\C ...

CCE-99766-8
This policy setting determines the maximum allowable age for a computer account password. By default, domain members automatically change their domain passwords every 30 days. If you increase this interval significantly or set it to 0 so that the computers no longer change their passwords, an attack ...

CCE-99866-6
This policy setting controls which protocol and protocol settings to use for outgoing Remote Procedure Call (RPC) connections to a remote print spooler. The recommended state for this setting is: Enabled: Default Fix: (1) GPO: Computer Configuration\Policies\Administrative Templates\Printers\Config ...

CCE-93028-9
Microsoft network server: Amount of idle time required before suspending session This policy setting allows you to specify the amount of continuous idle time that must pass in an SMB session before the session is suspended because of inactivity. Administrators can use this policy setting to control ...

CCE-93744-1
Network access: Do not allow anonymous enumeration of SAM accounts This policy setting controls the ability of anonymous users to enumerate the accounts in the Security Accounts Manager (SAM). If you enable this policy setting, users with anonymous connections cannot enumerate domain account user n ...

CCE-99670-2
This security setting determines whether a different account name is associated with the security identifier (SID) for the account Administrator. Renaming the well-known Administrator account makes it slightly more difficult for unauthorized persons to guess this privileged user name and password co ...

CCE-99661-1
This security setting determines whether a different account name is associated with the security identifier (SID) for the account &quot;Guest.&quot; Renaming the well-known Guest account makes it slightly more difficult for unauthorized persons to guess this user name and password combination. Def ...

CCE-93812-6
Domain member: Digitally sign secure channel data (when possible) This policy setting determines whether a domain member should attempt to negotiate whether all secure channel traffic that it initiates must be digitally signed. Digital signatures protect the traffic from being modified by anyone wh ...

CCE-99870-8
This policy setting manages how queue-specific files are processed during printer installation. At printer installation time, a vendor-supplied installation application can specify a set of files, of any type, to be associated with a particular print queue. The files are downloaded to each client th ...

CCE-93758-1
System objects: Require case insensitivity for non-Windows subsystems This policy setting determines whether case insensitivity is enforced for all subsystems. The Microsoft Win32? subsystem is case insensitive. However, the kernel supports case sensitivity for other subsystems, such as the Portabl ...

CCE-94128-6
Require secure RPC communication Specifies whether a Remote Desktop Session Host server requires secure RPC communication with all clients or allows unsecured communication. You can use this setting to strengthen the security of RPC communication with clients by allowing only authenticated and enc ...

CCE-99874-0
This policy setting controls packet level privacy for Remote Procedure Call (RPC) incoming connections.

CCE-99876-5
This setting determines whether the LDAP server (Domain Controller) enforces validation of Channel Binding Tokens (CBT) received in LDAP bind requests that are sent over SSL/TLS (i.e. LDAPS). For more information, see https://support.microsoft.com/help/4034879 . Some important points: * Before con ...

CCE-99867-4
This policy setting controls which protocols incoming Remote Procedure Call (RPC) connections to the print spooler are allowed to use. The recommended state for this setting is: Enabled: RPC over TCP. Fix: (1) GPO: Computer Configuration\Policies\Administrative Templates\Printers\Configure RPC list ...

CCE-93127-9
Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings This policy setting allows administrators to enable the more precise auditing capabilities present in Windows Vista. The Audit Policy settings available in Windows Server 2003 Active ...

CCE-94103-9
Domain member: Require strong (Windows 2000 or later) session key When this policy setting is enabled, a secure channel can only be established with domain controllers that are capable of encrypting secure channel data with a strong (128-bit) session key. To enable this policy setting, all domain c ...

CCE-93808-4
Network security: Minimum session security for NTLM SSP based (including secure RPC) clients This policy setting determines which behaviors are allowed for applications using the NTLM Security Support Provider (SSP). The SSP Interface (SSPI) is used by applications that need authentication services ...

CCE-93310-1
Interactive logon: Message text for users attempting to log on Microsoft recommends that you use this setting, if appropriate to your environment and your organization's business requirements, to help protect end user computers. This policy setting specifies a text message that displays to users wh ...

CCE-93576-7
Domain member: Digitally encrypt or sign secure channel data (always) This policy setting determines whether all secure channel traffic that is initiated by the domain member must be signed or encrypted. If a system is set to always encrypt or sign secure channel data, it cannot establish a secure ...

CCE-93732-6
Microsoft network client: Digitally sign communications (always) This policy setting determines whether packet signing is required by the SMB client component. If you enable this policy setting, the Microsoft network client computer cannot communicate with a Microsoft network server unless that ser ...

CCE-93604-7
This policy setting determines if the server side SMB service is able to sign SMB packets if it is requested to do so by a client that attempts to establish a connection. If no signing request comes from the client, a connection will be allowed without a signature if the Microsoft network server: Di ...

CCE-94079-1
Network security: LDAP client signing requirements This policy setting determines the level of data signing that is requested on behalf of clients that issue LDAP BIND requests, as follows: - None. The LDAP BIND request is issued with the caller-specified options. - Negotiate signing. If Transport ...

CCE-99871-6
This policy setting controls whether computers will show a warning and a security elevation prompt when users create a new printer connection using Point and Print. The recommended state for this setting is: Enabled: Show warning and elevation prompt. Fix: (1) GPO: Computer Configuration\Policie ...

CCE-99875-7
This security setting determines whether the domain controller bypasses secure RPC for Netlogon secure channel connections for specified machine accounts. When deployed, this policy should be applied to all domain controllers in a forest by enabling the policy on the domain controllers OU. When th ...

CCE-99868-2
This policy setting controls which protocols incoming Remote Procedure Call (RPC) connections to the print spooler are allowed to use. The recommended state for this setting is: Enabled: Negotiate or higher. Fix: (1) GPO: Computer Configuration\Policies\Administrative Templates\Printers\Configure R ...

CCE-94006-4
Network access: Shares that can be accessed anonymously Note: It can be very dangerous to add other shares to this Group Policy setting. Any network user can access any shares that are listed, which could exposure or corrupt sensitive data. Note: When you configure this setting you specify a list o ...

CCE-93404-2
Interactive logon: Do not require CTRL+ALT+DEL This policy setting determines whether users must press CTRL+ALT+DEL before they log on. If you enable this policy setting, users can log on without this key combination. If you disable this policy setting, users must press CTRL+ALT+DEL before they log ...

CCE-93306-9
Network access: Remotely accessible registry paths and sub-paths Note: In Windows XP this setting is called 'Network access: Remotely accessible registry paths,' the setting with that same name in Windows Vista, Windows Server 2008, and Windows Server 2003 does not exist in Windows XP. Note: When y ...

CCE-93631-0
Microsoft network client: Digitally sign communications (if server agrees) This policy setting determines whether the SMB client will attempt to negotiate SMB packet signing. The implementation of digital signing in Windows?based networks helps to prevent sessions from being hijacked. If you enable ...

CCE-99792-4
Specifies whether to require the use of a specific security layer to secure communications between clients and RD Session Host servers during Remote Desktop Protocol (RDP) connections. If you enable this setting, all communications between clients and RD Session Host servers during remote conne ...

CCE-93448-9
Require user authentication for remote connections by using Network Level Authentication This policy setting allows you to specify whether to require user authentication for remote connections to the RD Session Host server by using Network Level Authentication. This policy setting enhances security ...

CCE-94152-6
Interactive logon: Prompt user to change password before expiration This policy setting determines how far in advance users are warned that their password will expire. Microsoft recommends that you configure this policy setting to 14 days to sufficiently warn users when their passwords will expire.

CCE-93636-9
Microsoft network client: Send unencrypted password to third-party SMB servers Disable this policy setting to prevent the SMB redirector from sending plaintext passwords during authentication to third-party SMB servers that do not support password encryption. Microsoft recommends that you disable t ...

CCE-93810-0
Network access: Do not allow anonymous enumeration of SAM accounts and shares This policy setting controls the ability of anonymous users to enumerate SAM accounts as well as shares. If you enable this policy setting, anonymous users will not be able to enumerate domain account user names and netwo ...

CCE-99872-4
This policy setting controls whether computers will show a warning and a security elevation prompt when users are updating drivers for an existing connection using Point and Print. The recommended state for this setting is: Enabled: Show warning and elevation prompt. Fix: (1) GPO: Computer Configur ...

CCE-99736-1
If the Screen Saver Timeout setting is enabled, then the screen saver will be launched when the specified amount of time has passed since the last user action. Valid values range from 1 to 89,400 seconds (24 hours). The setting has no effect if the wait time is set to zero or no screen saver has bee ...

CCE-99727-0
If the Password protect the screen saver setting is enabled, then all screen savers are password protected, if it is disabled then password protection cannot be set on any screen saver.

CCE-93778-9
Reset account lockout counter after This policy setting determines the length of time before the Account lockout threshold resets to zero. The default value for this policy setting is Not Defined. If the Account lockout threshold is defined, this reset time must be less than or equal to the value f ...

CCE-93811-8
Account lockout duration This policy setting determines the length of time that must pass before a locked account is unlocked and a user can try to log on again. The setting does this by specifying the number of minutes a locked out account will remain unavailable. If the value for this policy sett ...

CCE-93900-9
No auto-restart with logged on users for scheduled automatic updates installations This policy setting specifies that Automatic Updates will wait for computers to be restarted by the users who are logged on to them to complete a scheduled installation. If you enable the No auto-restart for schedule ...

CCE-94155-9
Windows Firewall: Private: Firewall state Select On (recommended) to have Windows Firewall with Advanced Security use the settings for this profile to filter network traffic. If you select Off, Windows Firewall with Advanced Security will not use any of the firewall rules or connection security rul ...

CCE-94048-6
Windows Firewall: Domain: Firewall state Select On (recommended) to have Windows Firewall with Advanced Security use the settings for this profile to filter network traffic. If you select Off, Windows Firewall with Advanced Security will not use any of the firewall rules or connection security rule ...

CCE-93029-7
Windows Firewall: Public: Firewall state Select On (recommended) to have Windows Firewall with Advanced Security use the settings for this profile to filter network traffic. If you select Off, Windows Firewall with Advanced Security will not use any of the firewall rules or connection security rule ...

CCE-99818-7
Allow Windows Ink Workspace Fix: (1) GPO: Computer Configuration\Administrative Templates\Windows Components\Windows Ink Workspace\Allow Windows Ink Workspace (2) REG: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\WindowsInkWorkspace!AllowWindowsInkWorkspace

CCE-99877-3
This policy setting specifies if the Domain Name System (DNS) client will perform name resolution over Network Basic Input-Output System (NetBIOS). NetBIOS is a legacy name resolution method for internal Microsoft networking that predates the use of DNS for that purpose (Pre-Active Directory). Some ...

CCE-93897-7
Require trusted path for credential entry If you enable this policy setting, users are required to enter Windows credentials on the Secure Desktop by means of the trusted path mechanism. This means that before entering account and password information to authorize an elevation request, a user first ...

CCE-93907-4
Telnet The Telnet service supports connections from various TCP/IP Telnet clients, including UNIX-based and Windows-based computers. Telnet Server for Windows provides ASCII terminal sessions to Telnet clients. Telnet Server supports two types of authentication and supports four types of terminals: ...

CCE-99739-5
This policy setting allows you to manage whether or not screen savers run. If the Screen Saver setting is disabled screen savers do not run and the screen saver section of the Screen Saver tab in Display in Control Panel is disabled. If this setting is enabled a screen saver will run if the followin ...

CCE-99502-7
Internet Protocol version 6 (IPv6) is a set of protocols that computers use to exchange information over the Internet and over home and business networks. IPv6 allows for many more IP addresses to be assigned than IPv4 did. Older networking, hosts and operating systems may not support IPv6 natively. ...

CCE-99878-1
This policy setting allows you to audit when plug and play detects an external device. The recommended state for this setting is to include: Success. Fix: (1) GPO: Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\Detailed Tracking\ ...

CPE    1
cpe:/o:microsoft:windows_server_2019
*XCCDF
xccdf_org.secpod_benchmark_general_Windows_2019
OVAL    1143
oval:org.secpod.oval:def:85637
oval:org.secpod.oval:def:85632
oval:org.secpod.oval:def:85639
oval:org.secpod.oval:def:85642
...

© SecPod Technologies