| DoD Windows Server 2008 R2 Member Server STIG Computer v1r29 | |
| Data collected on: 4/24/2019 10:53:17 AM | |
| Domain | security.local |
| Owner | SECURITY\Domain Admins |
| Created | 4/24/2019 10:04:46 AM |
| Modified | 4/24/2019 10:05:26 AM |
| User Revisions | 1 (AD), 1 (sysvol) |
| Computer Revisions | 1 (AD), 1 (sysvol) |
| Unique ID | {C422A4F4-273E-475D-BE71-634ACEF76660} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| None | |||
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| SECURITY\Domain Admins | Edit settings, delete, modify security | No |
| SECURITY\Enterprise Admins | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Enforce password history | 24 passwords remembered |
| Maximum password age | 60 days |
| Minimum password age | 1 days |
| Minimum password length | 14 characters |
| Password must meet complexity requirements | Enabled |
| Store passwords using reversible encryption | Disabled |
| Policy | Setting |
|---|---|
| Account lockout duration | 15 minutes |
| Account lockout threshold | 3 invalid logon attempts |
| Reset account lockout counter after | 15 minutes |
| Policy | Setting |
|---|---|
| Access Credential Manager as a trusted caller | |
| Access this computer from the network | BUILTIN\Administrators, NT AUTHORITY\Authenticated Users |
| Act as part of the operating system | |
| Allow log on locally | BUILTIN\Administrators |
| Allow log on through Terminal Services | BUILTIN\Administrators |
| Back up files and directories | BUILTIN\Administrators |
| Change the system time | NT AUTHORITY\LOCAL SERVICE, BUILTIN\Administrators |
| Create a pagefile | BUILTIN\Administrators |
| Create a token object | |
| Create global objects | BUILTIN\Administrators, NT AUTHORITY\LOCAL SERVICE, NT AUTHORITY\NETWORK SERVICE, NT AUTHORITY\SERVICE |
| Create permanent shared objects | |
| Create symbolic links | BUILTIN\Administrators |
| Debug programs | BUILTIN\Administrators |
| Deny access to this computer from the network | ADD YOUR DOMAIN ADMINS, ADD YOUR ENTERPRISE ADMINS, BUILTIN\Guests, NT AUTHORITY\Local account |
| Deny log on as a batch job | BUILTIN\Guests, ADD YOUR ENTERPRISE ADMINS, ADD YOUR DOMAIN ADMINS |
| Deny log on as a service | ADD YOUR ENTERPRISE ADMINS, ADD YOUR DOMAIN ADMINS |
| Deny log on locally | BUILTIN\Guests, ADD YOUR ENTERPRISE ADMINS, ADD YOUR DOMAIN ADMINS |
| Deny log on through Terminal Services | ADD YOUR DOMAIN ADMINS, ADD YOUR ENTERPRISE ADMINS, BUILTIN\Guests, NT AUTHORITY\Local account |
| Enable computer and user accounts to be trusted for delegation | BUILTIN\Administrators |
| Force shutdown from a remote system | BUILTIN\Administrators |
| Generate security audits | NT AUTHORITY\LOCAL SERVICE, NT AUTHORITY\NETWORK SERVICE |
| Impersonate a client after authentication | BUILTIN\Administrators, NT AUTHORITY\LOCAL SERVICE, NT AUTHORITY\NETWORK SERVICE, NT AUTHORITY\SERVICE |
| Increase scheduling priority | BUILTIN\Administrators |
| Load and unload device drivers | BUILTIN\Administrators |
| Lock pages in memory | |
| Manage auditing and security log | BUILTIN\Administrators |
| Modify an object label | |
| Modify firmware environment values | BUILTIN\Administrators |
| Perform volume maintenance tasks | BUILTIN\Administrators |
| Profile single process | BUILTIN\Administrators |
| Profile system performance | BUILTIN\Administrators, NT SERVICE\WdiServiceHost |
| Replace a process level token | NT AUTHORITY\LOCAL SERVICE, NT AUTHORITY\NETWORK SERVICE |
| Restore files and directories | BUILTIN\Administrators |
| Take ownership of files or other objects | BUILTIN\Administrators |
| Policy | Setting |
|---|---|
| Accounts: Guest account status | Disabled |
| Accounts: Rename administrator account | "X_Admin" |
| Accounts: Rename guest account | "Visitor" |
| Policy | Setting |
|---|---|
| Devices: Allow undock without having to log on | Disabled |
| Policy | Setting |
|---|---|
| Network access: Allow anonymous SID/Name translation | Disabled |
| Policy | Setting |
|---|---|
| Network security: Force logoff when logon hours expire | Enabled |
| Policy | Setting |
|---|---|
| Shutdown: Allow system to be shut down without having to log on | Disabled |
| Policy | Setting |
|---|---|
| System cryptography: Force strong key protection for user keys stored on the computer | User must enter a password each time they use a key |
| Policy | Setting |
|---|---|
| System settings: Optional subsystems |
| Policy | Setting |
|---|---|
| User Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop | Disabled |
| User Account Control: Only elevate executables that are signed and validated | Disabled |
| Policy | Setting | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Accounts: Limit local account use of blank passwords to console logon only | Enabled | ||||||||||||
| Audit: Audit the access of global system objects | Disabled | ||||||||||||
| Audit: Audit the use of Backup and Restore privilege | Disabled | ||||||||||||
| Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings | Enabled | ||||||||||||
| Devices: Allowed to format and eject removable media | Administrators | ||||||||||||
| Devices: Prevent users from installing printer drivers | Enabled | ||||||||||||
| Domain member: Digitally encrypt or sign secure channel data (always) | Enabled | ||||||||||||
| Domain member: Digitally encrypt secure channel data (when possible) | Enabled | ||||||||||||
| Domain member: Digitally sign secure channel data (when possible) | Enabled | ||||||||||||
| Domain member: Disable machine account password changes | Disabled | ||||||||||||
| Domain member: Maximum machine account password age | 30 days | ||||||||||||
| Domain member: Require strong (Windows 2000 or later) session key | Enabled | ||||||||||||
| Interactive logon: Do not display last user name | Enabled | ||||||||||||
| Interactive logon: Do not require CTRL+ALT+DEL | Disabled | ||||||||||||
| Interactive logon: Message text for users attempting to log on | You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only., By using this IS (which includes any device attached to this IS), you consent to the following conditions:, -The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. -At any time, the USG may inspect and seize data stored on this IS. -Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose. -This IS includes security measures (e.g., authentication and access controls) to protect USG interests--not for your personal benefit or privacy. -Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details. | ||||||||||||
| Interactive logon: Message title for users attempting to log on | "DoD Notice and Consent Banner" | ||||||||||||
| Interactive logon: Number of previous logons to cache (in case domain controller is not available) | 2 logons | ||||||||||||
| Interactive logon: Prompt user to change password before expiration | 14 days | ||||||||||||
| Interactive logon: Smart card removal behavior | Lock Workstation | ||||||||||||
| Microsoft network client: Digitally sign communications (always) | Enabled | ||||||||||||
| Microsoft network client: Digitally sign communications (if server agrees) | Enabled | ||||||||||||
| Microsoft network client: Send unencrypted password to third-party SMB servers | Disabled | ||||||||||||
| Microsoft network server: Amount of idle time required before suspending session | 15 minutes | ||||||||||||
| Microsoft network server: Digitally sign communications (always) | Enabled | ||||||||||||
| Microsoft network server: Digitally sign communications (if client agrees) | Enabled | ||||||||||||
| Microsoft network server: Disconnect clients when logon hours expire | Enabled | ||||||||||||
| Microsoft network server: Server SPN target name validation level | Off | ||||||||||||
| Network access: Do not allow anonymous enumeration of SAM accounts | Enabled | ||||||||||||
| Network access: Do not allow anonymous enumeration of SAM accounts and shares | Enabled | ||||||||||||
| Network access: Do not allow storage of passwords and credentials for network authentication | Enabled | ||||||||||||
| Network access: Let Everyone permissions apply to anonymous users | Disabled | ||||||||||||
| Network access: Named Pipes that can be accessed anonymously | |||||||||||||
| Network access: Remotely accessible registry paths | System\CurrentControlSet\Control\ProductOptions, System\CurrentControlSet\Control\Server Applications, Software\Microsoft\Windows NT\CurrentVersion | ||||||||||||
| Network access: Remotely accessible registry paths and sub-paths | System\CurrentControlSet\Control\Print\Printers, System\CurrentControlSet\Services\Eventlog, Software\Microsoft\OLAP Server, Software\Microsoft\Windows NT\CurrentVersion\Print, Software\Microsoft\Windows NT\CurrentVersion\Windows, System\CurrentControlSet\Control\ContentIndex, System\CurrentControlSet\Control\Terminal Server, System\CurrentControlSet\Control\Terminal Server\UserConfig, System\CurrentControlSet\Control\Terminal Server\DefaultUserConfiguration, Software\Microsoft\Windows NT\CurrentVersion\Perflib, System\CurrentControlSet\Services\SysmonLog | ||||||||||||
| Network access: Restrict anonymous access to Named Pipes and Shares | Enabled | ||||||||||||
| Network access: Shares that can be accessed anonymously | |||||||||||||
| Network access: Sharing and security model for local accounts | Classic - local users authenticate as themselves | ||||||||||||
| Network security: Allow Local System to use computer identity for NTLM | Enabled | ||||||||||||
| Network security: Allow LocalSystem NULL session fallback | Disabled | ||||||||||||
| Network Security: Allow PKU2U authentication requests to this computer to use online identities | Disabled | ||||||||||||
| Network security: Configure encryption types allowed for Kerberos | Enabled | ||||||||||||
| |||||||||||||
| Network security: Do not store LAN Manager hash value on next password change | Enabled | ||||||||||||
| Network security: LAN Manager authentication level | Send NTLMv2 response only. Refuse LM & NTLM | ||||||||||||
| Network security: LDAP client signing requirements | Negotiate signing | ||||||||||||
| Network security: Minimum session security for NTLM SSP based (including secure RPC) clients | Enabled | ||||||||||||
| |||||||||||||
| Network security: Minimum session security for NTLM SSP based (including secure RPC) servers | Enabled | ||||||||||||
| |||||||||||||
| System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing | Enabled | ||||||||||||
| System objects: Require case insensitivity for non-Windows subsystems | Enabled | ||||||||||||
| System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links) | Enabled | ||||||||||||
| User Account Control: Admin Approval Mode for the Built-in Administrator account | Enabled | ||||||||||||
| User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode | Prompt for consent | ||||||||||||
| User Account Control: Behavior of the elevation prompt for standard users | Automatically deny elevation requests | ||||||||||||
| User Account Control: Detect application installations and prompt for elevation | Enabled | ||||||||||||
| User Account Control: Only elevate UIAccess applications that are installed in secure locations | Enabled | ||||||||||||
| User Account Control: Run all administrators in Admin Approval Mode | Enabled | ||||||||||||
| User Account Control: Switch to the secure desktop when prompting for elevation | Enabled | ||||||||||||
| User Account Control: Virtualize file and registry write failures to per-user locations | Enabled | ||||||||||||
| Policy | Setting |
|---|---|
| Allow users to select new root certification authorities (CAs) to trust | Enabled |
| Client computers can trust the following certificate stores | Third-Party Root Certification Authorities and Enterprise Root Certification Authorities |
| To perform certificate-based authentication of users and computers, CAs must meet the following criteria | Registered in Active Directory only |
| Policy | Setting |
|---|---|
| Audit Credential Validation | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Other Account Management Events | Success |
| Audit Security Group Management | Success |
| Audit User Account Management | Success, Failure |
| Policy | Setting |
|---|---|
| Audit Process Creation | Success |
| Policy | Setting |
|---|---|
| Audit Account Lockout | Success, Failure |
| Audit Logoff | Success |
| Audit Logon | Success, Failure |
| Audit Special Logon | Success |
| Policy | Setting |
|---|---|
| Audit Audit Policy Change | Success, Failure |
| Audit Authentication Policy Change | Success |
| Audit Authorization Policy Change | Success |
| Policy | Setting |
|---|---|
| Audit Sensitive Privilege Use | Success, Failure |
| Policy | Setting |
|---|---|
| Audit IPsec Driver | Success, Failure |
| Audit Other System Events | Success, Failure |
| Audit Security State Change | Success |
| Audit Security System Extension | Success |
| Audit System Integrity | Success, Failure |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Apply UAC restrictions to local accounts on network logons | Enabled | |||
| Configure SMB v1 client (extra setting needed for pre-Win8.1/2012R2) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Configure SMB v1 client driver | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Configure SMB v1 server | Disabled | |||
| WDigest Authentication (disabling may require KB2871997) | Disabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Turn on Mapper I/O (LLTDIO) driver | Disabled | |
| Turn on Responder (RSPNDR) driver | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Microsoft Peer-to-Peer Networking Services | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Prohibit installation and configuration of Network Bridge on your DNS domain network | Enabled | |||
| Require domain users to elevate when setting a network's location | Enabled | |||
| Route all traffic through the internal network | Enabled | |||
| ||||
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| 6to4 State | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| IP-HTTPS State | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| ISATAP State | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Teredo State | Enabled | |||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Configuration of wireless settings using Windows Connect Now | Disabled | |
| Prohibit Access of the Windows Connect Now wizards | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Extend Point and Print connection to search Windows Update | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Allow remote access to the Plug and Play interface | Disabled | |||
| Do not send a Windows error report when a generic driver is installed on a device | Enabled | |||
| Prevent creation of a system restore point during device activity that would normally prompt creation of a restore point | Disabled | |||
| Prevent device metadata retrieval from the Internet | Enabled | |||
| Prevent Windows from sending an error report when a device driver requests additional software during installation | Enabled | |||
| Specify search order for device driver source locations | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off Windows Update device driver search prompt | Enabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Registry policy processing | Enabled | |||||
| ||||||
| Policy | Setting | Comment | ||||
| Turn off background refresh of Group Policy | Disabled | |||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off downloading of print drivers over HTTP | Enabled | |
| Turn off Event Viewer "Events.asp" links | Enabled | |
| Turn off handwriting recognition error reporting | Enabled | |
| Turn off Internet download for Web publishing and online ordering wizards | Enabled | |
| Turn off Internet File Association service | Enabled | |
| Turn off printing over HTTP | Enabled | |
| Turn off the "Order Prints" picture task | Enabled | |
| Turn off Windows Customer Experience Improvement Program | Enabled | |
| Turn off Windows Error Reporting | Enabled | |
| Turn off Windows Update device driver searching | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Always use classic logon | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Require a Password When a Computer Wakes (On Battery) | Enabled | |
| Require a Password When a Computer Wakes (Plugged In) | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Offer Remote Assistance | Disabled | |
| Solicited Remote Assistance | Disabled | |
| Turn on session logging | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Restrictions for Unauthenticated RPC clients | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Microsoft Support Diagnostic Tool: Turn on MSDT interactive communication with Support Provider | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Enable/Disable PerfTrack | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Program Inventory | Enabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Default behavior for AutoRun | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn off Autoplay | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
| Turn off Autoplay for non-volume devices | Enabled | |||
| Policy | Setting | Comment |
|---|---|---|
| Enumerate administrator accounts on elevation | Disabled |
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Maximum Log Size (KB) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Maximum Log Size (KB) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Maximum Log Size (KB) | Enabled | |||
| ||||
| Policy | Setting | Comment | ||
|---|---|---|---|---|
| Maximum Log Size (KB) | Enabled | |||
| ||||
| Policy | Setting | Comment |
|---|---|---|
| Turn off downloading of game information | Enabled | |
| Turn off game updates | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent the computer from joining a homegroup | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow passwords to be saved | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Restrict Remote Desktop Services users to a single Remote Desktop Services session | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not allow COM port redirection | Enabled | |
| Do not allow drive redirection | Enabled | |
| Do not allow LPT port redirection | Enabled | |
| Do not allow smart card device redirection | Disabled | |
| Do not allow supported Plug and Play device redirection | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Redirect only the default client printer | Enabled |
| Policy | Setting | Comment | ||||
|---|---|---|---|---|---|---|
| Always prompt for password upon connection | Enabled | |||||
| Require secure RPC communication | Enabled | |||||
| Set client connection encryption level | Enabled | |||||
| ||||||
| Policy | Setting | Comment |
|---|---|---|
| Do not delete temp folder upon exit | Disabled | |
| Do not use temporary folders per session | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent downloading of enclosures | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent Windows Anytime Upgrade from running. | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Turn off Data Execution Prevention for Explorer | Disabled | |
| Turn off heap termination on corruption | Disabled | |
| Turn off shell protocol protected mode | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Always install with elevated privileges | Disabled | |
| Disable IE security prompt for Windows Installer scripts | Disabled | |
| Enable user control over installs | Disabled | |
| Prohibit non-administrators from applying vendor signed updates | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Prevent Windows Media DRM Internet Access | Enabled |
| Policy | Setting | Comment |
|---|---|---|
| Do Not Show First Use Dialog Boxes | Enabled | |
| Prevent Automatic Updates | Enabled |
| Setting | State |
|---|---|
| Software\policies\Microsoft\Windows\PowerShell\ScriptBlockLogging\EnableScriptBlockLogging | 1 |