STIGQter STIGQter: STIG Summary: Microsoft Windows 11 Security Technical Implementation Guide Version: 2 Release: 8 Benchmark Date: 01 Jul 2026:

Administrative accounts must not be used with applications that access the internet, such as web browsers, or with potential internet sources, such as email.

DISA Rule

SV-253294r991589_rule

Vulnerability Number

V-253294

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

WN11-00-000240

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Establish and enforce a policy that prohibits administrative accounts from using applications that access the internet, such as web browsers, or with potential internet sources, such as email. Define specific exceptions for local service administration. These exceptions may include HTTP(S)-based tools that are used for the administration of the local system, services, or attached devices.

Implement technical measures where feasible such as removal of applications or use of application allowlisting to restrict the use of applications that can access the internet.

Check Contents

Determine whether administrative accounts are prevented from using applications that access the internet, such as web browsers, or with potential internet sources, such as email, except as necessary for local service administration.

The organization must have a policy that prohibits administrative accounts from using applications that access the internet, such as web browsers, or with potential internet sources, such as email, except as necessary for local service administration. The policy must define specific exceptions for local service administration. These exceptions may include HTTP(S)-based tools that are used for the administration of the local system, services, or attached devices.

Technical measures such as the removal of applications or application allowlisting must be used where feasible to prevent the use of applications that access the internet.

If accounts with administrative privileges are not prevented from using applications that access the internet or with potential internet sources, this is a finding.

Vulnerability Number

V-253294

Documentable

False

Rule Version

WN11-00-000240

Severity Override Guidance

Determine whether administrative accounts are prevented from using applications that access the internet, such as web browsers, or with potential internet sources, such as email, except as necessary for local service administration.

The organization must have a policy that prohibits administrative accounts from using applications that access the internet, such as web browsers, or with potential internet sources, such as email, except as necessary for local service administration. The policy must define specific exceptions for local service administration. These exceptions may include HTTP(S)-based tools that are used for the administration of the local system, services, or attached devices.

Technical measures such as the removal of applications or application allowlisting must be used where feasible to prevent the use of applications that access the internet.

If accounts with administrative privileges are not prevented from using applications that access the internet or with potential internet sources, this is a finding.

Check Content Reference

M

Target Key

5471