STIGQter STIGQter: STIG Summary: Microsoft Windows Server 2022 Security Technical Implementation Guide Version: 2 Release: 9 Benchmark Date: 01 Jul 2026:

Windows Server 2022 administrative accounts must not be used with applications that access the internet, such as web browsers, or with potential internet sources, such as email.

DISA Rule

SV-254240r1210253_rule

Vulnerability Number

V-254240

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

WN22-00-000030

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Establish a policy, at minimum, to prohibit administrative accounts from using applications that access public-facing networks or the internet, such as web browsers, or applications with potential internet sources, such as email.

Ensure the policy is enforced by technical means, such as allow listing via AppLocker or SRPs.

Document any exceptions to technical enforcement with the ISSO.

Check Contents

Determine whether organization policy, at a minimum, prohibits administrative accounts from using applications that access the internet or other public-facing networks. These applications include web browsers or applications with potential internet sources, such as email, except as necessary for local service administration.

The policy must define specific exceptions for local service administration. These exceptions may include HTTP(S)-based tools that are used for the administration of the local system, services, or attached devices.

Determine whether the organization uses technical means, such as allow listing via AppLocker or Software Restriction Policies (SRPs), to prevent administrative accounts' use of browsers and email applications.

Note: Allow list tools facilitate defining rules that explicitly permit approved applications to run while blocking all others by default.

Administrative accounts that do not have technical restrictions to applications that access public-facing networks must be documented and approved by the information system security officer (ISSO) or AO.

If administrative access to applications that access public-facing networks is not blocked by technical means (except as approved by the AO), this is a finding.

Vulnerability Number

V-254240

Documentable

False

Rule Version

WN22-00-000030

Severity Override Guidance

Determine whether organization policy, at a minimum, prohibits administrative accounts from using applications that access the internet or other public-facing networks. These applications include web browsers or applications with potential internet sources, such as email, except as necessary for local service administration.

The policy must define specific exceptions for local service administration. These exceptions may include HTTP(S)-based tools that are used for the administration of the local system, services, or attached devices.

Determine whether the organization uses technical means, such as allow listing via AppLocker or Software Restriction Policies (SRPs), to prevent administrative accounts' use of browsers and email applications.

Note: Allow list tools facilitate defining rules that explicitly permit approved applications to run while blocking all others by default.

Administrative accounts that do not have technical restrictions to applications that access public-facing networks must be documented and approved by the information system security officer (ISSO) or AO.

If administrative access to applications that access public-facing networks is not blocked by technical means (except as approved by the AO), this is a finding.

Check Content Reference

M

Target Key

5485