STIGQter STIGQter: STIG Summary: Microsoft Windows Server 2022 Security Technical Implementation Guide Version: 2 Release: 9 Benchmark Date: 01 Jul 2026:

Windows Server 2022 data files owned by users must be on a different logical partition from the directory server data files.

DISA Rule

SV-254396r1137695_rule

Vulnerability Number

V-254396

Group Title

SRG-OS-000138-GPOS-00069

Rule Version

WN22-DC-000120

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Move shares used to store files owned by users to a different logical partition than the directory server data files.

Check Contents

This applies to domain controllers. It is NA for other systems.

Run "Regedit".

Navigate to "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters".

Note the directory locations in the values for "DSA Database file".

Open "Command Prompt".

Enter "net share".

Note the logical drive(s) or file system partition for any organization-created data shares.

Ignore system shares (e.g., NETLOGON, SYSVOL, and administrative shares ending in $). User shares that are hidden (ending with $) must not be ignored.

If user shares are located on the same logical partition as the directory server data files, this is a finding.

Vulnerability Number

V-254396

Documentable

False

Rule Version

WN22-DC-000120

Severity Override Guidance

This applies to domain controllers. It is NA for other systems.

Run "Regedit".

Navigate to "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters".

Note the directory locations in the values for "DSA Database file".

Open "Command Prompt".

Enter "net share".

Note the logical drive(s) or file system partition for any organization-created data shares.

Ignore system shares (e.g., NETLOGON, SYSVOL, and administrative shares ending in $). User shares that are hidden (ending with $) must not be ignored.

If user shares are located on the same logical partition as the directory server data files, this is a finding.

Check Content Reference

M

Target Key

5485