STIGQter STIGQter: STIG Summary: Microsoft Windows 11 Security Technical Implementation Guide Version: 2 Release: 8 Benchmark Date: 01 Jul 2026:

Windows 11 systems must block consumer account user authentication.

DISA Rule

SV-279688r1153564_rule

Vulnerability Number

V-279688

Group Title

SRG-OS-000095-GPOS-00049

Rule Version

WN11-00-000126

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the following Group Policy:
Computer Configuration >> Administrative Templates >> Windows Components >> Microsoft Account "block all consumer Microsoft account user authentication" to "Enabled".

For systems managed by Intune, apply the DOD Windows 11 STIG Settings Catalog (or equivalent Intune policy) found in the Intune policy package available on cyber.mil.
Steps to create an Intune policy:
1. Sign in to the Intune admin center >> Devices >> Configuration >> Create >> New Policy.
2. Platform: Windows 10 and later. Profile type: Settings Catalog, then click "Create".
3. Basics: Provide a Name and Description of the profile, then click "Next".
4. Configuration settings: Click "+ Add settings" and search for consumer under the Settings picker. Under the Administrative Templates\Windows Components\Microsoft account category, check the box next to "Block all consumer Microsoft account user authentication". Click the Enabled radio button, then click "Next".
5. Scope tags: (optional), then click "Next".
6. Assignments: Assign the policy to Entra security groups that contain the target users or devices, then click "Next".
7. Review + create: Review the deployment summary, then click "Create".

Check Contents

Verify the "block all consumer Microsoft account user authentication" is enabled.

Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \SOFTWARE\Policies\Microsoft\MicrosoftAccount

Value Name: DisableUserAuth

Value Type: REG_DWORD
Value: 0x00000001 (1)

If the registry value is not "1", this is a finding.

Vulnerability Number

V-279688

Documentable

False

Rule Version

WN11-00-000126

Severity Override Guidance

Verify the "block all consumer Microsoft account user authentication" is enabled.

Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \SOFTWARE\Policies\Microsoft\MicrosoftAccount

Value Name: DisableUserAuth

Value Type: REG_DWORD
Value: 0x00000001 (1)

If the registry value is not "1", this is a finding.

Check Content Reference

M

Target Key

5471