STIGQter STIGQter: STIG Summary:

Active Directory Domain Security Technical Implementation Guide

Version: 3

Release: 7 Benchmark Date: 01 Apr 2026

CheckedNameTitle
SV-243466r959010_ruleMembership to the Enterprise Admins group must be restricted to accounts used only to manage the Active Directory Forest.
SV-243467r959010_ruleMembership to the Domain Admins group must be restricted to accounts used only to manage the Active Directory domain and domain controllers.
SV-243468r959010_ruleAdministrators must have separate accounts specifically for managing domain member servers.
SV-243469r959010_ruleAdministrators must have separate accounts specifically for managing domain workstations.
SV-243470r959010_ruleDelegation of privileged accounts must be prohibited.
SV-243471r1186313_ruleLocal administrator accounts on domain systems must not share the same password.
SV-243472r959010_ruleSeparate smart cards must be used for Enterprise Admin (EA) and Domain Admin (DA) accounts from smart cards used for other accounts.
SV-243473r959010_ruleSeparate domain accounts must be used to manage public facing servers from any domain accounts used to manage internal servers.
SV-243475r959010_ruleDomain controllers must be blocked from Internet access.
SV-243476r1038967_ruleAll accounts, privileged and unprivileged, that require smart cards must have the underlying NT hash rotated at least every 60 days.
SV-243477r1153405_ruleUser accounts with domain level administrative privileges must be members of the Protected Users group in domains with a domain functional level of Windows 2012 R2 or higher.
SV-243478r959010_ruleDomain-joined systems (excluding domain controllers) must not be configured for unconstrained delegation.
SV-243479r1153403_ruleThe Directory Service Restore Mode (DSRM) passwords must be changed on each Domain Controller (DC) at least annually.
SV-243480r959010_ruleThe domain functional level must be at a Windows Server version still supported by Microsoft.
SV-243481r959010_ruleAccess to need-to-know information must be restricted to an authorized community of interest.
SV-243482r959010_ruleInterconnections between DoD directory services of different classification levels must use a cross-domain solution that is approved for use with inter-classification trusts.
SV-243483r959010_ruleA controlled interface must have interconnections among DoD information systems operating between DoD and non-DoD systems or networks.
SV-243484r958482_ruleSecurity identifiers (SIDs) must be configured to use only authentication data of directly trusted external or forest trust.
SV-243485r1117265_ruleSelective Authentication must be enabled on outgoing forest trusts.
SV-243486r958504_ruleThe Anonymous Logon and Everyone groups must not be members of the Pre-Windows 2000 Compatible Access group.
SV-243487r959010_ruleMembership in the Group Policy Creator Owners and Incoming Forest Trust Builders groups must be limited.
SV-243488r959010_ruleUser accounts with delegated authority must be removed from Windows built-in administrative groups or remove the delegated authority from the accounts.
SV-243489r959010_ruleRead-only Domain Controller (RODC) architecture and configuration must comply with directory services requirements.
SV-243490r959010_ruleUsage of administrative accounts must be monitored for suspicious and anomalous activity.
SV-243491r959010_ruleSystems must be monitored for attempts to use local accounts to log on remotely from other systems.
SV-243492r959010_ruleSystems must be monitored for remote desktop logons.
SV-243493r959010_ruleActive Directory data must be backed up daily for systems with a Risk Management Framework categorization for Availability of moderate or high. Systems with a categorization of low must be backed up weekly.
SV-243494r959010_ruleEach cross-directory authentication configuration must be documented.
SV-243495r958908_ruleA VPN must be used to protect directory network traffic for directory service implementation spanning enclave boundaries.
SV-243496r959010_ruleAccounts from outside directories that are not part of the same organization or are not subject to the same security policies must be removed from all highly privileged groups.
SV-243497r959010_ruleInter-site replication must be enabled and configured to occur at least daily.
SV-243498r958406_ruleIf a VPN is used in the AD implementation, the traffic must be inspected by the network Intrusion detection system (IDS).
SV-243499r959010_ruleActive Directory implementation information must be added to the organization contingency plan where the Risk Management Framework categorization for Availability is moderate or high.
SV-243500r959010_ruleActive Directory must be supported by multiple domain controllers where the Risk Management Framework categorization for Availability is moderate or high.
SV-243501r1016334_ruleThe impact of CPCON changes on the cross-directory authentication configuration must be considered and procedures documented.
SV-269097r1026170_ruleWindows Server domain controllers must have Kerberos logging enabled with servers hosting Active Directory Certificate Services (AD CS).