| Checked | Name | Title |
|---|
| ☐ | SV-243466r959010_rule | Membership to the Enterprise Admins group must be restricted to accounts used only to manage the Active Directory Forest. |
| ☐ | SV-243467r959010_rule | Membership to the Domain Admins group must be restricted to accounts used only to manage the Active Directory domain and domain controllers. |
| ☐ | SV-243468r959010_rule | Administrators must have separate accounts specifically for managing domain member servers. |
| ☐ | SV-243469r959010_rule | Administrators must have separate accounts specifically for managing domain workstations. |
| ☐ | SV-243470r959010_rule | Delegation of privileged accounts must be prohibited. |
| ☐ | SV-243471r1186313_rule | Local administrator accounts on domain systems must not share the same password. |
| ☐ | SV-243472r959010_rule | Separate smart cards must be used for Enterprise Admin (EA) and Domain Admin (DA) accounts from smart cards used for other accounts. |
| ☐ | SV-243473r959010_rule | Separate domain accounts must be used to manage public facing servers from any domain accounts used to manage internal servers. |
| ☐ | SV-243475r959010_rule | Domain controllers must be blocked from Internet access. |
| ☐ | SV-243476r1038967_rule | All accounts, privileged and unprivileged, that require smart cards must have the underlying NT hash rotated at least every 60 days. |
| ☐ | SV-243477r1153405_rule | User accounts with domain level administrative privileges must be members of the Protected Users group in domains with a domain functional level of Windows 2012 R2 or higher. |
| ☐ | SV-243478r959010_rule | Domain-joined systems (excluding domain controllers) must not be configured for unconstrained delegation. |
| ☐ | SV-243479r1153403_rule | The Directory Service Restore Mode (DSRM) passwords must be changed on each Domain Controller (DC) at least annually. |
| ☐ | SV-243480r959010_rule | The domain functional level must be at a Windows Server version still supported by Microsoft. |
| ☐ | SV-243481r959010_rule | Access to need-to-know information must be restricted to an authorized community of interest. |
| ☐ | SV-243482r959010_rule | Interconnections between DoD directory services of different classification levels must use a cross-domain solution that is approved for use with inter-classification trusts. |
| ☐ | SV-243483r959010_rule | A controlled interface must have interconnections among DoD information systems operating between DoD and non-DoD systems or networks. |
| ☐ | SV-243484r958482_rule | Security identifiers (SIDs) must be configured to use only authentication data of directly trusted external or forest trust. |
| ☐ | SV-243485r1117265_rule | Selective Authentication must be enabled on outgoing forest trusts. |
| ☐ | SV-243486r958504_rule | The Anonymous Logon and Everyone groups must not be members of the Pre-Windows 2000 Compatible Access group. |
| ☐ | SV-243487r959010_rule | Membership in the Group Policy Creator Owners and Incoming Forest Trust Builders groups must be limited. |
| ☐ | SV-243488r959010_rule | User accounts with delegated authority must be removed from Windows built-in administrative groups or remove the delegated authority from the accounts. |
| ☐ | SV-243489r959010_rule | Read-only Domain Controller (RODC) architecture and configuration must comply with directory services requirements. |
| ☐ | SV-243490r959010_rule | Usage of administrative accounts must be monitored for suspicious and anomalous activity. |
| ☐ | SV-243491r959010_rule | Systems must be monitored for attempts to use local accounts to log on remotely from other systems. |
| ☐ | SV-243492r959010_rule | Systems must be monitored for remote desktop logons. |
| ☐ | SV-243493r959010_rule | Active Directory data must be backed up daily for systems with a Risk Management Framework categorization for Availability of moderate or high. Systems with a categorization of low must be backed up weekly. |
| ☐ | SV-243494r959010_rule | Each cross-directory authentication configuration must be documented. |
| ☐ | SV-243495r958908_rule | A VPN must be used to protect directory network traffic for directory service implementation spanning enclave boundaries. |
| ☐ | SV-243496r959010_rule | Accounts from outside directories that are not part of the same organization or are not subject to the same security policies must be removed from all highly privileged groups. |
| ☐ | SV-243497r959010_rule | Inter-site replication must be enabled and configured to occur at least daily. |
| ☐ | SV-243498r958406_rule | If a VPN is used in the AD implementation, the traffic must be inspected by the network Intrusion detection system (IDS). |
| ☐ | SV-243499r959010_rule | Active Directory implementation information must be added to the organization contingency plan where the Risk Management Framework categorization for Availability is moderate or high. |
| ☐ | SV-243500r959010_rule | Active Directory must be supported by multiple domain controllers where the Risk Management Framework categorization for Availability is moderate or high. |
| ☐ | SV-243501r1016334_rule | The impact of CPCON changes on the cross-directory authentication configuration must be considered and procedures documented. |
| ☐ | SV-269097r1026170_rule | Windows Server domain controllers must have Kerberos logging enabled with servers hosting Active Directory Certificate Services (AD CS). |