STIGQter STIGQter: STIG Summary:

Active Directory Forest Security Technical Implementation Guide

Version: 3

Release: 2 Benchmark Date: 02 Jul 2025

CheckedNameTitle
SV-243502r1026198_ruleMembership to the Schema Admins group must be limited.
SV-243503r1026201_ruleAnonymous Access to AD forest data above the rootDSE level must be disabled.
SV-243504r1026204_ruleThe Windows Time Service on the forest root PDC Emulator must be configured to acquire its time from an external time source.
SV-243505r1026206_ruleChanges to the AD schema must be subject to a documented configuration management process.
SV-243506r1026208_ruleUpdate access to the directory schema must be restricted to appropriate accounts.
SV-269098r1106505_ruleWindows Server hosting Active Directory Certificate Services (AD CS) must enforce Certificate Authority (CA) certificate management approval for certificate requests.
SV-269099r1026184_ruleWindows Server running Active Directory Certificate Services (AD CS) must be managed by a PAW tier 0.