| Checked | Name | Title |
|---|
| ☐ | SV-243502r1026198_rule | Membership to the Schema Admins group must be limited. |
| ☐ | SV-243503r1026201_rule | Anonymous Access to AD forest data above the rootDSE level must be disabled. |
| ☐ | SV-243504r1026204_rule | The Windows Time Service on the forest root PDC Emulator must be configured to acquire its time from an external time source. |
| ☐ | SV-243505r1026206_rule | Changes to the AD schema must be subject to a documented configuration management process. |
| ☐ | SV-243506r1026208_rule | Update access to the directory schema must be restricted to appropriate accounts. |
| ☐ | SV-269098r1106505_rule | Windows Server hosting Active Directory Certificate Services (AD CS) must enforce Certificate Authority (CA) certificate management approval for certificate requests. |
| ☐ | SV-269099r1026184_rule | Windows Server running Active Directory Certificate Services (AD CS) must be managed by a PAW tier 0. |