STIGQter STIGQter: STIG Summary:

Microsoft Windows 11 Security Technical Implementation Guide

Version: 2

Release: 8 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-253254r991589_ruleDomain-joined systems must use Windows 11 Enterprise Edition 64-bit version.
SV-253255r1210279_ruleWindows 11 systems must have a Trusted Platform Module (TPM) enabled.
SV-253256r1210280_ruleWindows 11 systems must have Unified Extensible Firmware Interface (UEFI) firmware and be configured to run in UEFI mode, not Legacy BIOS.
SV-253257r1210281_ruleSecure Boot must be enabled on Windows 11 systems.
SV-253259r1210282_ruleWindows 11 information systems must use BitLocker to encrypt all disks to protect the confidentiality and integrity of all information at rest.
SV-253260r1210283_ruleWindows 11 systems must use a BitLocker PIN for pre-boot authentication.
SV-253261r1210284_ruleWindows 11 systems must use a BitLocker PIN with a minimum length of six digits for pre-boot authentication.
SV-253262r958808_ruleThe operating system must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
SV-253263r1016364_ruleWindows 11 systems must be maintained at a supported servicing level.
SV-253264r1186372_ruleThe Windows 11 system must use an antivirus program.
SV-253265r1137691_ruleLocal volumes must be formatted using NTFS.
SV-253266r991589_ruleAlternate operating systems must not be permitted on the same system.
SV-253267r1137695_ruleNon-system-created file shares on a system must limit access to groups that require it.
SV-253268r1051039_ruleUnused accounts must be disabled or removed from the system after 35 days of inactivity.
SV-253269r958702_ruleOnly accounts responsible for the administration of a system must have Administrator rights on the system.
SV-253270r991589_ruleOnly accounts responsible for the backup operations must be members of the Backup Operators group.
SV-253271r958702_ruleOnly authorized user accounts must be allowed to create or run virtual machines on Windows 11 systems.
SV-253272r1210286_ruleStandard local user accounts must not exist on a system in a domain.
SV-253273r1051040_ruleAccounts must be configured to require password expiration.
SV-253274r1016661_rulePermissions for system files and directories must conform to minimum requirements.
SV-253275r958478_ruleInternet Information System (IIS) or its subcomponents must not be installed on a workstation.
SV-253276r958480_ruleSimple Network Management Protocol (SNMP) must not be installed on the system.
SV-253277r958478_ruleSimple TCP/IP Services must not be installed on the system.
SV-253278r958480_ruleThe Telnet Client must not be installed on the system.
SV-253279r958480_ruleThe TFTP Client must not be installed on the system.
SV-253280r991589_ruleSoftware certificate installation files must be removed from Windows 11.
SV-253281r991589_ruleA host-based firewall must be installed and enabled on the system.
SV-253282r991593_ruleInbound exceptions to the firewall on Windows 11 domain workstations must only allow authorized remote management hosts.
SV-253284r958928_ruleStructured Exception Handling Overwrite Protection (SEHOP) must be enabled.
SV-253285r1153425_ruleThe Windows PowerShell 2.0 feature must be disabled on the system.
SV-253286r958478_ruleThe Server Message Block (SMB) v1 protocol must be disabled on the system.
SV-253287r958478_ruleThe Server Message Block (SMB) v1 protocol must be disabled on the SMB server.
SV-253288r958478_ruleThe Server Message Block (SMB) v1 protocol must be disabled on the SMB client.
SV-253289r958478_ruleThe Secondary Logon service must be disabled on Windows 11.
SV-253290r991589_ruleOrphaned security identifiers (SIDs) must be removed from user rights on Windows 11.
SV-253291r1153422_ruleBluetooth must be turned off unless approved by the organization.
SV-253293r991589_ruleThe system must notify the user when a Bluetooth device attempts to connect.
SV-253294r991589_ruleAdministrative accounts must not be used with applications that access the internet, such as web browsers, or with potential internet sources, such as email.
SV-253296r1051041_ruleThe Windows 11 time service must synchronize with an appropriate DOD time source.
SV-253297r958736_ruleWindows 11 account lockout duration must be configured to 15 minutes or greater.
SV-253298r958388_ruleThe number of allowed bad logon attempts must be configured to three or less.
SV-253299r958388_ruleThe period of time before the bad logon counter is reset must be configured to 15 minutes.
SV-253300r1210287_ruleThe password history must be configured to 24 passwords remembered.
SV-253301r1051042_ruleThe maximum password age must be configured to 60 days or less.
SV-253302r1051043_ruleThe minimum password age must be configured to at least 1 day.
SV-253303r1051044_rulePasswords must, at a minimum, be 14 characters.
SV-253304r1051045_ruleThe built-in Microsoft password complexity filter must be enabled.
SV-253305r1051046_ruleReversible password encryption must be disabled.
SV-253306r991570_ruleThe system must be configured to audit Account Logon - Credential Validation failures.
SV-253307r991570_ruleThe system must be configured to audit Account Logon - Credential Validation successes.
SV-253308r971541_ruleThe system must be configured to audit Account Management - Security Group Management successes.
SV-253309r958566_ruleThe system must be configured to audit Account Management - User Account Management failures.
SV-253310r991551_ruleThe system must be configured to audit Account Management - User Account Management successes.
SV-253311r1051047_ruleThe system must be configured to audit Detailed Tracking - PNP Activity successes.
SV-253312r1051048_ruleThe system must be configured to audit Detailed Tracking - Process Creation successes.
SV-253313r991578_ruleThe system must be configured to audit Logon/Logoff - Account Lockout failures.
SV-253314r991570_ruleThe system must be configured to audit Logon/Logoff - Group Membership successes.
SV-253315r958406_ruleThe system must be configured to audit Logon/Logoff - Logoff successes.
SV-253316r991581_ruleThe system must be configured to audit Logon/Logoff - Logon failures.
SV-253317r991581_ruleThe system must be configured to audit Logon/Logoff - Logon successes.
SV-253318r991578_ruleThe system must be configured to audit Logon/Logoff - Special Logon successes.
SV-253319r991572_ruleWindows 11 must be configured to audit Object Access - File Share failures.
SV-253320r991572_ruleWindows 11 must be configured to audit Object Access - File Share successes.
SV-253321r991572_ruleWindows 11 must be configured to audit Object Access - Other Object Access Events successes.
SV-253322r991572_ruleWindows 11 must be configured to audit Object Access - Other Object Access Events failures.
SV-253323r991583_ruleThe system must be configured to audit Object Access - Removable Storage failures.
SV-253324r991583_ruleThe system must be configured to audit Object Access - Removable Storage successes.
SV-253325r991572_ruleThe system must be configured to audit Policy Change - Audit Policy Change successes.
SV-253326r991572_ruleThe system must be configured to audit Policy Change - Authentication Policy Change successes.
SV-253327r991572_ruleThe system must be configured to audit Policy Change - Authorization Policy Change successes.
SV-253328r958732_ruleThe system must be configured to audit Privilege Use - Sensitive Privilege Use failures.
SV-253329r991575_ruleThe system must be configured to audit Privilege Use - Sensitive Privilege Use successes.
SV-253330r991586_ruleThe system must be configured to audit System - IPsec Driver failures.
SV-253331r991579_ruleThe system must be configured to audit System - Other System Events successes.
SV-253332r991579_ruleThe system must be configured to audit System - Other System Events failures.
SV-253333r991575_ruleThe system must be configured to audit System - Security State Change successes.
SV-253334r991575_ruleThe system must be configured to audit System - Security System Extension successes.
SV-253335r991573_ruleThe system must be configured to audit System - System Integrity failures.
SV-253336r991573_ruleThe system must be configured to audit System - System Integrity successes.
SV-253337r958752_ruleThe Application event log size must be configured to 32768 KB or greater.
SV-253338r1186375_ruleThe security event log size must be configured to a value that holds at least one week's worth of audit records.
SV-253339r958752_ruleThe System event log size must be configured to 32768 KB or greater.
SV-253340r958434_ruleWindows 11 permissions for the Application event log must prevent access by non-privileged accounts.
SV-253341r958434_ruleWindows 11 permissions for the Security event log must prevent access by non-privileged accounts.
SV-253342r958434_ruleWindows 11 permissions for the System event log must prevent access by non-privileged accounts.
SV-253344r958412_ruleWindows 11 must be configured to audit Other Policy Change Events Failures.
SV-253345r958412_ruleWindows 11 must be configured to audit other Logon/Logoff Events Successes.
SV-253346r958412_ruleWindows 11 must be configured to audit other Logon/Logoff Events Failures.
SV-253347r958412_ruleWindows 11 must be configured to audit Detailed File Share Failures.
SV-253348r958412_ruleWindows 11 must be configured to audit MPSSVC Rule-Level Policy Change Successes.
SV-253349r958412_ruleWindows 11 must be configured to audit MPSSVC Rule-Level Policy Change Failures.
SV-253350r958478_ruleCamera access from the lock screen must be disabled.
SV-253351r1106508_ruleWindows 11 must cover or disable the built-in or attached camera when not in use.
SV-253352r958478_ruleThe display of slide shows on the lock screen must be disabled.
SV-253353r991589_ruleIPv6 source routing must be configured to highest protection.
SV-253354r991589_ruleThe system must be configured to prevent IP source routing.
SV-253355r991589_ruleThe system must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF) generated routes.
SV-253356r958902_ruleThe system must be configured to ignore NetBIOS name release requests except from WINS servers.
SV-253357r958518_ruleLocal administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain systems.
SV-253358r958478_ruleWDigest Authentication must be disabled.
SV-253359r958478_ruleRun as different user must be removed from context menus.
SV-253360r991589_ruleInsecure logons to an SMB server must be disabled.
SV-253361r958478_ruleInternet connection sharing must be disabled.
SV-253362r991589_ruleHardened UNC Paths must be defined to require mutual authentication and integrity for at least the \\*\SYSVOL and \\*\NETLOGON shares.
SV-253363r971535_ruleWindows 11 must be configured to prioritize ECC Curves with longer key lengths first.
SV-253364r958358_ruleSimultaneous connections to the internet or a Windows domain must be limited.
SV-253365r991589_ruleConnections to non-domain networks when connected to a domain authenticated network must be blocked.
SV-253367r958422_ruleCommand line data must be included in process creation events.
SV-253368r991589_ruleWindows 11 must be configured to enable Remote host allows delegation of non-exportable credentials.
SV-253369r1210289_ruleVirtualization-Based Security (VBS) must be enabled on Windows 11 with the platform security level configured to Secure Boot or Secure Boot with DMA Protection.
SV-253370r1210290_ruleCredential Guard must be running on Windows 11 systems.
SV-253371r1210291_ruleVirtualization-based protection of code integrity must be enabled.
SV-253372r991589_ruleEarly Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers.
SV-253373r991589_ruleGroup Policy objects must be reprocessed even if they have not changed.
SV-253374r958478_ruleDownloading print driver packages over HTTP must be prevented.
SV-253375r958478_ruleWeb publishing and online ordering wizards must be prevented from downloading a list of providers.
SV-253376r958478_rulePrinting over HTTP must be prevented.
SV-253377r991589_ruleSystems must at least attempt device authentication using certificates.
SV-253378r958478_ruleThe network selection user interface (UI) must not be displayed on the logon screen.
SV-253379r958478_ruleLocal users on domain-joined computers must not be enumerated.
SV-253380r1051049_ruleUsers must be prompted for a password on resume from sleep (on battery).
SV-253381r1051050_ruleThe user must be prompted for a password on resume from sleep (plugged in).
SV-253382r1137695_ruleSolicited Remote Assistance must not be allowed.
SV-253383r971545_ruleUnauthenticated RPC clients must be restricted from connecting to the RPC server.
SV-253384r991589_ruleThe setting to allow Microsoft accounts to be optional for modern style apps must be enabled.
SV-253385r958478_ruleThe Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft.
SV-253386r958804_ruleAutoplay must be turned off for non-volume devices.
SV-253387r958804_ruleThe default autorun behavior must be configured to prevent autorun commands.
SV-253388r958804_ruleAutoplay must be disabled for all drives.
SV-253389r1210292_ruleEnhanced anti-spoofing for facial recognition must be enabled on Windows 11.
SV-253391r958518_ruleAdministrator accounts must not be enumerated during elevation.
SV-253392r991589_ruleEnhanced diagnostic data must be limited to the minimum required to support Windows Analytics.
SV-253393r1210293_ruleWindows Telemetry must not be configured to Full.
SV-253394r1210294_ruleWindows Update must not obtain updates from other PCs on the internet.
SV-253395r958478_ruleThe Microsoft Defender SmartScreen for Explorer must be enabled.
SV-253396r958928_ruleExplorer Data Execution Prevention must be enabled.
SV-253397r958902_ruleFile Explorer heap termination on corruption must be disabled.
SV-253398r991589_ruleFile Explorer shell protocol must run in protected mode.
SV-253399r1210295_ruleWindows 11 must be configured to disable Windows Game Recording and Broadcasting.
SV-253400r991589_ruleThe use of a hardware security device with Windows Hello for Business must be enabled.
SV-253401r1210296_ruleWindows 11 must be configured to require a minimum PIN length of six characters or greater.
SV-253402r1051051_rulePasswords must not be saved in the Remote Desktop Client.
SV-253403r1137695_ruleLocal drives must be prevented from sharing with Remote Desktop Session Hosts.
SV-253404r1051052_ruleRemote Desktop Services must always prompt a client for passwords upon connection.
SV-253405r991554_ruleThe Remote Desktop Session Host must require secure RPC communications.
SV-253406r958408_ruleRemote Desktop Services must be configured with the client connection encryption set to the required level.
SV-253407r991589_ruleAttachments must be prevented from being downloaded from RSS feeds.
SV-253408r958478_ruleBasic authentication for RSS feeds over HTTP must not be used.
SV-253409r1210297_ruleIndexing of encrypted files must be turned off.
SV-253410r1051053_ruleUsers must be prevented from changing installation options.
SV-253411r1051054_ruleThe Windows Installer feature "Always install with elevated privileges" must be disabled.
SV-253412r991589_ruleUsers must be notified if a web-based program attempts to install software.
SV-253413r991591_ruleAutomatically signing in the last interactive user after a system-initiated restart must be disabled.
SV-253414r958422_rulePowerShell script block logging must be enabled on Windows 11.
SV-253415r958420_rulePowerShell Transcription must be enabled on Windows 11.
SV-253416r958510_ruleThe Windows Remote Management (WinRM) client must not use Basic authentication.
SV-253417r958848_ruleThe Windows Remote Management (WinRM) client must not allow unencrypted traffic.
SV-253418r958510_ruleThe Windows Remote Management (WinRM) service must not use Basic authentication.
SV-253419r958850_ruleThe Windows Remote Management (WinRM) service must not allow unencrypted traffic.
SV-253420r1051055_ruleThe Windows Remote Management (WinRM) service must not store RunAs credentials.
SV-253421r958510_ruleThe Windows Remote Management (WinRM) client must not use Digest authentication.
SV-253422r1210298_ruleWindows 11 must be configured to prevent Windows apps from being activated by voice while the system is locked.
SV-253423r958478_ruleThe convenience PIN for Windows 11 must be disabled.
SV-253424r1210299_ruleWindows Ink Workspace must be configured to disallow access above the lock.
SV-253425r958478_ruleWindows 11 must be configured to prevent users from receiving suggestions for third-party or additional applications.
SV-253426r991580_ruleWindows 11 Kernel (Direct Memory Access) DMA Protection must be enabled.
SV-253427r1210300_ruleThe DOD Root CA certificates must be installed in the Trusted Root Store.
SV-253428r1210301_ruleThe External Root CA certificates must be installed in the Trusted Root Store on unclassified systems.
SV-253429r958448_ruleThe DoD Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems.
SV-253430r1081058_ruleThe US DOD CCEB Interoperability Root CA cross-certificates must be installed in the Untrusted Certificates Store on unclassified systems.
SV-253431r958726_ruleDefault permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained.
SV-253433r958504_ruleThe built-in guest account must be disabled.
SV-253434r991589_ruleLocal accounts with blank passwords must be restricted to prevent access from the network.
SV-253435r991589_ruleThe built-in administrator account must be renamed.
SV-253436r991589_ruleThe built-in guest account must be renamed.
SV-253437r958442_ruleAudit policy using subcategories must be enabled.
SV-253438r958908_ruleOutgoing secure channel traffic must be encrypted or signed.
SV-253439r958908_ruleOutgoing secure channel traffic must be encrypted.
SV-253440r958908_ruleOutgoing secure channel traffic must be signed.
SV-253441r991589_ruleThe computer account password must not be prevented from being reset.
SV-253442r991589_ruleThe maximum age for machine account passwords must be configured to 30 days or less.
SV-253443r958908_ruleThe system must be configured to require a strong session key.
SV-253444r958636_ruleThe machine inactivity limit must be set to 15 minutes, locking the system with the screensaver.
SV-253445r1210302_ruleThe required legal notice must be configured to display before console logon.
SV-253446r958586_ruleThe Windows message title for the legal notice must be configured.
SV-253447r991589_ruleCaching of logon credentials must be limited.
SV-253448r991589_ruleThe Smart Card removal option must be configured to Force Logoff or Lock Workstation.
SV-253449r958908_ruleThe Windows SMB client must be configured to always perform SMB packet signing.
SV-253450r987796_ruleUnencrypted passwords must not be sent to third-party SMB Servers.
SV-253451r958908_ruleThe Windows SMB server must be configured to always perform SMB packet signing.
SV-253452r991589_ruleAnonymous SID/Name translation must not be allowed.
SV-253453r991589_ruleAnonymous enumeration of SAM accounts must not be allowed.
SV-253454r1137695_ruleAnonymous enumeration of shares must be restricted.
SV-253455r991589_ruleThe system must be configured to prevent anonymous users from having the same rights as the Everyone group.
SV-253456r1137695_ruleAnonymous access to Named Pipes and Shares must be restricted.
SV-253457r1081060_ruleRemote calls to the Security Account Manager (SAM) must be restricted to Administrators.
SV-253458r991589_ruleNTLM must be prevented from falling back to a Null session.
SV-253459r991589_rulePKU2U authentication using online identities must be prevented.
SV-253460r971535_ruleKerberos encryption types must be configured to prevent the use of DES and RC4 encryption suites.
SV-253461r1051056_ruleThe system must be configured to prevent the storage of the LAN Manager hash of passwords.
SV-253462r991589_ruleThe LanMan authentication level must be set to send NTLMv2 response only, and to refuse LM and NTLM.
SV-253463r991589_ruleThe system must be configured to the required LDAP client signing level.
SV-253464r991589_ruleThe system must be configured to meet the minimum session security requirement for NTLM SSP based clients.
SV-253465r991589_ruleThe system must be configured to meet the minimum session security requirement for NTLM SSP based servers.
SV-253466r1210303_ruleThe system must be configured to use FIPS-compliant algorithms for encryption, hashing, and signing.
SV-253467r991589_ruleThe default permissions of global system objects must be increased.
SV-253468r1051057_ruleUser Account Control approval mode for the built-in Administrator must be enabled.
SV-253469r958518_ruleUser Account Control must prompt administrators for consent on the secure desktop.
SV-253470r1106510_ruleWindows 11 must use multifactor authentication for local and network access to privileged and nonprivileged accounts.
SV-253471r1051058_ruleUser Account Control must automatically deny elevation requests for standard users.
SV-253472r958518_ruleUser Account Control must be configured to detect application installations and prompt for elevation.
SV-253473r958518_ruleUser Account Control must only elevate UIAccess applications that are installed in secure locations.
SV-253474r1051059_ruleUser Account Control must run all administrators in Admin Approval Mode, enabling UAC.
SV-253475r958518_ruleUser Account Control must virtualize file and registry write failures to per-user locations.
SV-253476r1210304_rulePasswords for enabled local Administrator accounts must be changed at least every 60 days.
SV-253477r958478_ruleToast notifications to the lock screen must be turned off.
SV-253478r991589_ruleZone information must be preserved when saving attachments.
SV-253479r958726_ruleThe "Access Credential Manager as a trusted caller" user right must not be assigned to any groups or accounts.
SV-253480r1137691_ruleThe "Access this computer from the network" user right must only be assigned to the Administrators and Remote Desktop Users groups.
SV-253481r958726_ruleThe "Act as part of the operating system" user right must not be assigned to any groups or accounts.
SV-253482r1137691_ruleThe "Allow log on locally" user right must only be assigned to the Administrators and Users groups.
SV-253483r958726_ruleThe "Back up files and directories" user right must only be assigned to the Administrators group.
SV-253484r958726_ruleThe "Change the system time" user right must only be assigned to Administrators and Local Service.
SV-253485r958726_ruleThe "Create a pagefile" user right must only be assigned to the Administrators group.
SV-253486r958726_ruleThe "Create a token object" user right must not be assigned to any groups or accounts.
SV-253487r958726_ruleThe "Create global objects" user right must only be assigned to Administrators, Service, Local Service, and Network Service.
SV-253488r958726_ruleThe "Create permanent shared objects" user right must not be assigned to any groups or accounts.
SV-253489r958726_ruleThe "Create symbolic links" user right must only be assigned to the Administrators group.
SV-253490r958726_ruleThe "Debug programs" user right must only be assigned to the Administrators group.
SV-253491r1137691_ruleThe "Deny access to this computer from the network" user right on workstations must be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems.
SV-253492r1137691_ruleThe "Deny log on as a batch job" user right on domain-joined workstations must be configured to prevent access from highly privileged domain accounts.
SV-253493r1137691_ruleThe "Deny log on as a service" user right on Windows 11 domain-joined workstations must be configured to prevent access from highly privileged domain accounts.
SV-253494r1137691_ruleThe "Deny log on locally" user right on workstations must be configured to prevent access from highly privileged domain accounts on domain systems and unauthenticated access on all systems.
SV-253495r1137691_ruleThe "Deny log on through Remote Desktop Services" user right on Windows 11 workstations must be configured to prevent access from highly privileged domain accounts and local accounts on domain systems and unauthenticated access on all systems.
SV-253496r958726_ruleThe "Enable computer and user accounts to be trusted for delegation" user right must not be assigned to any groups or accounts.
SV-253497r958726_ruleThe "Force shutdown from a remote system" user right must only be assigned to the Administrators group.
SV-253498r1138526_ruleThe "Impersonate a client after authentication" user right must only be assigned to Administrators, Service, Local Service, and Network Service.
SV-253499r958726_ruleThe "Load and unload device drivers" user right must only be assigned to the Administrators group.
SV-253500r958726_ruleThe "Lock pages in memory" user right must not be assigned to any groups or accounts.
SV-253501r958434_ruleThe "Manage auditing and security log" user right must only be assigned to the Administrators group.
SV-253502r958726_ruleThe "Modify firmware environment values" user right must only be assigned to the Administrators group.
SV-253503r958726_ruleThe "Perform volume maintenance tasks" user right must only be assigned to the Administrators group.
SV-253504r958726_ruleThe "Profile single process" user right must only be assigned to the Administrators group.
SV-253505r958726_ruleThe "Restore files and directories" user right must only be assigned to the Administrators group.
SV-253506r958726_ruleThe "Take ownership of files or other objects" user right must only be assigned to the Administrators group.
SV-256893r958552_ruleInternet Explorer must be disabled for Windows 11.
SV-257592r991589_ruleWindows 11 must not have portproxy enabled or in use.
SV-257770r958412_ruleWindows 11 must have command line process auditing events enabled for failures.
SV-268317r1135320_ruleCopilot must be disabled for Windows 11.
SV-268318r1210288_ruleWindows 11 systems must use either Group Policy or an approved Mobile Device Management (MDM) product to enforce STIG compliance.
SV-278928r1135302_ruleWindows 11 must be configured to audit handle manipulation failures.
SV-278930r1135308_ruleWindows 11 must be configured to audit registry failures.
SV-278931r1135311_ruleWindows 11 must be configured to audit registry successes.
SV-278932r1141916_ruleWindows 11 must be configured to audit sensitive privilege use successes.
SV-278933r1141919_ruleWindows 11 must be configured to audit sensitive privilege use failures.
SV-279688r1153564_ruleWindows 11 systems must block consumer account user authentication.