| Checked | Name | Title |
|---|
| ☐ | SV-254238r991589_rule | Windows Server 2022 users with Administrative privileges must have separate accounts for administrative duties and normal operational tasks. |
| ☐ | SV-254239r1153440_rule | Windows Server 2022 passwords for the built-in Administrator account must be changed at least every 60 days. |
| ☐ | SV-254240r1210253_rule | Windows Server 2022 administrative accounts must not be used with applications that access the internet, such as web browsers, or with potential internet sources, such as email. |
| ☐ | SV-254241r991589_rule | Windows Server 2022 members of the Backup Operators group must have separate accounts for backup duties and normal operational tasks. |
| ☐ | SV-254242r1051087_rule | Windows Server 2022 manually managed application account passwords must be at least 14 characters in length. |
| ☐ | SV-254243r991589_rule | Windows Server 2022 manually managed application account passwords must be changed at least annually or when a system administrator with knowledge of the password leaves the organization. |
| ☐ | SV-254244r958482_rule | Windows Server 2022 shared user accounts must not be permitted. |
| ☐ | SV-254245r958808_rule | Windows Server 2022 must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs. |
| ☐ | SV-254246r1210256_rule | Windows Server 2022 systems must have a Trusted Platform Module (TPM) enabled and ready for use. |
| ☐ | SV-254247r991589_rule | Windows Server 2022 must be maintained at a supported servicing level. |
| ☐ | SV-254248r991589_rule | Windows Server 2022 must use an antivirus program. |
| ☐ | SV-254249r1186387_rule | Windows Server 2022 must have a host-based intrusion detection and prevention service installed. |
| ☐ | SV-254250r1137691_rule | Windows Server 2022 local volumes must use a format that supports NTFS attributes. |
| ☐ | SV-254251r958702_rule | Windows Server 2022 permissions for the system drive root directory (usually C:\) must conform to minimum requirements. |
| ☐ | SV-254252r958702_rule | Windows Server 2022 permissions for program file directories must conform to minimum requirements. |
| ☐ | SV-254253r958702_rule | Windows Server 2022 permissions for the Windows installation directory must conform to minimum requirements. |
| ☐ | SV-254254r1210473_rule | Windows Server 2022 default permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained. |
| ☐ | SV-254255r1137691_rule | Windows Server 2022 nonadministrative accounts or groups must only have print permissions on printer shares. |
| ☐ | SV-254256r1051088_rule | Windows Server 2022 outdated or unused accounts must be removed or disabled. |
| ☐ | SV-254257r958482_rule | Windows Server 2022 accounts must require passwords. |
| ☐ | SV-254258r1051089_rule | Windows Server 2022 passwords must be configured to expire. |
| ☐ | SV-254259r958794_rule | Windows Server 2022 system files must be monitored for unauthorized changes. |
| ☐ | SV-254260r1137695_rule | Windows Server 2022 nonsystem-created file shares must limit access to groups that require it. |
| ☐ | SV-254261r1210262_rule | Windows Server 2022 must have software certificate installation files removed. |
| ☐ | SV-254262r1210265_rule | Windows Server 2022 systems requiring data-at-rest protections must employ cryptographic mechanisms to prevent unauthorized disclosure and modification of the information at rest. |
| ☐ | SV-254263r958912_rule | Windows Server 2022 must implement protection methods such as TLS, encrypted VPNs, or IPsec if the data owner has a strict requirement for ensuring data integrity and confidentiality is maintained at every step of the data transfer and handling process. |
| ☐ | SV-254264r1186389_rule | Windows Server 2022 must have the roles and features required by the system documented. |
| ☐ | SV-254265r991589_rule | Windows Server 2022 must have a host-based firewall installed and enabled. |
| ☐ | SV-254267r958364_rule | Windows Server 2022 must automatically remove or disable temporary user accounts after 72 hours. |
| ☐ | SV-254268r958508_rule | Windows Server 2022 must automatically remove or disable emergency accounts after the crisis is resolved or within 72 hours. |
| ☐ | SV-254269r958478_rule | Windows Server 2022 must not have the Fax Server role installed. |
| ☐ | SV-254270r958480_rule | Windows Server 2022 must not have the Microsoft FTP service installed unless required by the organization. |
| ☐ | SV-254271r958478_rule | Windows Server 2022 must not have the Peer Name Resolution Protocol installed. |
| ☐ | SV-254272r958478_rule | Windows Server 2022 must not have Simple TCP/IP Services installed. |
| ☐ | SV-254273r958480_rule | Windows Server 2022 must not have the Telnet Client installed. |
| ☐ | SV-254274r958478_rule | Windows Server 2022 must not have the TFTP Client installed. |
| ☐ | SV-254275r958478_rule | Windows Server 2022 must not the Server Message Block (SMB) v1 protocol installed. |
| ☐ | SV-254276r958478_rule | Windows Server 2022 must have the Server Message Block (SMB) v1 protocol disabled on the SMB server. |
| ☐ | SV-254277r958478_rule | Windows Server 2022 must have the Server Message Block (SMB) v1 protocol disabled on the SMB client. |
| ☐ | SV-254278r958478_rule | Windows Server 2022 must not have Windows PowerShell 2.0 installed. |
| ☐ | SV-254279r991589_rule | Windows Server 2022 FTP servers must be configured to prevent anonymous logons. |
| ☐ | SV-254280r991589_rule | Windows Server 2022 FTP servers must be configured to prevent access to the system drive. |
| ☐ | SV-254281r1051090_rule | The Windows Server 2022 time service must synchronize with an appropriate DOD time source. |
| ☐ | SV-254282r991589_rule | Windows Server 2022 must have orphaned security identifiers (SIDs) removed from user rights. |
| ☐ | SV-254283r991589_rule | Windows Server 2022 systems must have Unified Extensible Firmware Interface (UEFI) firmware and be configured to run in UEFI mode, not Legacy BIOS. |
| ☐ | SV-254284r991589_rule | Windows Server 2022 must have Secure Boot enabled. |
| ☐ | SV-254285r958736_rule | Windows Server 2022 account lockout duration must be configured to 15 minutes or greater. |
| ☐ | SV-254286r958388_rule | Windows Server 2022 must have the number of allowed bad logon attempts configured to three or less. |
| ☐ | SV-254287r958388_rule | Windows Server 2022 must have the period of time before the bad logon counter is reset configured to 15 minutes or greater. |
| ☐ | SV-254288r1000156_rule | Windows Server 2022 password history must be configured to 24 passwords remembered. |
| ☐ | SV-254289r1051091_rule | Windows Server 2022 maximum password age must be configured to 60 days or less. |
| ☐ | SV-254290r1051092_rule | Windows Server 2022 minimum password age must be configured to at least one day. |
| ☐ | SV-254291r1051093_rule | Windows Server 2022 minimum password length must be configured to 14 characters. |
| ☐ | SV-254292r1051094_rule | Windows Server 2022 must have the built-in Windows password complexity policy enabled. |
| ☐ | SV-254293r1051095_rule | Windows Server 2022 reversible password encryption must be disabled. |
| ☐ | SV-254294r958754_rule | Windows Server 2022 audit records must be backed up to a different system or media than the system being audited. |
| ☐ | SV-254295r959008_rule | Windows Server 2022 must, at a minimum, offload audit records of interconnected systems in real time and offload standalone or nondomain-joined systems weekly. |
| ☐ | SV-254296r958434_rule | Windows Server 2022 permissions for the Application event log must prevent access by nonprivileged accounts. |
| ☐ | SV-254297r958434_rule | Windows Server 2022 permissions for the Security event log must prevent access by nonprivileged accounts. |
| ☐ | SV-254298r958434_rule | Windows Server 2022 permissions for the System event log must prevent access by nonprivileged accounts. |
| ☐ | SV-254299r991558_rule | Windows Server 2022 Event Viewer must be protected from unauthorized modification and deletion. |
| ☐ | SV-254300r991578_rule | Windows Server 2022 must be configured to audit Account Logon - Credential Validation successes. |
| ☐ | SV-254301r991578_rule | Windows Server 2022 must be configured to audit Account Logon - Credential Validation failures. |
| ☐ | SV-254302r958732_rule | Windows Server 2022 must be configured to audit Account Management - Other Account Management Events successes. |
| ☐ | SV-254303r958368_rule | Windows Server 2022 must be configured to audit Account Management - Security Group Management successes. |
| ☐ | SV-254304r958368_rule | Windows Server 2022 must be configured to audit Account Management - User Account Management successes. |
| ☐ | SV-254305r958368_rule | Windows Server 2022 must be configured to audit Account Management - User Account Management failures. |
| ☐ | SV-254306r991583_rule | Windows Server 2022 must be configured to audit Detailed Tracking - Plug and Play Events successes. |
| ☐ | SV-254307r958732_rule | Windows Server 2022 must be configured to audit Detailed Tracking - Process Creation successes. |
| ☐ | SV-254309r991552_rule | Windows Server 2022 must be configured to audit Logon/Logoff - Account Lockout failures. |
| ☐ | SV-254310r991578_rule | Windows Server 2022 must be configured to audit Logon/Logoff - Group Membership successes. |
| ☐ | SV-254311r991581_rule | Windows Server 2022 must be configured to audit logoff successes. |
| ☐ | SV-254312r958406_rule | Windows Server 2022 must be configured to audit logon successes. |
| ☐ | SV-254313r958406_rule | Windows Server 2022 must be configured to audit logon failures. |
| ☐ | SV-254314r991578_rule | Windows Server 2022 must be configured to audit Logon/Logoff - Special Logon successes. |
| ☐ | SV-254315r991578_rule | Windows Server 2022 must be configured to audit Object Access - Other Object Access Events successes. |
| ☐ | SV-254316r991578_rule | Windows Server 2022 must be configured to audit Object Access - Other Object Access Events failures. |
| ☐ | SV-254317r991583_rule | Windows Server 2022 must be configured to audit Object Access - Removable Storage successes. |
| ☐ | SV-254318r991583_rule | Windows Server 2022 must be configured to audit Object Access - Removable Storage failures. |
| ☐ | SV-254319r958732_rule | Windows Server 2022 must be configured to audit Policy Change - Audit Policy Change successes. |
| ☐ | SV-254320r958732_rule | Windows Server 2022 must be configured to audit Policy Change - Audit Policy Change failures. |
| ☐ | SV-254321r958732_rule | Windows Server 2022 must be configured to audit Policy Change - Authentication Policy Change successes. |
| ☐ | SV-254322r958732_rule | Windows Server 2022 must be configured to audit Policy Change - Authorization Policy Change successes. |
| ☐ | SV-254323r958732_rule | Windows Server 2022 must be configured to audit Privilege Use - Sensitive Privilege Use successes. |
| ☐ | SV-254324r958732_rule | Windows Server 2022 must be configured to audit Privilege Use - Sensitive Privilege Use failures. |
| ☐ | SV-254325r958732_rule | Windows Server 2022 must be configured to audit System - IPsec Driver successes. |
| ☐ | SV-254326r958732_rule | Windows Server 2022 must be configured to audit System - IPsec Driver failures. |
| ☐ | SV-254327r958732_rule | Windows Server 2022 must be configured to audit System - Other System Events successes. |
| ☐ | SV-254328r958732_rule | Windows Server 2022 must be configured to audit System - Other System Events failures. |
| ☐ | SV-254329r958732_rule | Windows Server 2022 must be configured to audit System - Security State Change successes. |
| ☐ | SV-254330r958732_rule | Windows Server 2022 must be configured to audit System - Security System Extension successes. |
| ☐ | SV-254331r958732_rule | Windows Server 2022 must be configured to audit System - System Integrity successes. |
| ☐ | SV-254332r958732_rule | Windows Server 2022 must be configured to audit System - System Integrity failures. |
| ☐ | SV-254333r958478_rule | Windows Server 2022 must prevent the display of slide shows on the lock screen. |
| ☐ | SV-254334r958478_rule | Windows Server 2022 must have WDigest Authentication disabled. |
| ☐ | SV-254335r991589_rule | Windows Server 2022 Internet Protocol version 6 (IPv6) source routing must be configured to the highest protection level to prevent IP source routing. |
| ☐ | SV-254336r991589_rule | Windows Server 2022 source routing must be configured to the highest protection level to prevent Internet Protocol (IP) source routing. |
| ☐ | SV-254337r991589_rule | Windows Server 2022 must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF)-generated routes. |
| ☐ | SV-254338r958902_rule | Windows Server 2022 must be configured to ignore NetBIOS name release requests except from WINS servers. |
| ☐ | SV-254339r991589_rule | Windows Server 2022 insecure logons to an SMB server must be disabled. |
| ☐ | SV-254340r991589_rule | Windows Server 2022 hardened Universal Naming Convention (UNC) paths must be defined to require mutual authentication and integrity for at least the \\*\SYSVOL and \\*\NETLOGON shares. |
| ☐ | SV-254341r958422_rule | Windows Server 2022 command line data must be included in process creation events. |
| ☐ | SV-254342r991589_rule | Windows Server 2022 must be configured to enable Remote host allows delegation of nonexportable credentials. |
| ☐ | SV-254343r991589_rule | Windows Server 2022 virtualization-based security must be enabled with the platform security level configured to Secure Boot or Secure Boot with DMA Protection. |
| ☐ | SV-254344r991589_rule | Windows Server 2022 Early Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers identified as bad. |
| ☐ | SV-254345r1135378_rule | Windows Server 2022 group policy objects must be reprocessed even if they have not changed. |
| ☐ | SV-254346r958478_rule | Windows Server 2022 downloading print driver packages over HTTP must be turned off. |
| ☐ | SV-254347r958478_rule | Windows Server 2022 printing over HTTP must be turned off. |
| ☐ | SV-254348r958478_rule | Windows Server 2022 network selection user interface (UI) must not be displayed on the logon screen. |
| ☐ | SV-254349r991589_rule | Windows Server 2022 users must be prompted to authenticate when the system wakes from sleep (on battery). |
| ☐ | SV-254350r991589_rule | Windows Server 2022 users must be prompted to authenticate when the system wakes from sleep (plugged in). |
| ☐ | SV-254351r958478_rule | Windows Server 2022 Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft. |
| ☐ | SV-254352r958804_rule | Windows Server 2022 Autoplay must be turned off for nonvolume devices. |
| ☐ | SV-254353r958804_rule | Windows Server 2022 default AutoRun behavior must be configured to prevent AutoRun commands. |
| ☐ | SV-254354r958804_rule | Windows Server 2022 AutoPlay must be disabled for all drives. |
| ☐ | SV-254355r958518_rule | Windows Server 2022 administrator accounts must not be enumerated during elevation. |
| ☐ | SV-254356r991589_rule | Windows Server 2022 Diagnostic Data must be configured to send "required diagnostic data" or "optional diagnostic data". |
| ☐ | SV-254357r991589_rule | Windows Server 2022 Windows Update must not obtain updates from other PCs on the internet. |
| ☐ | SV-254358r958752_rule | Windows Server 2022 Application event log size must be configured to 32768 KB or greater. |
| ☐ | SV-254359r1210268_rule | The Windows Server 2022 security event log size must be configured to a value that holds at least one week's worth of audit records. |
| ☐ | SV-254360r958752_rule | Windows Server 2022 System event log size must be configured to 32768 KB or greater. |
| ☐ | SV-254361r958478_rule | Windows Server 2022 Microsoft Defender antivirus SmartScreen must be enabled. |
| ☐ | SV-254362r958928_rule | Windows Server 2022 Explorer Data Execution Prevention must be enabled. |
| ☐ | SV-254363r991589_rule | Windows Server 2022 Turning off File Explorer heap termination on corruption must be disabled. |
| ☐ | SV-254364r991589_rule | Windows Server 2022 File Explorer shell protocol must run in protected mode. |
| ☐ | SV-254365r1051096_rule | Windows Server 2022 must not save passwords in the Remote Desktop Client. |
| ☐ | SV-254366r1137695_rule | Windows Server 2022 Remote Desktop Services must prevent drive redirection. |
| ☐ | SV-254367r1051097_rule | Windows Server 2022 Remote Desktop Services must always prompt a client for passwords upon connection. |
| ☐ | SV-254368r958408_rule | Windows Server 2022 Remote Desktop Services must require secure Remote Procedure Call (RPC) communications. |
| ☐ | SV-254369r958408_rule | Windows Server 2022 Remote Desktop Services must be configured with the client connection encryption set to High Level. |
| ☐ | SV-254370r991589_rule | Windows Server 2022 must prevent attachments from being downloaded from RSS feeds. |
| ☐ | SV-254371r958478_rule | Windows Server 2022 must disable Basic authentication for RSS feeds over HTTP. |
| ☐ | SV-254372r958478_rule | Windows Server 2022 must prevent Indexing of encrypted files. |
| ☐ | SV-254373r1051098_rule | Windows Server 2022 must prevent users from changing installation options. |
| ☐ | SV-254374r1051099_rule | Windows Server 2022 must disable the Windows Installer Always install with elevated privileges option. |
| ☐ | SV-254375r991589_rule | Windows Server 2022 users must be notified if a web-based program attempts to install software. |
| ☐ | SV-254376r991591_rule | Windows Server 2022 must disable automatically signing in the last interactive user after a system-initiated restart. |
| ☐ | SV-254377r958422_rule | Windows Server 2022 PowerShell script block logging must be enabled. |
| ☐ | SV-254378r958510_rule | Windows Server 2022 Windows Remote Management (WinRM) client must not use Basic authentication. |
| ☐ | SV-254379r958848_rule | Windows Server 2022 Windows Remote Management (WinRM) client must not allow unencrypted traffic. |
| ☐ | SV-254380r958510_rule | Windows Server 2022 Windows Remote Management (WinRM) client must not use Digest authentication. |
| ☐ | SV-254381r958510_rule | Windows Server 2022 Windows Remote Management (WinRM) service must not use Basic authentication. |
| ☐ | SV-254382r958848_rule | Windows Server 2022 Windows Remote Management (WinRM) service must not allow unencrypted traffic. |
| ☐ | SV-254383r1051100_rule | Windows Server 2022 Windows Remote Management (WinRM) service must not store RunAs credentials. |
| ☐ | SV-254384r958420_rule | Windows Server 2022 must have PowerShell Transcription enabled. |
| ☐ | SV-254385r958726_rule | Windows Server 2022 must only allow administrators responsible for the domain controller to have Administrator rights on the system. |
| ☐ | SV-254386r1051101_rule | Windows Server 2022 Kerberos user logon restrictions must be enforced. |
| ☐ | SV-254387r1051102_rule | Windows Server 2022 Kerberos service ticket maximum lifetime must be limited to 600 minutes or less. |
| ☐ | SV-254388r1051103_rule | Windows Server 2022 Kerberos user ticket lifetime must be limited to 10 hours or less. |
| ☐ | SV-254389r1051104_rule | Windows Server 2022 Kerberos policy user ticket renewal maximum lifetime must be limited to seven days or less. |
| ☐ | SV-254390r1051105_rule | Windows Server 2022 computer clock synchronization tolerance must be limited to five minutes or less. |
| ☐ | SV-254391r958726_rule | Windows Server 2022 permissions on the Active Directory data files must only allow System and Administrators access. |
| ☐ | SV-254392r958726_rule | Windows Server 2022 Active Directory SYSVOL directory must have the proper access control permissions. |
| ☐ | SV-254393r1081073_rule | Windows Server 2022 Active Directory Group Policy objects must have proper access control permissions. |
| ☐ | SV-254394r958726_rule | Windows Server 2022 Active Directory Domain Controllers Organizational Unit (OU) object must have the proper access control permissions. |
| ☐ | SV-254395r958726_rule | Windows Server 2022 organization created Active Directory Organizational Unit (OU) objects must have proper access control permissions. |
| ☐ | SV-254396r1137695_rule | Windows Server 2022 data files owned by users must be on a different logical partition from the directory server data files. |
| ☐ | SV-254397r958478_rule | Windows Server 2022 domain controllers must run on a machine dedicated to that function. |
| ☐ | SV-254398r987791_rule | Windows Server 2022 must use separate, NSA-approved (Type 1) cryptography to protect the directory data in transit for directory service implementations at a classified confidentiality level when replication data traverses a network cleared to a lower level than the data. |
| ☐ | SV-254399r991589_rule | Windows Server 2022 directory data (outside the root DSE) of a nonpublic directory must be configured to prevent anonymous access. |
| ☐ | SV-254400r970703_rule | Windows Server 2022 directory service must be configured to terminate LDAP-based network connections to the directory server after five minutes of inactivity. |
| ☐ | SV-254401r958732_rule | Windows Server 2022 Active Directory Group Policy objects must be configured with proper audit settings. |
| ☐ | SV-254402r958732_rule | Windows Server 2022 Active Directory Domain object must be configured with proper audit settings. |
| ☐ | SV-254403r1210271_rule | Windows Server 2022 Active Directory Infrastructure object must be configured with proper audit settings. |
| ☐ | SV-254404r958732_rule | Windows Server 2022 Active Directory Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings. |
| ☐ | SV-254405r1210274_rule | Windows Server 2022 Active Directory AdminSDHolder object must be configured with proper audit settings. |
| ☐ | SV-254406r958732_rule | Windows Server 2022 Active Directory RID Manager$ object must be configured with proper audit settings. |
| ☐ | SV-254407r958368_rule | Windows Server 2022 must be configured to audit Account Management - Computer Account Management successes. |
| ☐ | SV-254408r958732_rule | Windows Server 2022 must be configured to audit DS Access - Directory Service Access successes. |
| ☐ | SV-254409r958732_rule | Windows Server 2022 must be configured to audit DS Access - Directory Service Access failures. |
| ☐ | SV-254410r958732_rule | Windows Server 2022 must be configured to audit DS Access - Directory Service Changes successes. |
| ☐ | SV-254412r958448_rule | Windows Server 2022 domain controllers must have a PKI server certificate. |
| ☐ | SV-254413r1153446_rule | Windows Server 2022 domain controller PKI certificates must be issued by the DOD PKI or an approved External Certificate Authority (ECA). |
| ☐ | SV-254414r958448_rule | Windows Server 2022 PKI certificates associated with user accounts must be issued by a DoD PKI or an approved External Certificate Authority (ECA). |
| ☐ | SV-254415r1210275_rule | Windows Server 2022 Active Directory user accounts, including administrators, must be configured to require the use of a Common Access Card (CAC), Personal Identity Verification (PIV)-compliant hardware token, or Alternate Logon Token (ALT) for user authentication. |
| ☐ | SV-254416r958908_rule | Windows Server 2022 domain controllers must require LDAP access signing. |
| ☐ | SV-254417r991589_rule | Windows Server 2022 domain controllers must be configured to allow reset of machine account passwords. |
| ☐ | SV-254418r1137691_rule | Windows Server 2022 Access this computer from the network user right must only be assigned to the Administrators, Authenticated Users, and
Enterprise Domain Controllers groups on domain controllers. |
| ☐ | SV-254419r958726_rule | Windows Server 2022 Add workstations to domain user right must only be assigned to the Administrators group on domain controllers. |
| ☐ | SV-254420r1137691_rule | Windows Server 2022 Allow log on through Remote Desktop Services user right must only be assigned to the Administrators group on domain controllers. |
| ☐ | SV-254421r1137691_rule | Windows Server 2022 Deny access to this computer from the network user right on domain controllers must be configured to prevent unauthenticated access. |
| ☐ | SV-254422r1137691_rule | Windows Server 2022 Deny log on as a batch job user right on domain controllers must be configured to prevent unauthenticated access. |
| ☐ | SV-254423r1137691_rule | Windows Server 2022 Deny log on as a service user right must be configured to include no accounts or groups (blank) on domain controllers. |
| ☐ | SV-254424r1137691_rule | Windows Server 2022 Deny log on locally user right on domain controllers must be configured to prevent unauthenticated access. |
| ☐ | SV-254425r958672_rule | Windows Server 2022 Deny log on through Remote Desktop Services user right on domain controllers must be configured to prevent unauthenticated access. |
| ☐ | SV-254426r958726_rule | Windows Server 2022 Enable computer and user accounts to be trusted for delegation user right must only be assigned to the Administrators group on domain controllers. |
| ☐ | SV-254427r991589_rule | The password for the krbtgt account on a domain must be reset at least every 180 days. |
| ☐ | SV-254428r958726_rule | Windows Server 2022 must only allow administrators responsible for the member server or standalone or nondomain-joined system to have Administrator rights on the system. |
| ☐ | SV-254429r958518_rule | Windows Server 2022 local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain-joined member servers. |
| ☐ | SV-254430r958478_rule | Windows Server 2022 local users on domain-joined member servers must not be enumerated. |
| ☐ | SV-254431r971545_rule | Windows Server 2022 must restrict unauthenticated Remote Procedure Call (RPC) clients from connecting to the RPC server on domain-joined member servers and standalone or nondomain-joined systems. |
| ☐ | SV-254432r991589_rule | Windows Server 2022 must limit the caching of logon credentials to four or less on domain-joined member servers. |
| ☐ | SV-254433r1106522_rule | Windows Server 2022 must restrict remote calls to the Security Account Manager (SAM) to Administrators on domain-joined member servers and standalone or nondomain-joined systems. |
| ☐ | SV-254434r1137691_rule | Windows Server 2022 Access this computer from the network user right must only be assigned to the Administrators and Authenticated Users groups on domain-joined member servers and standalone or nondomain-joined systems. |
| ☐ | SV-254435r1137691_rule | Windows Server 2022 Deny access to this computer from the network user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and local accounts and from unauthenticated access on all systems. |
| ☐ | SV-254436r1137691_rule | Windows Server 2022 Deny log on as a batch job user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems. |
| ☐ | SV-254437r1137691_rule | Windows Server 2022 Deny log on as a service user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts. No other groups or accounts must be assigned this right. |
| ☐ | SV-254438r1137691_rule | Windows Server 2022 Deny log on locally user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems. |
| ☐ | SV-254439r958672_rule | Windows Server 2022 Deny log on through Remote Desktop Services user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and all local accounts and from unauthenticated access on all systems. |
| ☐ | SV-254440r958726_rule | Windows Server 2022 Enable computer and user accounts to be trusted for delegation user right must not be assigned to any groups or accounts on domain-joined member servers and standalone or nondomain-joined systems. |
| ☐ | SV-254441r991589_rule | Windows Server 2022 must be running Credential Guard on domain-joined member servers. |
| ☐ | SV-254442r1210278_rule | Windows Server 2022 must have the DOD Root Certificate Authority (CA) certificates installed in the Trusted Root Store. |
| ☐ | SV-254443r958448_rule | Windows Server 2022 must have the DoD Interoperability Root Certificate Authority (CA) cross-certificates installed in the Untrusted Certificates Store on unclassified systems. |
| ☐ | SV-254444r1081077_rule | Windows Server 2022 must have the US DOD CCEB Interoperability Root CA cross-certificates in the Untrusted Certificates Store on unclassified systems. |
| ☐ | SV-254445r958504_rule | Windows Server 2022 must have the built-in guest account disabled. |
| ☐ | SV-254446r991589_rule | Windows Server 2022 must prevent local accounts with blank passwords from being used from the network. |
| ☐ | SV-254447r991589_rule | Windows Server 2022 built-in administrator account must be renamed. |
| ☐ | SV-254448r991589_rule | Windows Server 2022 built-in guest account must be renamed. |
| ☐ | SV-254449r958442_rule | Windows Server 2022 must force audit policy subcategory settings to override audit policy category settings. |
| ☐ | SV-254450r958908_rule | Windows Server 2022 setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled. |
| ☐ | SV-254451r958908_rule | Windows Server 2022 setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to Enabled. |
| ☐ | SV-254452r958908_rule | Windows Server 2022 setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled. |
| ☐ | SV-254453r971545_rule | Windows Server 2022 computer account password must not be prevented from being reset. |
| ☐ | SV-254454r991589_rule | Windows Server 2022 maximum age for machine account passwords must be configured to 30 days or less. |
| ☐ | SV-254455r958908_rule | Windows Server 2022 must be configured to require a strong session key. |
| ☐ | SV-254456r958400_rule | Windows Server 2022 machine inactivity limit must be set to 15 minutes or less, locking the system with the screen saver. |
| ☐ | SV-254457r958390_rule | Windows Server 2022 required legal notice must be configured to display before console logon. |
| ☐ | SV-254458r958390_rule | Windows Server 2022 title for legal banner dialog box must be configured with the appropriate text. |
| ☐ | SV-254459r991589_rule | Windows Server 2022 Smart Card removal option must be configured to Force Logoff or Lock Workstation. |
| ☐ | SV-254460r958908_rule | Windows Server 2022 setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled. |
| ☐ | SV-254461r958908_rule | Windows Server 2022 setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled. |
| ☐ | SV-254462r987796_rule | Windows Server 2022 unencrypted passwords must not be sent to third-party Server Message Block (SMB) servers. |
| ☐ | SV-254463r958908_rule | Windows Server 2022 setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled. |
| ☐ | SV-254464r958908_rule | Windows Server 2022 setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled. |
| ☐ | SV-254465r991589_rule | Windows Server 2022 must not allow anonymous SID/Name translation. |
| ☐ | SV-254466r991589_rule | Windows Server 2022 must not allow anonymous enumeration of Security Account Manager (SAM) accounts. |
| ☐ | SV-254467r1137695_rule | Windows Server 2022 must not allow anonymous enumeration of shares. |
| ☐ | SV-254468r991589_rule | Windows Server 2022 must be configured to prevent anonymous users from having the same permissions as the Everyone group. |
| ☐ | SV-254469r1137695_rule | Windows Server 2022 must restrict anonymous access to Named Pipes and Shares. |
| ☐ | SV-254470r991589_rule | Windows Server 2022 services using Local System that use Negotiate when reverting to NTLM authentication must use the computer identity instead of authenticating anonymously. |
| ☐ | SV-254471r991589_rule | Windows Server 2022 must prevent NTLM from falling back to a Null session. |
| ☐ | SV-254472r991589_rule | Windows Server 2022 must prevent PKU2U authentication using online identities. |
| ☐ | SV-254473r971535_rule | Windows Server 2022 Kerberos encryption types must be configured to prevent the use of DES and RC4 encryption suites. |
| ☐ | SV-254474r1051107_rule | Windows Server 2022 must be configured to prevent the storage of the LAN Manager hash of passwords. |
| ☐ | SV-254475r991589_rule | Windows Server 2022 LAN Manager authentication level must be configured to send NTLMv2 response only and to refuse LM and NTLM. |
| ☐ | SV-254476r991589_rule | Windows Server 2022 must be configured to at least negotiate signing for LDAP client signing. |
| ☐ | SV-254477r991589_rule | Windows Server 2022 session security for NTLM SSP-based clients must be configured to require NTLMv2 session security and 128-bit encryption. |
| ☐ | SV-254478r991589_rule | Windows Server 2022 session security for NTLM SSP-based servers must be configured to require NTLMv2 session security and 128-bit encryption. |
| ☐ | SV-254479r958450_rule | Windows Server 2022 users must be required to enter a password to access private keys stored on the computer. |
| ☐ | SV-254480r1137699_rule | Windows Server 2022 must be configured to use FIPS-compliant algorithms for encryption, hashing, and signing. |
| ☐ | SV-254481r991589_rule | Windows Server 2022 default permissions of global system objects must be strengthened. |
| ☐ | SV-254482r1051108_rule | Windows Server 2022 User Account Control (UAC) approval mode for the built-in Administrator must be enabled. |
| ☐ | SV-254483r958518_rule | Windows Server 2022 UIAccess applications must not be allowed to prompt for elevation without using the secure desktop. |
| ☐ | SV-254484r958518_rule | Windows Server 2022 User Account Control (UAC) must, at a minimum, prompt administrators for consent on the secure desktop. |
| ☐ | SV-254485r1051109_rule | Windows Server 2022 User Account Control (UAC) must automatically deny standard user requests for elevation. |
| ☐ | SV-254486r958518_rule | Windows Server 2022 User Account Control (UAC) must be configured to detect application installations and prompt for elevation. |
| ☐ | SV-254487r958518_rule | Windows Server 2022 User Account Control (UAC) must only elevate UIAccess applications that are installed in secure locations. |
| ☐ | SV-254488r1051110_rule | Windows Server 2022 User Account Control (UAC) must run all administrators in Admin Approval Mode, enabling UAC. |
| ☐ | SV-254489r958518_rule | Windows Server 2022 User Account Control (UAC) must virtualize file and registry write failures to per-user locations. |
| ☐ | SV-254490r991589_rule | Windows Server 2022 must preserve zone information when saving attachments. |
| ☐ | SV-254491r958726_rule | Windows Server 2022 Access Credential Manager as a trusted caller user right must not be assigned to any groups or accounts. |
| ☐ | SV-254492r958726_rule | Windows Server 2022 Act as part of the operating system user right must not be assigned to any groups or accounts. |
| ☐ | SV-254493r1137691_rule | Windows Server 2022 Allow log on locally user right must only be assigned to the Administrators group. |
| ☐ | SV-254494r958726_rule | Windows Server 2022 back up files and directories user right must only be assigned to the Administrators group. |
| ☐ | SV-254495r958726_rule | Windows Server 2022 create a pagefile user right must only be assigned to the Administrators group. |
| ☐ | SV-254496r958726_rule | Windows Server 2022 create a token object user right must not be assigned to any groups or accounts. |
| ☐ | SV-254497r958726_rule | Windows Server 2022 create global objects user right must only be assigned to Administrators, Service, Local Service, and Network Service. |
| ☐ | SV-254498r958726_rule | Windows Server 2022 create permanent shared objects user right must not be assigned to any groups or accounts. |
| ☐ | SV-254499r958726_rule | Windows Server 2022 create symbolic links user right must only be assigned to the Administrators group. |
| ☐ | SV-254500r958726_rule | Windows Server 2022 debug programs user right must only be assigned to the Administrators group. |
| ☐ | SV-254501r958726_rule | Windows Server 2022 force shutdown from a remote system user right must only be assigned to the Administrators group. |
| ☐ | SV-254502r958726_rule | Windows Server 2022 generate security audits user right must only be assigned to Local Service and Network Service. |
| ☐ | SV-254503r958726_rule | Windows Server 2022 impersonate a client after authentication user right must only be assigned to Administrators, Service, Local Service, and Network Service. |
| ☐ | SV-254504r958726_rule | Windows Server 2022 increase scheduling priority: user right must only be assigned to the Administrators group. |
| ☐ | SV-254505r958726_rule | Windows Server 2022 load and unload device drivers user right must only be assigned to the Administrators group. |
| ☐ | SV-254506r958726_rule | Windows Server 2022 lock pages in memory user right must not be assigned to any groups or accounts. |
| ☐ | SV-254507r958434_rule | Windows Server 2022 manage auditing and security log user right must only be assigned to the Administrators group. |
| ☐ | SV-254508r958726_rule | Windows Server 2022 modify firmware environment values user right must only be assigned to the Administrators group. |
| ☐ | SV-254509r958726_rule | Windows Server 2022 perform volume maintenance tasks user right must only be assigned to the Administrators group. |
| ☐ | SV-254510r958726_rule | Windows Server 2022 profile single process user right must only be assigned to the Administrators group. |
| ☐ | SV-254511r958726_rule | Windows Server 2022 restore files and directories user right must only be assigned to the Administrators group. |
| ☐ | SV-254512r958726_rule | Windows Server 2022 take ownership of files or other objects user right must only be assigned to the Administrators group. |
| ☐ | SV-271426r1137691_rule | Windows Server 2022 must be configured for certificate-based authentication for domain controllers. |
| ☐ | SV-271427r1137691_rule | Windows Server 2022 must be configured for name-based strong mappings for certificates. |
| ☐ | SV-278944r1135361_rule | Windows Server 2022 must be configured to audit handle manipulation failures. |
| ☐ | SV-278946r1135367_rule | Windows Server 2022 must be configured to audit registry failures. |
| ☐ | SV-278947r1135370_rule | Windows Server 2022 must be configured to audit registry successes. |
| ☐ | SV-278948r1141928_rule | Windows Server 2022 must be configured to audit sensitive privilege use successes. |
| ☐ | SV-278949r1141931_rule | Windows Server 2022 must be configured to audit sensitive privilege use failures. |