| Checked | Name | Title |
|---|
| ☐ | SV-277982r1181944_rule | Windows Server 2025 must install security-relevant software updates within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs). |
| ☐ | SV-277983r1180655_rule | Windows Server 2025 must prohibit the use or connection of unauthorized hardware components. |
| ☐ | SV-277985r1182240_rule | Windows Server 2025 users with administrative privileges must have separate accounts for administrative duties and normal operational tasks. |
| ☐ | SV-277986r1182007_rule | Windows Server 2025 passwords for the built-in Administrator account must be changed at least every 60 days. |
| ☐ | SV-277987r1212169_rule | Windows Server 2025 administrative accounts must not be used with applications that access the internet, such as web browsers, or with potential internet sources, such as email. |
| ☐ | SV-277988r1182011_rule | Windows Server 2025 members of the Backup Operators group must have separate accounts for backup duties and normal operational tasks. |
| ☐ | SV-277989r1181947_rule | Windows Server 2025 manually managed application account passwords must be at least 15 characters in length. |
| ☐ | SV-277990r1182248_rule | Windows Server 2025 manually managed application account passwords must be changed at least annually or when a system administrator with knowledge of the password leaves the organization. |
| ☐ | SV-277991r1181778_rule | Windows Server 2025 shared user accounts must not be permitted. |
| ☐ | SV-277992r1182016_rule | Windows Server 2025 must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs. |
| ☐ | SV-277993r1212171_rule | Windows Server 2025 systems must have a Trusted Platform Module (TPM) enabled and ready for use. |
| ☐ | SV-277995r1180691_rule | Windows Server 2025 must use an antivirus program. |
| ☐ | SV-277996r1182235_rule | Windows Server 2025 must have a host-based intrusion detection and prevention service (IDPS) installed. |
| ☐ | SV-277997r1182022_rule | Windows Server 2025 local volumes must use a format that supports New Technology File System (NTFS) attributes. |
| ☐ | SV-277998r1180700_rule | Windows Server 2025 permissions for the system drive root directory (usually C:\) must conform to minimum requirements. |
| ☐ | SV-277999r1180703_rule | Windows Server 2025 permissions for program file directories must conform to minimum requirements. |
| ☐ | SV-278000r1182252_rule | Windows Server 2025 permissions for the Windows installation directory must conform to minimum requirements. |
| ☐ | SV-278001r1211143_rule | Windows Server 2025 default permissions for the HKEY_LOCAL_MACHINE registry hive must be maintained. |
| ☐ | SV-278002r1181785_rule | Windows Server 2025 nonadministrative accounts or groups must only have print permissions on printer shares. |
| ☐ | SV-278003r1182254_rule | Outdated or unused accounts on Windows Server 2025 must be removed or disabled. |
| ☐ | SV-278004r1182256_rule | Windows Server 2025 accounts must require passwords. |
| ☐ | SV-278005r1182259_rule | Windows Server 2025 passwords must be configured to expire. |
| ☐ | SV-278006r1182237_rule | Windows Server 2025 system files must be monitored for unauthorized changes. |
| ☐ | SV-278007r1181789_rule | Windows Server 2025 nonsystem-created file shares must limit access to groups that require it. |
| ☐ | SV-278008r1211146_rule | Windows Server 2025 must have software certificate installation files removed. |
| ☐ | SV-278009r1211149_rule | Windows Server 2025 systems requiring data-at-rest protections must employ cryptographic mechanisms to prevent unauthorized disclosure and modification of the information at rest. |
| ☐ | SV-278010r1180736_rule | Windows Server 2025 must implement protection methods such as TLS, encrypted VPNs, or IPsec if the data owner has a strict requirement for ensuring data integrity and confidentiality is maintained at every step of the data transfer and handling process. |
| ☐ | SV-278011r1182239_rule | Windows Server 2025 must have the roles and features required by the system documented. |
| ☐ | SV-278012r1181951_rule | Windows Server 2025 must have a host-based firewall installed and enabled. |
| ☐ | SV-278013r1182261_rule | Windows Server 2025 must automatically remove or disable temporary user accounts after 72 hours. |
| ☐ | SV-278014r1182263_rule | Windows Server 2025 must automatically remove or disable emergency accounts after the crisis is resolved or within 72 hours. |
| ☐ | SV-278015r1180751_rule | Windows Server 2025 must not have the Fax Server role installed. |
| ☐ | SV-278016r1181795_rule | Windows Server 2025 must not have the Microsoft FTP service installed unless required by the organization. |
| ☐ | SV-278017r1180757_rule | Windows Server 2025 must not have Wi-Fi enabled unless required by the organization. |
| ☐ | SV-278018r1180760_rule | Windows Server 2025 must not have Bluetooth enabled unless required by the organization. |
| ☐ | SV-278019r1180763_rule | Windows Server 2025 must not have the Peer Name Resolution Protocol installed. |
| ☐ | SV-278020r1180766_rule | Windows Server 2025 must not have Simple TCP/IP Services installed. |
| ☐ | SV-278021r1180769_rule | Windows Server 2025 must not have the Telnet Client installed. |
| ☐ | SV-278022r1180772_rule | Windows Server 2025 must not have the TFTP Client installed. |
| ☐ | SV-278023r1182034_rule | Windows Server 2025 must not have the Server Message Block (SMB) v1 protocol installed. |
| ☐ | SV-278024r1182036_rule | Windows Server 2025 must have the Server Message Block (SMB) v1 protocol disabled on the SMB server. |
| ☐ | SV-278025r1182038_rule | Windows Server 2025 must have the Server Message Block (SMB) v1 protocol disabled on the SMB client. |
| ☐ | SV-278026r1180784_rule | Windows Server 2025 must not have Windows PowerShell 2.0 installed. |
| ☐ | SV-278027r1181803_rule | Windows Server 2025 FTP servers must be configured to prevent anonymous logons. |
| ☐ | SV-278028r1182265_rule | Windows Server 2025 FTP servers must be configured to prevent access to the system drive. |
| ☐ | SV-278029r1182267_rule | The Windows Server 2025 time service must synchronize with an appropriate DOD time source. |
| ☐ | SV-278030r1182043_rule | Windows Server 2025 must have orphaned security identifiers (SIDs) removed from user rights. |
| ☐ | SV-278031r1182046_rule | Windows Server 2025 systems must have Unified Extensible Firmware Interface (UEFI) firmware and be configured to run in UEFI mode, not Legacy BIOS. |
| ☐ | SV-278032r1180802_rule | Windows Server 2025 must have Secure Boot enabled. |
| ☐ | SV-278033r1180805_rule | Windows Server 2025 account lockout duration must be configured to 15 minutes or greater. |
| ☐ | SV-278034r1180808_rule | Windows Server 2025 must have the number of allowed bad logon attempts configured to three or less. |
| ☐ | SV-278035r1180811_rule | Windows Server 2025 must have the period of time before the bad logon counter is reset configured to 15 minutes or greater. |
| ☐ | SV-278036r1180814_rule | Windows Server 2025 password history must be configured to 24 passwords remembered. |
| ☐ | SV-278037r1180817_rule | Windows Server 2025 maximum password age must be configured to 60 days or less. |
| ☐ | SV-278038r1180820_rule | Windows Server 2025 minimum password age must be configured to at least one day. |
| ☐ | SV-278039r1180823_rule | Windows Server 2025 must have the built-in Windows password complexity policy enabled. |
| ☐ | SV-278040r1180826_rule | Windows Server 2025 reversible password encryption must be disabled. |
| ☐ | SV-278041r1180829_rule | Windows Server 2025 audit records must be backed up to a different system or media than the system being audited. |
| ☐ | SV-278042r1182270_rule | Windows Server 2025 must, at a minimum, off-load audit records of interconnected systems in real time and off-load stand-alone or nondomain-joined systems weekly. |
| ☐ | SV-278043r1180835_rule | Windows Server 2025 permissions for the Application event log must prevent access by nonprivileged accounts. |
| ☐ | SV-278044r1182051_rule | Windows Server 2025 permissions for the Security event log must prevent access by nonprivileged accounts. |
| ☐ | SV-278045r1180841_rule | Windows Server 2025 permissions for the System event log must prevent access by nonprivileged accounts. |
| ☐ | SV-278046r1211151_rule | Windows Server 2025 Event Viewer must be protected from unauthorized modification and deletion. |
| ☐ | SV-278047r1180847_rule | Windows Server 2025 must be configured to audit Account Logon - Credential Validation successes. |
| ☐ | SV-278048r1180850_rule | Windows Server 2025 must be configured to audit Account Logon - Credential Validation failures. |
| ☐ | SV-278049r1180853_rule | Windows Server 2025 must be configured to audit Account Management - Other Account Management Events successes. |
| ☐ | SV-278050r1180856_rule | Windows Server 2025 must be configured to audit Account Management - Security Group Management successes. |
| ☐ | SV-278051r1180859_rule | Windows Server 2025 must be configured to audit Account Management - User Account Management successes. |
| ☐ | SV-278052r1180862_rule | Windows Server 2025 must be configured to audit Account Management - User Account Management failures. |
| ☐ | SV-278053r1180865_rule | Windows Server 2025 must be configured to audit Detailed Tracking - Plug and Play Events successes. |
| ☐ | SV-278054r1180868_rule | Windows Server 2025 must be configured to audit Detailed Tracking - Process Creation successes. |
| ☐ | SV-278055r1180871_rule | Windows Server 2025 must be configured to audit Logon/Logoff - Account Lockout successes. |
| ☐ | SV-278056r1180874_rule | Windows Server 2025 must be configured to audit Logon/Logoff - Account Lockout failures. |
| ☐ | SV-278057r1180877_rule | Windows Server 2025 must be configured to audit Logon/Logoff - Group Membership successes. |
| ☐ | SV-278058r1180880_rule | Windows Server 2025 must be configured to audit logoff successes. |
| ☐ | SV-278059r1180883_rule | Windows Server 2025 must be configured to audit logon successes. |
| ☐ | SV-278060r1180886_rule | Windows Server 2025 must be configured to audit logon failures. |
| ☐ | SV-278061r1180889_rule | Windows Server 2025 must be configured to audit Logon/Logoff - Special Logon successes. |
| ☐ | SV-278062r1180892_rule | Windows Server 2025 must be configured to audit Object Access - Other Object Access Events successes. |
| ☐ | SV-278063r1180895_rule | Windows Server 2025 must be configured to audit Object Access - Other Object Access Events failures. |
| ☐ | SV-278064r1180898_rule | Windows Server 2025 must be configured to audit Object Access - Removable Storage successes. |
| ☐ | SV-278065r1180901_rule | Windows Server 2025 must be configured to audit Object Access - Removable Storage failures. |
| ☐ | SV-278066r1180904_rule | Windows Server 2025 must be configured to audit Policy Change - Audit Policy Change successes. |
| ☐ | SV-278067r1180907_rule | Windows Server 2025 must be configured to audit Policy Change - Audit Policy Change failures. |
| ☐ | SV-278068r1180910_rule | Windows Server 2025 must be configured to audit Policy Change - Authentication Policy Change successes. |
| ☐ | SV-278069r1180913_rule | Windows Server 2025 must be configured to audit Policy Change - Authorization Policy Change successes. |
| ☐ | SV-278070r1180916_rule | Windows Server 2025 must be configured to audit Privilege Use - Sensitive Privilege Use successes. |
| ☐ | SV-278071r1180919_rule | Windows Server 2025 must be configured to audit Privilege Use - Sensitive Privilege Use failures. |
| ☐ | SV-278072r1180922_rule | Windows Server 2025 must be configured to audit System - IPsec Driver successes. |
| ☐ | SV-278073r1180925_rule | Windows Server 2025 must be configured to audit System - IPsec Driver failures. |
| ☐ | SV-278074r1180928_rule | Windows Server 2025 must be configured to audit System - Other System Events successes. |
| ☐ | SV-278075r1180931_rule | Windows Server 2025 must be configured to audit System - Other System Events failures. |
| ☐ | SV-278076r1180934_rule | Windows Server 2025 must be configured to audit System - Security State Change successes. |
| ☐ | SV-278077r1180937_rule | Windows Server 2025 must be configured to audit System - Security System Extension successes. |
| ☐ | SV-278078r1180940_rule | Windows Server 2025 must be configured to audit System - System Integrity successes. |
| ☐ | SV-278079r1180943_rule | Windows Server 2025 must be configured to audit System - System Integrity failures. |
| ☐ | SV-278080r1180946_rule | Windows Server 2025 must prevent the display of slide shows on the lock screen. |
| ☐ | SV-278082r1180952_rule | Windows Server 2025 Internet Protocol version 6 (IPv6) source routing must be configured to the highest protection level to prevent IP source routing. |
| ☐ | SV-278083r1180955_rule | Windows Server 2025 source routing must be configured to the highest protection level to prevent Internet Protocol (IP) source routing. |
| ☐ | SV-278084r1180958_rule | Windows Server 2025 must be configured to prevent Internet Control Message Protocol (ICMP) redirects from overriding Open Shortest Path First (OSPF)-generated routes. |
| ☐ | SV-278085r1180961_rule | Windows Server 2025 must be configured to ignore NetBIOS name release requests except from WINS servers. |
| ☐ | SV-278086r1180964_rule | Windows Server 2025 insecure logons to an SMB server must be disabled. |
| ☐ | SV-278087r1182272_rule | Windows Server 2025 hardened Universal Naming Convention (UNC) paths must be defined to require mutual authentication and integrity for at least the \\*\SYSVOL and \\*\NETLOGON shares. |
| ☐ | SV-278088r1180970_rule | Windows Server 2025 command line data must be included in process creation events. |
| ☐ | SV-278089r1180973_rule | Windows Server 2025 must be configured to enable Remote host allows delegation of nonexportable credentials. |
| ☐ | SV-278090r1182274_rule | Windows Server 2025 virtualization-based security must be enabled with the platform security level configured to Secure Boot or Secure Boot with DMA Protection. |
| ☐ | SV-278091r1182244_rule | Windows Server 2025 Early Launch Antimalware, Boot-Start Driver Initialization Policy must prevent boot drivers identified as bad. |
| ☐ | SV-278092r1182059_rule | Windows Server 2025 group policy objects must be reprocessed even if they have not changed. |
| ☐ | SV-278093r1180985_rule | Windows Server 2025 downloading print driver packages over HTTP must be turned off. |
| ☐ | SV-278094r1180988_rule | Windows Server 2025 printing over HTTP must be turned off. |
| ☐ | SV-278095r1180991_rule | Windows Server 2025 network selection user interface (UI) must not be displayed on the logon screen. |
| ☐ | SV-278096r1180994_rule | Windows Server 2025 users must be prompted to authenticate when the system wakes from sleep (on battery). |
| ☐ | SV-278097r1180997_rule | Windows Server 2025 users must be prompted to authenticate when the system wakes from sleep (plugged in). |
| ☐ | SV-278098r1181000_rule | Windows Server 2025 Application Compatibility Program Inventory must be prevented from collecting data and sending the information to Microsoft. |
| ☐ | SV-278099r1181003_rule | Windows Server 2025 AutoPlay must be turned off for nonvolume devices. |
| ☐ | SV-278100r1181006_rule | Windows Server 2025 default AutoRun behavior must be configured to prevent AutoRun commands. |
| ☐ | SV-278101r1181009_rule | Windows Server 2025 AutoPlay must be disabled for all drives. |
| ☐ | SV-278102r1181012_rule | Windows Server 2025 administrator accounts must not be enumerated during elevation. |
| ☐ | SV-278103r1181982_rule | Windows Server 2025 Telemetry must be configured to limit diagnostic data sent to Microsoft. |
| ☐ | SV-278104r1181018_rule | Windows Server 2025 Windows Update must not obtain updates from other PCs on the internet. |
| ☐ | SV-278105r1181812_rule | Windows Server 2025 Application event log size must be configured to 32768 KB or greater. |
| ☐ | SV-278106r1211154_rule | Windows Server 2025 Security event log size must be configured to a value that holds at least one week of audit records. |
| ☐ | SV-278107r1181816_rule | Windows Server 2025 System event log size must be configured to 32768 KB or greater. |
| ☐ | SV-278108r1181818_rule | Windows Server 2025 Microsoft Defender antivirus SmartScreen must be enabled. |
| ☐ | SV-278109r1182061_rule | Windows Server 2025 Explorer Data Execution Prevention must be enabled. |
| ☐ | SV-278110r1182063_rule | Windows Server 2025 Turning off File Explorer heap termination on corruption must be disabled. |
| ☐ | SV-278111r1182065_rule | Windows Server 2025 File Explorer shell protocol must run in protected mode. |
| ☐ | SV-278112r1181042_rule | Windows Server 2025 must not save passwords in the Remote Desktop Client. |
| ☐ | SV-278113r1181045_rule | Windows Server 2025 Remote Desktop Services must prevent drive redirection. |
| ☐ | SV-278114r1181048_rule | Windows Server 2025 Remote Desktop Services must always prompt a client for passwords upon connection. |
| ☐ | SV-278115r1181051_rule | Windows Server 2025 Remote Desktop Services must require secure Remote Procedure Call (RPC) communications. |
| ☐ | SV-278116r1181054_rule | Windows Server 2025 Remote Desktop Services must be configured with the client connection encryption set to High Level. |
| ☐ | SV-278117r1181057_rule | Windows Server 2025 must prevent attachments from being downloaded from RSS feeds. |
| ☐ | SV-278118r1182067_rule | Windows Server 2025 must disable Basic authentication for RSS feeds over HTTP. |
| ☐ | SV-278119r1181063_rule | Windows Server 2025 must prevent Indexing of encrypted files. |
| ☐ | SV-278120r1181066_rule | Windows Server 2025 must prevent users from changing installation options. |
| ☐ | SV-278121r1181069_rule | Windows Server 2025 must disable the Windows Installer Always install with elevated privileges option. |
| ☐ | SV-278122r1182069_rule | Windows Server 2025 users must be notified if a web-based program attempts to install software. |
| ☐ | SV-278123r1181075_rule | Windows Server 2025 must disable automatically signing in the last interactive user after a system-initiated restart. |
| ☐ | SV-278124r1181078_rule | Windows Server 2025 PowerShell script block logging must be enabled. |
| ☐ | SV-278125r1181081_rule | Windows Server 2025 Windows Remote Management (WinRM) client must not use Basic authentication. |
| ☐ | SV-278126r1181084_rule | Windows Server 2025 Windows Remote Management (WinRM) client must not allow unencrypted traffic. |
| ☐ | SV-278127r1181087_rule | Windows Server 2025 Windows Remote Management (WinRM) client must not use Digest authentication. |
| ☐ | SV-278128r1181090_rule | Windows Server 2025 Windows Remote Management (WinRM) service must not use Basic authentication. |
| ☐ | SV-278129r1181093_rule | Windows Server 2025 Windows Remote Management (WinRM) service must not allow unencrypted traffic. |
| ☐ | SV-278130r1181925_rule | Windows Server 2025 Windows Remote Management (WinRM) service must not store RunAs credentials. |
| ☐ | SV-278131r1181099_rule | Windows Server 2025 must have PowerShell Transcription enabled. |
| ☐ | SV-278132r1181102_rule | Windows Server 2025 must only allow administrators responsible for the domain controller to have Administrator rights on the system. |
| ☐ | SV-278133r1182071_rule | Windows Server 2025 Kerberos user logon restrictions must be enforced. |
| ☐ | SV-278134r1182073_rule | Windows Server 2025 Kerberos service ticket maximum lifetime must be limited to 600 minutes or less. |
| ☐ | SV-278135r1182075_rule | Windows Server 2025 Kerberos user ticket lifetime must be limited to 10 hours or less. |
| ☐ | SV-278136r1182077_rule | Windows Server 2025 Kerberos policy user ticket renewal maximum lifetime must be limited to seven days or less. |
| ☐ | SV-278137r1182079_rule | Windows Server 2025 computer clock synchronization tolerance must be limited to five minutes or less. |
| ☐ | SV-278138r1182081_rule | Windows Server 2025 permissions on the Active Directory data files must only allow system administrators (SAs) access. |
| ☐ | SV-278139r1182083_rule | Windows Server 2025 Active Directory SYSVOL directory must have the proper access control permissions. |
| ☐ | SV-278140r1182086_rule | Windows Server 2025 Active Directory (AD) Group Policy Objects (GPOs) must have proper access control permissions. |
| ☐ | SV-278141r1182088_rule | Windows Server 2025 Active Directory Domain Controllers Organizational Unit (OU) object must have the proper access control permissions. |
| ☐ | SV-278142r1182090_rule | Windows Server 2025 organization created Active Directory Organizational Unit (OU) objects must have proper access control permissions. |
| ☐ | SV-278143r1182092_rule | Windows Server 2025 data files owned by users must be on a different logical partition from the directory server data files. |
| ☐ | SV-278144r1182094_rule | Windows Server 2025 domain controllers must run on a machine dedicated to that function. |
| ☐ | SV-278145r1182096_rule | Windows Server 2025 must use separate, NSA-approved (Type 1) cryptography to protect the directory data in transit for directory service implementations at a classified confidentiality level when replication data traverses a network cleared to a lower level than the data. |
| ☐ | SV-278146r1182098_rule | Windows Server 2025 directory data (outside the root DSE) of a nonpublic directory must be configured to prevent anonymous access. |
| ☐ | SV-278147r1192630_rule | Windows Server 2025 directory service must be configured to terminate LDAP-based network connections to the directory server after five minutes of inactivity. |
| ☐ | SV-278148r1192632_rule | Windows Server 2025 Active Directory Group Policy Objects (GPOs) must be configured with proper audit settings. |
| ☐ | SV-278149r1182104_rule | Windows Server 2025 Active Directory (AD) Domain object must be configured with proper audit settings. |
| ☐ | SV-278150r1211157_rule | Windows Server 2025 Active Directory (AD) Infrastructure object must be configured with proper audit settings. |
| ☐ | SV-278151r1182108_rule | Windows Server 2025 Active Directory (AD) Domain Controllers Organizational Unit (OU) object must be configured with proper audit settings. |
| ☐ | SV-278152r1211160_rule | Windows Server 2025 Active Directory (AD) AdminSDHolder object must be configured with proper audit settings. |
| ☐ | SV-278153r1182112_rule | Windows Server 2025 Active Directory (AD) RID Manager$ object must be configured with proper audit settings. |
| ☐ | SV-278154r1182114_rule | Windows Server 2025 must be configured to audit Account Management - Computer Account Management successes. |
| ☐ | SV-278155r1182116_rule | Windows Server 2025 must be configured to audit DS Access - Directory Service Access successes. |
| ☐ | SV-278156r1182118_rule | Windows Server 2025 must be configured to audit DS Access - Directory Service Access failures. |
| ☐ | SV-278157r1182120_rule | Windows Server 2025 must be configured to audit DS Access - Directory Service Changes successes. |
| ☐ | SV-278158r1182122_rule | Windows Server 2025 must be configured to audit DS Access - Directory Service Changes failures. |
| ☐ | SV-278159r1182124_rule | Windows Server 2025 domain controllers must have a PKI server certificate. |
| ☐ | SV-278160r1182126_rule | Windows Server 2025 domain Controller PKI certificates must be issued by the DOD PKI or an approved External Certificate Authority (ECA). |
| ☐ | SV-278161r1182128_rule | Windows Server 2025 PKI certificates associated with user accounts must be issued by a DOD PKI or an approved External Certificate Authority (ECA). |
| ☐ | SV-278162r1211161_rule | Windows Server 2025 Active Directory (AD) user accounts, including administrators, must be configured to require the use of a common access card (CAC), Personal Identity Verification (PIV)-compliant hardware token, or Alternate Logon Token (ALT) for user authentication. |
| ☐ | SV-278163r1182132_rule | Windows Server 2025 domain controllers must require LDAP access signing. |
| ☐ | SV-278164r1182134_rule | Windows Server 2025 domain controllers must be configured to allow reset of machine account passwords. |
| ☐ | SV-278165r1182136_rule | The Windows Server 2025 "Access this computer from the network" user right must only be assigned to the Administrators, Authenticated Users, and Enterprise Domain Controllers groups on domain controllers. |
| ☐ | SV-278166r1182138_rule | The Windows Server 2025 "Add workstations to domain" user right must only be assigned to the Administrators group on domain controllers. |
| ☐ | SV-278167r1182140_rule | The Windows Server 2025 "Allow log on through Remote Desktop Services" user right must only be assigned to the Administrators group on domain controllers. |
| ☐ | SV-278168r1182141_rule | The Windows Server 2025 "Deny access to this computer from the network" user right on domain controllers must be configured to prevent unauthenticated access. |
| ☐ | SV-278169r1182142_rule | The Windows Server 2025 "Deny log on as a batch job" user right on domain controllers must be configured to prevent unauthenticated access. |
| ☐ | SV-278170r1182143_rule | The Windows Server 2025 "Deny log on as a service" user right must be configured to include no accounts or groups (blank) on domain controllers. |
| ☐ | SV-278171r1182144_rule | The Windows Server 2025 "Deny log on locally" user right on domain controllers must be configured to prevent unauthenticated access. |
| ☐ | SV-278172r1182145_rule | Windows Server 2025 must be configured for certificate-based authentication for domain controllers. |
| ☐ | SV-278173r1182146_rule | Windows Server 2025 must be configured for name-based strong mappings for certificates. |
| ☐ | SV-278174r1182147_rule | The Windows Server 2025 "Deny log on through Remote Desktop Services" user right on domain controllers must be configured to prevent unauthenticated access. |
| ☐ | SV-278175r1182148_rule | The Windows Server 2025 "Enable computer and user accounts to be trusted for delegation" user right must only be assigned to the Administrators group on domain controllers. |
| ☐ | SV-278176r1192634_rule | The password for the krbtgt account on a domain must be reset at least every 180 days. |
| ☐ | SV-278177r1182280_rule | Windows Server 2025 must only allow administrators responsible for the member server or stand-alone or nondomain-joined system to have Administrator rights on the system. |
| ☐ | SV-278178r1182282_rule | Windows Server 2025 local administrator accounts must have their privileged token filtered to prevent elevated privileges from being used over the network on domain-joined member servers. |
| ☐ | SV-278179r1182284_rule | Windows Server 2025 local users on domain-joined member servers must not be enumerated. |
| ☐ | SV-278180r1182286_rule | Windows Server 2025 must restrict unauthenticated Remote Procedure Call (RPC) clients from connecting to the RPC server on domain-joined member servers and stand-alone or nondomain-joined systems. |
| ☐ | SV-278181r1182288_rule | Windows Server 2025 must limit the caching of logon credentials to four or less on domain-joined member servers. |
| ☐ | SV-278182r1182290_rule | Windows Server 2025 must restrict remote calls to the Security Account Manager (SAM) to Administrators on domain-joined member servers and stand-alone or nondomain-joined systems. |
| ☐ | SV-278183r1182327_rule | Windows Server 2025 "Access this computer from the network" user right must only be assigned to the Administrators and Authenticated Users groups on domain-joined member servers and stand-alone or nondomain-joined systems. |
| ☐ | SV-278184r1182294_rule | The Windows Server 2025 "Deny access to this computer from the network" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and local accounts and from unauthenticated access on all systems. |
| ☐ | SV-278185r1182296_rule | Windows Server 2025 Deny log on as a batch job user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems. |
| ☐ | SV-278186r1182299_rule | The Windows Server 2025 "Deny log on as a service" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts. No other groups or accounts must be assigned this right. |
| ☐ | SV-278187r1182301_rule | The Windows Server 2025 "Deny log on locally" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems. |
| ☐ | SV-278188r1182303_rule | The Windows Server 2025 "Deny log on through Remote Desktop Services" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and all local accounts and from unauthenticated access on all systems. |
| ☐ | SV-278189r1182305_rule | The Windows Server 2025 "Enable computer and user accounts to be trusted for delegation" user right must not be assigned to any groups or accounts on domain-joined member servers and stand-alone or nondomain-joined systems. |
| ☐ | SV-278190r1182307_rule | Windows Server 2025 must be running Credential Guard on domain-joined member servers. |
| ☐ | SV-278192r1212173_rule | Windows Server 2025 must have the DOD Root Certificate Authority (CA) certificates installed in the Trusted Root Store. |
| ☐ | SV-278193r1182311_rule | Windows Server 2025 must have the DOD Interoperability Root Certificate Authority (CA) cross-certificates installed in the Untrusted Certificates Store on unclassified systems. |
| ☐ | SV-278194r1182313_rule | Windows Server 2025 must have the US DOD CCEB Interoperability Root CA cross-certificates in the Untrusted Certificates Store on unclassified systems. |
| ☐ | SV-278195r1181291_rule | Windows Server 2025 must have the built-in guest account disabled. |
| ☐ | SV-278196r1181294_rule | Windows Server 2025 must prevent local accounts with blank passwords from being used from the network. |
| ☐ | SV-278197r1182315_rule | The Windows Server 2025 built-in administrator account must be renamed. |
| ☐ | SV-278198r1182317_rule | The Windows Server 2025 built-in guest account must be renamed. |
| ☐ | SV-278199r1181303_rule | Windows Server 2025 must force audit policy subcategory settings to override audit policy category settings. |
| ☐ | SV-278200r1181306_rule | The Windows Server 2025 setting Domain member: Digitally encrypt or sign secure channel data (always) must be configured to Enabled. |
| ☐ | SV-278201r1181309_rule | Windows Server 2025 setting Domain member: Digitally encrypt secure channel data (when possible) must be configured to Enabled. |
| ☐ | SV-278202r1181312_rule | The Windows Server 2025 setting Domain member: Digitally sign secure channel data (when possible) must be configured to Enabled. |
| ☐ | SV-278203r1181315_rule | Windows Server 2025 computer account password must not be prevented from being reset. |
| ☐ | SV-278204r1182319_rule | Windows Server 2025 maximum age for machine account passwords must be configured to 30 days or less. |
| ☐ | SV-278205r1181321_rule | Windows Server 2025 must be configured to require a strong session key. |
| ☐ | SV-278206r1181324_rule | Windows Server 2025 machine inactivity limit must be set to 15 minutes or less, locking the system with the screen saver. |
| ☐ | SV-278207r1181327_rule | The Windows Server 2025 required legal notice must be configured to display before console logon. |
| ☐ | SV-278208r1181330_rule | Windows Server 2025 title for legal banner dialog box must be configured with the appropriate text. |
| ☐ | SV-278209r1181333_rule | The Windows Server 2025 Smart Card removal option must be configured to Force Logoff or Lock Workstation. |
| ☐ | SV-278210r1181336_rule | The Windows Server 2025 setting Microsoft network client: Digitally sign communications (always) must be configured to Enabled. |
| ☐ | SV-278211r1181339_rule | The Windows Server 2025 setting Microsoft network client: Digitally sign communications (if server agrees) must be configured to Enabled. |
| ☐ | SV-278212r1181342_rule | Windows Server 2025 unencrypted passwords must not be sent to third-party Server Message Block (SMB) servers. |
| ☐ | SV-278213r1181345_rule | The Windows Server 2025 setting Microsoft network server: Digitally sign communications (always) must be configured to Enabled. |
| ☐ | SV-278214r1181348_rule | The Windows Server 2025 setting Microsoft network server: Digitally sign communications (if client agrees) must be configured to Enabled. |
| ☐ | SV-278215r1181351_rule | Windows Server 2025 must not allow anonymous SID/Name translation. |
| ☐ | SV-278216r1181354_rule | Windows Server 2025 must not allow anonymous enumeration of Security Account Manager (SAM) accounts. |
| ☐ | SV-278217r1181357_rule | Windows Server 2025 must not allow anonymous enumeration of shares. |
| ☐ | SV-278218r1181360_rule | Windows Server 2025 must be configured to prevent anonymous users from having the same permissions as the Everyone group. |
| ☐ | SV-278219r1181363_rule | Windows Server 2025 must restrict anonymous access to Named Pipes and Shares. |
| ☐ | SV-278220r1181366_rule | Windows Server 2025 services using Local System that use Negotiate when reverting to NTLM authentication must use the computer identity instead of authenticating anonymously. |
| ☐ | SV-278221r1181369_rule | Windows Server 2025 must prevent NTLM from falling back to a Null session. |
| ☐ | SV-278222r1181372_rule | Windows Server 2025 must prevent PKU2U authentication using online identities. |
| ☐ | SV-278223r1181375_rule | Windows Server 2025 Kerberos encryption types must be configured to prevent the use of DES and RC4 encryption suites. |
| ☐ | SV-278225r1182320_rule | Windows Server 2025 LAN Manager authentication level must be configured to send NTLMv2 response only and to refuse LM and NTLM. |
| ☐ | SV-278226r1181384_rule | Windows Server 2025 must be configured to at least negotiate signing for LDAP client signing. |
| ☐ | SV-278227r1181387_rule | Windows Server 2025 session security for NTLM SSP-based clients must be configured to require NTLMv2 session security and 128-bit encryption. |
| ☐ | SV-278228r1181390_rule | Windows Server 2025 session security for NTLM SSP-based servers must be configured to require NTLMv2 session security and 128-bit encryption. |
| ☐ | SV-278229r1181393_rule | Windows Server 2025 users must be required to enter a password to access private keys stored on the computer. |
| ☐ | SV-278230r1181396_rule | Windows Server 2025 must be configured to use FIPS-compliant algorithms for encryption, hashing, and signing. |
| ☐ | SV-278231r1181399_rule | Windows Server 2025 default permissions of global system objects must be strengthened. |
| ☐ | SV-278232r1182191_rule | Windows Server 2025 User Account Control (UAC) approval mode for the built-in Administrator must be enabled. |
| ☐ | SV-278233r1182193_rule | Windows Server 2025 UIAccess applications must not be allowed to prompt for elevation without using the secure desktop. |
| ☐ | SV-278234r1182195_rule | Windows Server 2025 User Account Control (UAC) must, at a minimum, prompt administrators for consent on the secure desktop. |
| ☐ | SV-278235r1182197_rule | Windows Server 2025 User Account Control (UAC) must automatically deny standard user requests for elevation. |
| ☐ | SV-278236r1182199_rule | Windows Server 2025 User Account Control (UAC) must be configured to detect application installations and prompt for elevation. |
| ☐ | SV-278237r1182201_rule | Windows Server 2025 User Account Control (UAC) must only elevate UIAccess applications that are installed in secure locations. |
| ☐ | SV-278238r1182203_rule | Windows Server 2025 User Account Control (UAC) must run all administrators in Admin Approval Mode, enabling UAC. |
| ☐ | SV-278239r1182205_rule | Windows Server 2025 User Account Control (UAC) must virtualize file and registry write failures to per-user locations. |
| ☐ | SV-278240r1182207_rule | Windows Server 2025 must preserve zone information when saving attachments. |
| ☐ | SV-278241r1182208_rule | The Windows Server 2025 "Access Credential Manager as a trusted caller" user right must not be assigned to any groups or accounts. |
| ☐ | SV-278242r1182209_rule | The Windows Server 2025 "Act as part of the operating system" user right must not be assigned to any groups or accounts. |
| ☐ | SV-278243r1182210_rule | The Windows Server 2025 "Allow log on locally" user right must only be assigned to the Administrators group. |
| ☐ | SV-278244r1182211_rule | The Windows Server 2025 "Back up files and directories" user right must only be assigned to the Administrators group. |
| ☐ | SV-278245r1182212_rule | The Windows Server 2025 "Create a pagefile" user right must only be assigned to the Administrators group. |
| ☐ | SV-278246r1182213_rule | The Windows Server 2025 "Create a token object" user right must not be assigned to any groups or accounts. |
| ☐ | SV-278247r1182214_rule | The Windows Server 2025 "Create global objects" user right must only be assigned to Administrators, Service, Local Service, and Network Service. |
| ☐ | SV-278248r1182215_rule | The Windows Server 2025 "Create permanent shared objects" user right must not be assigned to any groups or accounts. |
| ☐ | SV-278249r1182217_rule | The Windows Server 2025 "Create symbolic links" user right must only be assigned to the Administrators group. |
| ☐ | SV-278250r1182218_rule | The Windows Server 2025 "Debug programs" user right must only be assigned to the Administrators group. |
| ☐ | SV-278251r1182219_rule | The Windows Server 2025 "Force shutdown from a remote system" user right must only be assigned to the Administrators group. |
| ☐ | SV-278252r1182220_rule | The Windows Server 2025 "Generate security audits" user right must only be assigned to Local Service and Network Service. |
| ☐ | SV-278253r1182221_rule | The Windows Server 2025 "Impersonate a client after authentication" user right must only be assigned to Administrators, Service, Local Service, and Network Service. |
| ☐ | SV-278254r1182222_rule | The Windows Server 2025 "Increase scheduling priority" user right must only be assigned to the Administrators group. |
| ☐ | SV-278255r1182223_rule | The Windows Server 2025 "Load and unload device drivers" user right must only be assigned to the Administrators group. |
| ☐ | SV-278256r1182224_rule | The Windows Server 2025 "Lock pages in memory" user right must not be assigned to any groups or accounts. |
| ☐ | SV-278257r1182225_rule | The Windows Server 2025 "Manage auditing and security log" user right must only be assigned to the Administrators group. |
| ☐ | SV-278258r1182226_rule | The Windows Server 2025 "Modify firmware environment values" user right must only be assigned to the Administrators group. |
| ☐ | SV-278259r1182227_rule | The Windows Server 2025 "Perform volume maintenance tasks" user right must only be assigned to the Administrators group. |
| ☐ | SV-278260r1182228_rule | The Windows Server 2025 "Profile single process" user right must only be assigned to the Administrators group. |
| ☐ | SV-278261r1182229_rule | The Windows Server 2025 "Restore files and directories" user right must only be assigned to the Administrators group. |
| ☐ | SV-278262r1182230_rule | The Windows Server 2025 "Take ownership of files or other objects" user right must only be assigned to the Administrators group. |
| ☐ | SV-279918r1181960_rule | Windows Server 2025 must be configured to audit handle manipulation failures. |
| ☐ | SV-279920r1181966_rule | Windows Server 2025 must be configured to audit registry failures. |
| ☐ | SV-279921r1181969_rule | Windows Server 2025 must be configured to audit registry successes. |
| ☐ | SV-279922r1181972_rule | Windows Server 2025 must be configured to audit sensitive privilege use successes. |
| ☐ | SV-279923r1181975_rule | Windows Server 2025 must be configured to audit sensitive privilege use failures. |
| ☐ | SV-285313r1211167_rule | Windows Server 2025 networked systems must have and implement OpenSSH to protect the confidentiality and integrity of transmitted and received information, as well as information during preparation for transmission. |
| ☐ | SV-285314r1211170_rule | Windows Server 2025 OpenSSH must display the Standard Mandatory DOD Notice and Consent Banner before granting remote access to the system via an OpenSSH logon. |
| ☐ | SV-285315r1211173_rule | Windows Server 2025 OpenSSH must accept public key authentication. |
| ☐ | SV-285316r1211176_rule | Windows Server 2025 OpenSSH must not allow blank passwords. |
| ☐ | SV-285317r1211179_rule | Windows Server 2025 OpenSSH must force a frequent session key renegotiation for SSH connections to the server. |
| ☐ | SV-285318r1211182_rule | Windows Server 2025 OpenSSH must be configured so that all network connections associated with SSH traffic terminate after becoming unresponsive. |
| ☐ | SV-285319r1212174_rule | Windows Server 2025 OpenSSH must be configured so that all network connections associated with SSH traffic are terminated after 10 minutes of becoming unresponsive. |
| ☐ | SV-285320r1212175_rule | The Windows Server 2025 OpenSSH configuration file must conform to minimum requirements. |
| ☐ | SV-285321r1211191_rule | Windows Server 2025 OpenSSH private host key files must conform to minimum requirements. |
| ☐ | SV-285322r1211194_rule | Windows Server 2025 OpenSSH public host key files must conform to minimum requirements. |
| ☐ | SV-285323r1211197_rule | Windows Server 2025 OpenSSH must not allow GSSAPI authentication. |