Changes between CIS Benchmark 1.10.1 and CIS Benchmark 3.0.0

Overview

This knowledge base article will describe the differences between CIS Benchmark 1.10.1 and CIS Benchmark 3.0.0.

Breakdown of the differences between CIS 1.10.1 and CIS 3.0.0

1. Account Policies

1.1 Password Policy

CIS Benchmark Version CIS Control Description Recommended Value
1.10.1 1.1.2 (L1) Ensure 'Maximum password age' is set to '60 or fewer days, but not 0' 42
3.0.0 1.1.2 (L1) Ensure 'Maximum password age' is set to '365 or fewer days, but not 0' 365

1.2 Account Lockout Policy

CIS Benchmark Version CIS Control Description Recommended Value
1.10.1 1.2.2 (L1) Ensure 'Account lockout threshold' is set to '10 or fewer invalid logon attempt(s), but not 0' 10
3.0.0 1.2.2 (L1) Ensure 'Account lockout threshold' is set to '5 or fewer invalid logon attempt(s), but not 0' 5
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Allow Administrator account lockout' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 1.2.3 (L1) Ensure 'Allow Administrator account lockout' is set to 'Enabled' Enabled

2. Local Policies

2.3.11 Network Security

CIS Benchmark Version CIS Control Description Recommended Value
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Network security: Restrict NTLM: Audit Incoming NTLM Traffic' is set to 'Enable auditing for all accounts' Does not exist in CIS 1.10.1
3.0.0 2.3.11.11 (L1) Ensure 'Network security: Restrict NTLM: Audit Incoming NTLM Traffic' is set to 'Enable auditing for all accounts' Enabled auditing for all accounts
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers' is set to 'Audit all' or higher Does not exist in CIS 1.10.1
3.0.0 2.3.11.12 (L1) Ensure 'Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers' is set to 'Audit all' or higher Audit all or higher

5. System Services

CIS Benchmark Version CIS Control Description Recommended Value
1.10.1 5.8 (L1) Ensure 'Internet Connection Sharing (ICS) (SharedAccess)' is set to 'Disabled' Disabled
3.0.0 Deprecated in CIS 3.0 (L1) Ensure 'Internet Connection Sharing (ICS) (SharedAccess)' is set to 'Disabled' Deprecated in CIS 3.0

9. Windows Defender Firewall with Advanced Security

9.1 Domain Profile

CIS Benchmark Version CIS Control Description Recommended Value
1.10.1 9.1.3 (L1) Ensure 'Windows Firewall: Domain: Outbound connections' is set to 'Allow (default)' Enabled: Allowed
3.0.0 Deprecated in CIS 3.0 (L1) Ensure 'Windows Firewall: Domain: Outbound connections' is set to 'Allow (default)' Deprecated in CIS 3.0

9.2 Private Profile

CIS Benchmark Version CIS Control Description Recommended Value
1.10.1 9.2.3 (L1) Ensure 'Windows Firewall: Private: Outbound connections' is set to 'Allow (default)' Enabled: Allowed
3.0.0 Deprecated in CIS 3.0 (L1) Ensure 'Windows Firewall: Private: Outbound connections' is set to 'Allow (default)' Deprecated in CIS 3.0

9.3 Private Profile

CIS Benchmark Version CIS Control Description Recommended Value
1.10.1 9.3.3 (L1) Ensure 'Windows Firewall: Public: Outbound connections' is set to 'Allow (default)' Enabled: Allowed
3.0.0 Deprecated in CIS 3.0 (L1) Ensure 'Windows Firewall: Public: Outbound connections' is set to 'Allow (default)' Deprecated in CIS 3.0

18. Administrative Templates (Computer)

18.2 Desktop

CIS Benchmark Version CIS Control Description Recommended Value
1.10.1 18.2.1 (L1) Ensure LAPS AdmPwd GPO Extension / CSE is installed Not installed
3.0.0 Depreciated in CIS 3.0 (L1) Ensure LAPS AdmPwd GPO Extension / CSE is installed Deprecated in CIS 3.0
1.10.1 18.2.2 (L1) Ensure 'Do not allow password expiration time longer than required by policy' is set to 'Enabled' Enabled
3.0.0 Deprecated in CIS 3.0 (L1) Ensure 'Do not allow password expiration time longer than required by policy' is set to 'Enabled' Deprecated in CIS 3.0
1.10.1 18.2.3 (L1) Ensure 'Enable Local Admin Password Management' is set to 'Enabled' Enabled
3.0.0 Deprecated in CIS 3.0 (L1) Ensure 'Enable Local Admin Password Management' is set to 'Enabled' Deprecated in CIS 3.0

18.3 LAPS (Microsoft LAPS Legacy) and 18.4 MS Security Guide
Note: All CIS 1.10.1 18.3 policies have updated as CIS 3.0.0 18.4 policies.

CIS Benchmark Version CIS Control Description Recommended Value
1.10.1 18.3.1 (L1) Ensure 'Apply UAC restrictions to local accounts on network logons' is set to 'Enabled' Enabled
3.0.0 18.4.1 (L1) Ensure 'Apply UAC restrictions to local accounts on network logons' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Configure RPC packet level privacy setting for incoming connections' is set to Enabled Does not exist in CIS 1.10.1
3.0.0

18.4.2

(L1) Ensure 'Configure RPC packet level privacy setting for incoming connections' is set to Enabled Enabled
1.10.1 18.3.2 (L1) Ensure 'Configure SMB v1 client driver' is set to 'Enabled: Disable driver (recommended)' Enabled: Disabled driver (recommended)
3.0.0 18.4.3 (L1) Ensure 'Configure SMB v1 client driver' is set to 'Enabled: Disable driver (recommended)' Enabled: Disabled driver (recommended)
1.10.1 18.3.3 (L1) Ensure 'Configure SMB v1 server' is set to 'Disabled' Disabled
3.0.0 18.4.4 (L1) Ensure 'Configure SMB v1 server' is set to 'Disabled' Disabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Enable Certificate Padding' is set to Enabled Does not exist in CIS 1.10.1
3.0.0 18.4.5 (L1) Ensure 'Enable Certificate Padding' is set to Enabled Enabled
1.10.1 18.3.4 (L1) Ensure 'Enable Structured Exception Handling Overwrite Protection (SEHOP)' is set to 'Enabled'' Enabled
3.0.0 18.4.6 (L1) Ensure 'Enable Structured Exception Handling Overwrite Protection (SEHOP)' is set to 'Enabled'' Enabled
1.10.1 18.3.5 (L1) Ensure 'NetBT NodeType configuration' is set to 'Enabled: P-node (recommended)'

Enabled: P-node (recommended)

3.0.0 18.4.7 (L1) Ensure 'NetBT NodeType configuration' is set to 'Enabled: P-node (recommended)' Enabled: P-node (recommended)
1.10.1 18.3.6 (L1) Ensure 'WDigest Authentication' is set to 'Disabled' Disabled
3.0.0 18.4.8 (L1) Ensure 'WDigest Authentication' is set to 'Disabled' Disabled

18.5 MSS (Legacy)

CIS Benchmark Version CIS Control Description Recommended Value
1.10.1 18.4.1 (L1) Ensure 'MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended)' is set to 'Disabled' Disabled
3.0.0 18.5.1 (L1) Ensure 'MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended)' is set to 'Disabled' Disabled
1.10.1 18.4.2 (L1) Ensure 'MSS: (DisableIPSourceRouting IPv6) IP source routing protection level (protects against packet spoofing)' is set to 'Enabled: Highest protection, source routing is completely disabled' Enabled: Highest protection, source routing is completely disabled
3.0.0 18.5.2 (L1) Ensure 'MSS: (DisableIPSourceRouting IPv6) IP source routing protection level (protects against packet spoofing)' is set to 'Enabled: Highest protection, source routing is completely disabled' Enabled: Highest protection, source routing is completely disabled
1.10.1 18.4.3 (L1) Ensure 'MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)' is set to 'Enabled: Highest protection, source routing is completely disabled' Enabled: Highest protection, source routing is completely disabled
3.0.0 18.5.3 (L1) Ensure 'MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)' is set to 'Enabled: Highest protection, source routing is completely disabled' Enabled: Highest protection, source routing is completely disabled
1.10.1 18.4.5 (L1) Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled' Disabled
3.0.0 18.5.5 (L1) Ensure 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is set to 'Disabled' Disabled
1.10.1 18.4.7 (L1) Ensure 'MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers' is set to 'Enabled' Enabled
3.0.0 18.5.7 (L1) Ensure 'MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers' is set to 'Enabled' Enabled
1.10.1 18.4.9 (L1) Ensure 'MSS: (SafeDllSearchMode) Enable Safe DLL search mode (recommended)' is set to 'Enabled' Enabled
3.0.0 18.5.9 (L1) Ensure 'MSS: (SafeDllSearchMode) Enable Safe DLL search mode (recommended)' is set to 'Enabled' Enabled
1.10.1 18.4.10 (L1) Ensure 'MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended)' is set to 'Enabled: 5 or fewer seconds' Enabled: 5
3.0.0 18.5.10 (L1) Ensure 'MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended)' is set to 'Enabled: 5 or fewer seconds' Enabled: 5
1.10.1 18.4.13 (L1) Ensure 'MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning' is set to 'Enabled: 90% or less' Enabled: 90
3.0.0 18.5.13 (L1) Ensure 'MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning' is set to 'Enabled: 90% or less' Enabled: 90

18.6 Network

CIS Benchmark Version CIS Control Description Recommended Value
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Configure DNS over HTTPS (DoH) name resolution' is set to 'Enabled: Allow DoH or higher' Enabled: Allow DoH or higher
3.0.0 18.6.4.1 (L1) Ensure 'Configure DNS over HTTPS (DoH) name resolution' is set to 'Enabled: Allow DoH or higher' Enabled: Allow DoH or higher
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Configure NetBIOS settings' is set to 'Enabled: Disable NetBIOS name resolution on public networks' Enabled: Disable NetBIOS name resolution on public networks
3.0.0 18.6.4.2 (L1) Ensure 'Configure NetBIOS settings' is set to 'Enabled: Disable NetBIOS name resolution on public networks' Enabled: Disable NetBIOS name resolution on public networks
1.10.1

18.5.4.1

(L1) Ensure 'Turn off multicast name resolution' is set to 'Enabled' Enabled
3.0.0 18.6.4.3 (L1) Ensure 'Turn off multicast name resolution' is set to 'Enabled' Enabled
1.10.1 18.5.8.1 (L1) Ensure 'Enable insecure guest logons' is set to 'Disabled' Disabled
3.0.0 18.6.8.1 (L1) Ensure 'Enable insecure guest logons' is set to 'Disabled' Disabled
1.10.1 18.5.11.2 (L1) Ensure 'Prohibit installation and configuration of Network Bridge on your DNS domain network' is set to 'Enabled' Enabled
3.0.0 18.6.11.2 (L1) Ensure 'Prohibit installation and configuration of Network Bridge on your DNS domain network' is set to 'Enabled' Enabled
1.10.1 18.5.11.3 (L1) Ensure 'Prohibit use of Internet Connection Sharing on your DNS domain network' is set to 'Enabled' Enabled
3.0.0 18.6.11.3 (L1) Ensure 'Prohibit use of Internet Connection Sharing on your DNS domain network' is set to 'Enabled' Enabled
1.10.1 18.5.11.4 (L1) Ensure 'Require domain users to elevate when setting a network's location' is set to 'Enabled' Enabled
3.0.0 18.6.11.4 (L1) Ensure 'Require domain users to elevate when setting a network's location' is set to 'Enabled' Enabled
1.10.1 18.5.14.1 (L1) Ensure 'Hardened UNC Paths' is set to 'Enabled, with "Require Mutual Authentication" and "Require Integrity" set for all NETLOGON and SYSVOL shares' Enabled, with "Require Mutual Authentication", "Require Integrity", and “Require Privacy” set for all NETLOGON and SYSVOL shares
3.0.0 18.6.14.1 (L1) Ensure 'Hardened UNC Paths' is set to 'Enabled, with "Require Mutual Authentication" and "Require Integrity" set for all NETLOGON and SYSVOL shares' Enabled, with "Require Mutual Authentication", "Require Integrity", and “Require Privacy” set for all NETLOGON and SYSVOL shares
1.10.1 18.5.21.1 (L1) Ensure 'Minimize the number of simultaneous connections to the Internet or a Windows Domain' is set to 'Enabled: 3 = Prevent Wi-Fi when on Ethernet' 3
3.0.0 18.6.21.1 (L1) Ensure 'Minimize the number of simultaneous connections to the Internet or a Windows Domain' is set to 'Enabled: 3 = Prevent Wi-Fi when on Ethernet' 3
1.10.1 18.5.21.2 (L1) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled' Enabled
3.0.0 18.6.21.2 (L1) Ensure 'Prohibit connection to non-domain networks when connected to domain authenticated network' is set to 'Enabled' Enabled
1.10.1 18.5.23.2.1 (L1) Ensure 'Allow Windows to automatically connect to suggested open hotspots, to networks shared by contacts, and to hotspots offering paid services' is set to 'Disabled' Disabled
3.0.0 18.6.23.2.1 (L1) Ensure 'Allow Windows to automatically connect to suggested open hotspots, to networks shared by contacts, and to hotspots offering paid services' is set to 'Disabled' Disabled

18.7 Printers

CIS Benchmark Version CIS Control Description Recommended Value
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Allow Print Spooler to accept client connections' is set to 'Disabled' Does not exist in CIS 1.10.1
3.0.0 18.7.1 (L1) Ensure 'Allow Print Spooler to accept client connections' is set to 'Disabled' Disabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Configure Redirection Guard' is set to 'Enabled: Redirection Guard Enabled' Does not exist in CIS 1.10.1
3.0.0 18.7.2 (L1) Ensure 'Configure Redirection Guard' is set to 'Enabled: Redirection Guard Enabled' Enabled: Redirection Guard Enabled
1.10.1

Does not exist in CIS 1.10.1

(L1) Ensure 'Configure RPC connection settings: Protocol to use for outgoing RPC connections' is set to 'Enabled: RPC over TCP' Does not exist in CIS 1.10.1
3.0.0 18.7.3 (L1) Ensure 'Configure RPC connection settings: Protocol to use for outgoing RPC connections' is set to 'Enabled: RPC over TCP' Enabled: RPC over TCP
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Configure RPC connection settings: Use authentication for outgoing RPC connections' is set to 'Default' Does not exist in CIS 1.10.1
3.0.0 18.7.4 (L1) Ensure 'Configure RPC connection settings: Use authentication for outgoing RPC connections' is set to 'Default' Enabled: Default
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Configure RPC listener settings: Protocols to allow for incoming RPC connections' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.7.5 (L1) Ensure 'Configure RPC listener settings: Authentication protocol to use for incoming RPC connections' is set to 'Enabled' Enabled: RPC over TCP
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Configure RPC listener settings: Authentication protocol to use for incoming RPC connections' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.7.6 (L1) Ensure 'Configure RPC listener settings: Authentication protocol to use for incoming RPC connections' is set to 'Enabled' Enabled: Negotiate or higher
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Configure RPC over TCP port' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.7.7 (L1) Ensure 'Configure RPC over TCP port' is set to 'Enabled' Enabled: 0
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Limits print driver installation to Administrators' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.7.8 (L1) Ensure 'Limits print driver installation to Administrators' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Manage processing of Queue-specific files' is set to 'Enabled: Limit Queue-specific files to Color profiles' Does not exist in CIS 1.10.1
3.0.0 18.7.9 (L1) Ensure 'Manage processing of Queue-specific files' is set to 'Enabled: Limit Queue-specific files to Color profiles' Enabled: Limit Queue-specific files to Color profiles
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Point and Print Restrictions: When installing drivers for a new connection' is set to 'Enabled: Show warning and elevation prompt' Does not exist in CIS 1.10.1
3.0.0 18.7.10 (L1) Ensure 'Point and Print Restrictions: When installing drivers for a new connection' is set to 'Enabled: Show warning and elevation prompt' Enabled: Show warning and elevation prompt
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Point and Print Restrictions: When updating drivers for an existing connection' is set to 'Enabled: Show warning and elevation prompt' Does not exist in CIS 1.10.1
3.0.0 18.7.11 (L1) Ensure 'Point and Print Restrictions: When updating drivers for an existing connection' is set to 'Enabled: Show warning and elevation prompt' Enabled: Show warning and elevation prompt

18.9 System

CIS Benchmark Version CIS Control Description Recommended Value
1.10.1 18.8.3.1 (L1) Ensure 'Include command line in process creation events' is set to 'Disabled' Disabled
3.0.0 18.9.3.1 (L1) Ensure 'Include command line in process creation events' is set to 'Enabled' Enabled
1.10.1 18.8.4.1 (L1) Ensure 'Encryption Oracle Remediation' is set to 'Enabled: Force Updated Clients' Enabled: Force Updated Clients
3.0.0 18.9.4.1 (L1) Ensure 'Encryption Oracle Remediation' is set to 'Enabled: Force Updated Clients' Enabled: Force Updated Clients
1.10.1 18.8.4.2 (L1) Ensure 'Remote host allows delegation of non-exportable credentials' is set to 'Enabled' Enabled
3.0.0 18.9.4.2 (L1) Ensure 'Remote host allows delegation of non-exportable credentials' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Turn On Virtualization Based Security' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.9.5.1. (L1) Ensure 'Turn On Virtualization Based Security' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Turn On Virtualization Based Security: Select Platform Security Level is set to 'Secure Boot or higher' Does not exist in CIS 1.10.1
3.0.0 18.9.5.2 (L1) Ensure 'Turn On Virtualization Based Security: Select Platform Security Level is set to 'Secure Boot or higher' Secure Boot or higher
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Turn On Virtualization Based Security: Virtualization Based Protection of Code Integrity' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.9.5.3 (L1) Ensure 'Turn On Virtualization Based Security: Virtualization Based Protection of Code Integrity' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Turn On Virtualization Based Security: Require UEFI Memory Attributes Table' is set to 'True (checked)' Does not exist in CIS 1.10.1
3.0.0 18.9.5.4 (L1) Ensure 'Turn On Virtualization Based Security: Require UEFI Memory Attributes Table' is set to 'True (checked)' True (checked)
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Turn On Virtualization Based Security: Credential Guard Configuration' is set to 'Enabled with UEFI lock' Does not exist in CIS 1.10.1
3.0.0 18.9.5.5 (L1) Ensure 'Turn On Virtualization Based Security: Credential Guard Configuration' is set to 'Enabled with UEFI lock' Enabled with UEFI lock
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Turn On Virtualization Based Security: Secure Launch Configuration' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.9.5.6 (L1) Ensure 'Turn On Virtualization Based Security: Secure Launch Configuration' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Turn On Virtualization Based Security: Kernel-mode Hardware-enforced Stack Protection' is set to 'Enabled: Enabled in enforcement mode' Does not exist in CIS 1.10.1
3.0.0 18.9.5.7 (L1) Ensure 'Turn On Virtualization Based Security: Kernel-mode Hardware-enforced Stack Protection' is set to 'Enabled: Enabled in enforcement mode' Enabled: Enabled in enforcement mode
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Prevent device metadata retrieval from the Internet' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.9.7.2 (L1) Ensure 'Prevent device metadata retrieval from the Internet' is set to 'Enabled' Enabled
1.10.1 18.8.4.2 (L1) Ensure 'Remote host allows delegation of non-exportable credentials' is set to 'Enabled' Enabled
3.0.0 Depreciated in CIS 3.0 (L1) Ensure 'Remote host allows delegation of non-exportable credentials' is set to 'Enabled' Depreciated in CIS 3.0
1.10.1 18.8.14.1 (L1) Ensure 'Boot-Start Driver Initialization Policy is set to 'Enabled: Good, unknown and bad but critical' Enabled: Good, unknown and bad but critical
3.0.0 18.9.13.1 (L1) Ensure 'Boot-Start Driver Initialization Policy is set to 'Enabled: Good, unknown and bad but critical' Enabled: Good, unknown and bad but critical
1.10.1 18.8.21.2 (L1) Ensure 'Configure registry policy processing: Do not apply during periodic background processing' is set to 'Enabled: FALSE' Enabled: FALSE
3.0.0 18.9.19.2 (L1) Ensure 'Configure registry policy processing: Do not apply during periodic background processing' is set to 'Enabled: FALSE' Enabled: FALSE
1.10.1 18.8.21.3 (L1) Ensure 'Configure registry policy processing: Process even if the Group Policy objects have not changed' is set to 'Enabled: TRUE' Enabled: TRUE
3.0.0 18.9.19.3 (L1) Ensure 'Configure registry policy processing: Process even if the Group Policy objects have not changed' is set to 'Enabled: TRUE' Enabled: TRUE
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Configure security policy processing: Do not apply during periodic background processing' is set to 'Enabled: FALSE' Does not exist in CIS 1.10.1
3.0.0 18.9.19.4 (L1) Ensure 'Configure security policy processing: Do not apply during periodic background processing' is set to 'Enabled: FALSE' Enabled: FALSE
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Configure security policy processing: Process even if the Group Policy objects have not changed' is set to 'Enabled: TRUE' Does not exist in CIS 1.10.1
3.0.0 18.9.19.5 (L1) Ensure 'Configure security policy processing: Process even if the Group Policy objects have not changed' is set to 'Enabled: TRUE' Enabled: TRUE
1.10.1 18.8.21.4 (L1) Ensure 'Continue experiences on this device' is set to 'Disabled' Disabled
3.0.0 18.9.19.6 (L1) Ensure 'Continue experiences on this device' is set to 'Disabled' Disabled
1.10.1 18.8.21.5 (L1) Ensure 'Turn off background refresh of Group Policy is set to 'Disabled' Disabled
3.0.0 18.9.19.7 (L1) Ensure 'Turn off background refresh of Group Policy is set to 'Disabled' Disabled
1.10.1 18.8.22.1.2 (L1) Ensure 'Turn off downloading of print drivers over HTTP is set to 'Enabled' Enabled
3.0.0 18.9.20.1.2 (L1) Ensure 'Turn off downloading of print drivers over HTTP is set to 'Enabled' Enabled
1.10.1 18.8.22.1.6 (L1) Ensure 'Turn off Internet download for Web publishing and online ordering wizards' is set to 'Enabled' Enabled
3.0.0 18.9.20.1.6 (L1) Ensure 'Turn off Internet download for Web publishing and online ordering wizards' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Configure password backup directory' is set to 'Enabled: Active Directory' Does not exist in CIS 1.10.1
3.0.0 18.9.25.1 (L1) Ensure 'Configure password backup directory' is set to 'Enabled: Active Directory' Enabled: Active Directory
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Do not allow password expiration time longer than required by policy' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.9.25.2 (L1) Ensure 'Do not allow password expiration time longer than required by policy' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Enable password encryption' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.9.25.3 (L1) Ensure 'Enable password encryption' is set to 'Enabled' Enabled
1.10.1 18.2.4 (L1) Ensure 'Password Settings: Password Complexity' is set to 'Enabled: Large letters + small letters + numbers + special characters' Not applicable
3.0.0 18.9.25.4 (L1) Ensure 'Password Settings: Password Complexity' is set to 'Enabled: Large letters + small letters + numbers + special characters' Enabled: Large letters + small letters + numbers + special characters
1.10.1 18.2.5 (L1) Ensure 'Password Settings: Password Length' is set to 'Enabled: 15 or more' Not applicable
3.0.0 18.9.25.5 (L1) Ensure 'Password Settings: Password Length' is set to 'Enabled: 15 or more' Enabled: 15
1.10.1 18.2.6 (L1) Ensure 'Password Settings: Password Age (Days)' is set to 'Enabled: 30 or fewer' Not applicable
3.0.0 18.9.25.6 (L1) Ensure 'Password Settings: Password Age (Days)' is set to 'Enabled: 30 or fewer' Enabled: 30
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Post-authentication actions: Grace period (hours) is set to 'Enabled: 8 or fewer hours, but not 0' Does not exist in CIS 1.10.1
3.0.0 18.9.25.7 (L1) Ensure 'Post-authentication actions: Grace period (hours) is set to 'Enabled: 8 or fewer hours, but not 0' Enabled: 8
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Post-authentication actions: Actions' is set to 'Enabled: Reset the password and logoff the managed account' Does not exist in CIS 1.10.1
3.0.0 18.9.25.8 (L1) Ensure 'Post-authentication actions: Actions' is set to 'Enabled: Reset the password and logoff the managed account' Enabled: Reset the password and logoff the managed account
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Allow Custom SSPs and APs to be loaded into LSASS' is set to 'Disabled' Does not exist in CIS 1.10.1
3.0.0 18.9.26.1 (L1) Ensure 'Allow Custom SSPs and APs to be loaded into LSASS' is set to 'Disabled' Disabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock' Does not exist in CIS 1.10.1
3.0.0 18.9.26.2 (L1) Ensure 'Configures LSASS to run as a protected process' is set to 'Enabled: Enabled with UEFI Lock' Enabled: Enabled with UEFI Lock
1.10.1 18.8.28.1 (L1) Ensure 'Block user from showing account details on sign-in' is set to 'Enabled' Enabled
3.0.0 18.9.28.1 (L1) Ensure 'Block user from showing account details on sign-in' is set to 'Enabled' Enabled
1.10.1 18.8.28.2 (L1) Ensure 'Do not display network selection UI' is set to 'Enabled' Enabled
3.0.0 18.9.28.2 (L1) Ensure 'Do not display network selection UI' is set to 'Enabled' Enabled
1.10.1 18.8.28.4 (L1) Ensure 'Do not enumerate connected users on domain-joined computers' is set to 'Enabled' Enabled
3.0.0 18.9.28.3 (L1) Ensure 'Do not enumerate connected users on domain-joined computers' is set to 'Enabled' Enabled
1.10.1 18.8.28.4 (L1) Ensure 'Enumerate local users on domain-joined computers' is set to 'Disabled' Disabled
3.0.0 18.9.28.4 (L1) Ensure 'Enumerate local users on domain-joined computers' is set to 'Disabled' Disabled
1.10.1 18.8.28.5 (L1) Ensure 'Turn off app notifications on the lock screen' is set to 'Enabled' Enabled
3.0.0 18.9.28.5 (L1) Ensure 'Turn off app notifications on the lock screen' is set to 'Enabled' Enabled
1.10.1 18.8.28.6 (L1) Ensure 'Turn off picture password sign-in' is set to 'Enabled' Enabled
3.0.0 18.9.28.6 (L1) Ensure 'Turn off picture password sign-in' is set to 'Enabled' Enabled
1.10.1 18.8.28.7 (L1) Ensure 'Turn on convenience PIN sign-in' is set to 'Disabled' Disabled
3.0.0 18.9.28.7 (L1) Ensure 'Turn on convenience PIN sign-in' is set to 'Disabled' Disabled
1.10.1 18.8.34.6.1 (L1) Ensure 'Allow network connectivity during connected-standby (on battery)' is set to 'Disabled' Disabled
3.0.0 18.9.33.6.1 (L1) Ensure 'Allow network connectivity during connected-standby (on battery)' is set to 'Disabled' Disabled
1.10.1 18.8.34.6.2 (L1) Ensure 'Allow network connectivity during connected-standby (plugged in) is set to 'Disabled' Disabled
3.0.0 18.9.33.6.2 (L1) Ensure 'Allow network connectivity during connected-standby (plugged in) is set to 'Disabled' Disabled
1.10.1 18.8.34.6.5 (L1) Ensure 'Require a password when a computer wakes (on battery)' is set to 'Enabled' Enabled
3.0.0 18.9.33.6.5 (L1) Ensure 'Require a password when a computer wakes (on battery)' is set to 'Enabled' Enabled
1.10.1 18.8.34.6.6 (L1) Ensure 'Require a password when a computer wakes (plugged in)' is set to 'Enabled' Enabled
3.0.0 18.9.33.6.6 (L1) Ensure 'Require a password when a computer wakes (plugged in)' is set to 'Enabled' Enabled
1.10.1 18.8.36.1 (L1) Ensure 'Configure Offer Remote Assistance' is set to 'Disabled' Disabled
3.0.0 18.9.35.1 (L1) Ensure 'Configure Offer Remote Assistance' is set to 'Disabled' Disabled
1.10.1 18.8.36.2 (L1) Ensure 'Configure Solicited Remote Assistance' is set to 'Disabled' Disabled
3.0.0 18.9.35.2 (L1) Ensure 'Configure Solicited Remote Assistance' is set to 'Disabled' Disabled
1.10.1 18.8.37.1 (L1) Ensure 'Enable RPC Endpoint Mapper Client Authentication' is set to 'Enabled' Enabled
3.0.0 18.9.36.1 (L1) Ensure 'Enable RPC Endpoint Mapper Client Authentication' is set to 'Enabled' Enabled
1.10.1 18.8.37.2 (L1) Ensure 'Restrict Unauthenticated RPC clients' is set to 'Enabled: Authenticated' Enabled: Authenticated
3.0.0 18.9.36.2 (L1) Ensure 'Restrict Unauthenticated RPC clients' is set to 'Enabled: Authenticated' Enabled: Authenticated
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Enable Windows NTP Client' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.9.51.1.1 (L1) Ensure 'Enable Windows NTP Client' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1
(L1) Ensure 'Enable Windows NTP Server is set to 'Disabled'
Does not exist in CIS 1.10.1
3.0.0 18.9.51.12
(L1) Ensure 'Enable Windows NTP Server is set to 'Disabled'
Enabled

18.10 Windows Components

CIS Benchmark Version CIS Control Description Recommended Value
1.10.1 18.9.4.2 (L1) Ensure 'Prevent non-admin users from installing packaged Windows apps' is set to 'Enabled' Disabled
3.0.0 18.9.3.1 (L1) Ensure 'Prevent non-admin users from installing packaged Windows apps' is set to 'Enabled' Enabled
1.10.1 18.8.5.1 (L1) Ensure 'Let Windows apps activate with voice while the system is locked' is set to 'Enabled: Force Deny' Enabled: Force Updated Clients
3.0.0 18.9.4.1 (L1) Ensure 'Let Windows apps activate with voice while the system is locked' is set to 'Enabled: Force Deny' Enabled: Force Updated Clients
1.10.1 18.9.6.1 (L1) Ensure 'Allow Microsoft accounts to be optional' is set to 'Enabled' Enabled
3.0.0 18.10.5.1 (L1) Ensure 'Allow Microsoft accounts to be optional' is set to 'Enabled' Enabled
1.10.1 18.9.8.1 (L1) Ensure 'Disallow Autoplay for non-volume devices' is set to 'Enabled' Enabled
3.0.0 18.10.7.1 (L1) Ensure 'Disallow Autoplay for non-volume devices' is set to 'Enabled' Enabled
1.10.1 18.9.8.2 (L1) Ensure 'Set the default behavior for AutoRun' is set to 'Enabled: Do not execute any autorun commands' Enabled: Do not execute any autorun commands
3.0.0 18.10.7.2 (L1) Ensure 'Set the default behavior for AutoRun' is set to 'Enabled: Do not execute any autorun commands' Enabled: Do not execute any autorun commands
1.10.1 18.9.8.3 (L1) Ensure 'Turn off Autoplay' is set to 'Enabled: All drives' Enabled: All drives
3.0.0 18.10.7.3 (L1) Ensure 'Turn off Autoplay' is set to 'Enabled: All drives' Enabled: All drives
1.10.1 18.9.10.1.1 (L1) Ensure 'Configure enhanced anti-spoofing' is set to 'Enabled' Enabled
3.0.0 18.10.8.1.1 (L1) Ensure 'Configure enhanced anti-spoofing' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Turn off cloud consumer account state content' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.10.12.1 (L1) Ensure 'Turn off cloud consumer account state content' is set to 'Enabled' Enabled
1.10.1 18.9.13.2 (L1) Ensure 'Turn off Microsoft consumer experiences' is set to 'Enabled' Enabled
3.0.0 18.10.12.3 (L1) Ensure 'Turn off Microsoft consumer experiences' is set to 'Enabled' Enabled
1.10.1 18.9.14.1 (L1) Ensure 'Require pin for pairing' is set to 'Enabled: First Time' OR 'Enabled: Always' Enabled: First Time
3.0.0 18.10.13.1 (L1) Ensure 'Require pin for pairing' is set to 'Enabled: First Time' OR 'Enabled: Always' Enabled: First Time
1.10.1 18.9.15.1 (L1) Ensure 'Do not display the password reveal button' is set to 'Enabled' Enabled
3.0.0 18.10.14.1 (L1) Ensure 'Do not display the password reveal button' is set to 'Enabled' Enabled
1.10.1 18.9.15.2 (L1) Ensure 'Enumerate administrator accounts on elevation' is set to 'Disabled' Disabled
3.0.0 18.10.14.2 (L1) Ensure 'Enumerate administrator accounts on elevation' is set to 'Disabled' Disabled
1.10.1 18.9.15.3 (L1) Ensure 'Prevent the use of security questions for local accounts' is set to 'Enabled' Enabled
3.0.0 18.10.14.3 (L1) Ensure 'Prevent the use of security questions for local accounts' is set to 'Enabled' Enabled
1.10.1 18.9.16.1 (L1) Ensure 'Allow Telemetry' is set to 'Enabled: 0 - Security [Enterprise Only]' or 'Enabled: 1 - Basic' Enabled: 0 - Security [Enterprise Only]
3.0.0 18.10.15.1 (L1) Ensure 'Allow Diagnostic Data' is set to 'Enabled: Diagnostic data off (not recommended)' Enabled: Diagnostic data off (not recommended)
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Disable OneSettings Download' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.10.15.3 (L1) Ensure 'Disable OneSettings Download' is set to 'Enabled' Enabled
1.10.1 18.9.16.3 (L1) Ensure 'Do not show feedback notifications' is set to 'Enabled' Enabled
3.0.0 18.10.15.4 (L1) Ensure 'Do not show feedback notifications' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Limit Diagnostic Log Collection' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.10.15.6 (L1) Ensure 'Limit Diagnostic Log Collection' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Limit Dump Collection' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.10.15.7 (L1) Ensure 'Limit Dump Collection' is set to 'Enabled' Enabled
1.10.1 18.9.16.4 (L1) Ensure 'Toggle user control over Insider builds' is set to 'Disabled' Disabled
3.0.0 18.10.15.8 (L1) Ensure 'Toggle user control over Insider builds' is set to 'Disabled' Disabled
1.10.1 18.9.17.1 (L1) Ensure 'Download Mode' is NOT set to 'Enabled: Internet' Enabled: Internet
3.0.0 18.10.16.1 (L1) Ensure 'Download Mode' is NOT set to 'Enabled: Internet' Enabled: Internet
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Enable App Installer' is set to 'Disabled' Does not exist in CIS 1.10.1
3.0.0 18.10.17.1 (L1) Ensure 'Enable App Installer' is set to 'Disabled' Disabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Enable App Installer Experimental Features' is set to 'Disabled' Does not exist in CIS 1.10.1
3.0.0 18.10.17.2 (L1) Ensure 'Enable App Installer Experimental Features' is set to 'Disabled' Disabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Enable App Installer Hash Override' is set to 'Disabled' Does not exist in CIS 1.10.1
3.0.0 18.10.17.3 (L1) Ensure 'Enable App Installer Hash Override' is set to 'Disabled' Disabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Enable App Installer ms-appinstaller protocol' is set to 'Disabled' Does not exist in CIS 1.10.1
3.0.0 18.10.17.4 (L1) Ensure 'Enable App Installer ms-appinstaller protocol' is set to 'Disabled' Disabled
1.10.1 18.9.26.1.1 (L1) Ensure 'Application: Control Event Log behavior when the log file reaches its maximum size' is set to 'Disabled' Disabled
3.0.0 18.10.25.1.1 (L1) Ensure 'Application: Control Event Log behavior when the log file reaches its maximum size' is set to 'Disabled' Disabled
1.10.1 18.9.26.1.2 (L1) Ensure 'Application: Specify the maximum log file size (KB)' is set to 'Enabled: 32,768 or greater' Enabled: 32,768 or greater
3.0.0 18.10.25.1.2 (L1) Ensure 'Application: Specify the maximum log file size (KB)' is set to 'Enabled: 32,768 or greater' Enabled: 32,768 or greater
1.10.1 18.9.26.2.1 (L1) Ensure 'Security: Control Event Log behavior when the log file reaches its maximum size' is set to 'Disabled' Disabled
3.0.0 18.10.25.2.1 (L1) Ensure 'Security: Control Event Log behavior when the log file reaches its maximum size' is set to 'Disabled' Disabled
1.10.1 18.9.26.2.2 (L1) Ensure 'Security: Specify the maximum log file size (KB)' is set to 'Enabled: 196,608 or greater' Enabled: 196,608 or greater
3.0.0 18.10.25.2.2 (L1) Ensure 'Security: Specify the maximum log file size (KB)' is set to 'Enabled: 196,608 or greater' Enabled: 196,608 or greater
1.10.1 18.9.26.3.1 (L1) Ensure 'Setup: Control Event Log behavior when the log file reaches its maximum size' is set to 'Disabled' Disabled
3.0.0 18.10.25.3.1 (L1) Ensure 'Setup: Control Event Log behavior when the log file reaches its maximum size' is set to 'Disabled' Disabled
1.10.1 18.9.26.3.2 (L1) Ensure 'Setup: Specify the maximum log file size (KB)' is set to 'Enabled: 32,768 or greater' Enabled: 32,768 or greater
3.0.0 18.10.25.3.2 (L1) Ensure 'Setup: Specify the maximum log file size (KB)' is set to 'Enabled: 32,768 or greater' Enabled: 32,768 or greater
1.10.1 18.9.26.4.1  (L1) Ensure 'System: Control Event Log behavior when the log file reaches its maximum size' is set to 'Disabled' Disabled
3.0.0 18.10.25.4.1 (L1) Ensure 'System: Control Event Log behavior when the log file reaches its maximum size' is set to 'Disabled' Disabled
1.10.1 18.9.26.4.2 (L1) Ensure 'System: Specify the maximum log file size (KB)' is set to 'Enabled: 32,768 or greater' Enabled: 32,768 or greater
3.0.0 18.10.25.4.2 (L1) Ensure 'System: Specify the maximum log file size (KB)' is set to 'Enabled: 32,768 or greater' Enabled: 32,768 or greater
1.10.1 18.9.30.2 (L1) Ensure 'Turn off Data Execution Prevention for Explorer' is set to 'Disabled' Disabled
3.0.0 18.10.28.3 (L1) Ensure 'Turn off Data Execution Prevention for Explorer' is set to 'Disabled' Disabled
1.10.1 18.9.30.3 (L1) Ensure 'Turn off heap termination on corruption' is set to 'Disabled' Disabled
3.0.0 18.10.28.4 (L1) Ensure 'Turn off heap termination on corruption' is set to 'Disabled' Disabled
1.10.1 18.9.30.4 (L1) Ensure 'Turn off shell protocol protected mode' is set to 'Disabled' Disabled
3.0.0 18.10.28.5 (L1) Ensure 'Turn off shell protocol protected mode' is set to 'Disabled' Disabled
1.10.1 18.9.35.1 (L1) Ensure 'Prevent the computer from joining a homegroup' is set to 'Enabled' Enabled
3.0.0 Deprecated in CIS 3.0 (L1) Ensure 'Prevent the computer from joining a homegroup' is set to 'Enabled' Deprecated in CIS 3.0
1.10.1 18.9.44.1 (L1) Ensure 'Block all consumer Microsoft account user authentication' is set to 'Enabled' Enabled
3.0.0 18.10.41.1 (L1) Ensure 'Block all consumer Microsoft account user authentication' is set to 'Enabled' Enabled
1.10.1 18.9.45.14 (L1) Ensure 'Configure detection for potentially unwanted applications' is set to 'Enabled: Block' Enabled: Block
3.0.0 18.10.42.16 (L1) Ensure 'Configure detection for potentially unwanted applications' is set to 'Enabled: Block' Enabled: Block
1.10.1 18.9.45.15 (L1) Ensure 'Turn off Microsoft Defender AntiVirus' is set to 'Disabled' Disabled
3.0.0 18.10.42.17 (L1) Ensure 'Turn off Microsoft Defender AntiVirus' is set to 'Disabled' Disabled
1.10.1 18.9.45.3.1 (L1) Ensure 'Configure local setting override for reporting to Microsoft MAPS' is set to 'Disabled' Disabled
3.0.0 18.10.42.5.1 (L1) Ensure 'Configure local setting override for reporting to Microsoft MAPS' is set to 'Disabled' Disabled
1.10.1 18.9.45.4.1.1 (L1) Ensure 'Configure Attack Surface Reduction rules' is set to 'Enabled' Enabled
3.0.0 18.10.42.6.1.1 (L1) Ensure 'Configure Attack Surface Reduction rules' is set to 'Enabled' configured
1.10.1 18.9.45.4.1.2 (L1) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured' configured
3.0.0 18.10.42.6.1.2 (L1) Ensure 'Configure Attack Surface Reduction rules: Set the state for each ASR rule' is 'configured' configured
1.10.1 18.9.45.4.3.1 (L1) Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block' Enabled: Block
3.0.0 18.10.42.6.3.1 (L1) Ensure 'Prevent users and apps from accessing dangerous websites' is set to 'Enabled: Block' Enabled: Block
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Enable file hash computation feature' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.10.42.7.1 (L1) Ensure 'Enable file hash computation feature' is set to 'Enabled' Enabled
1.10.1 18.9.45.8.1 (L1) Ensure 'Scan all downloaded files and attachments' is set to 'Enabled' Enabled
3.0.0 18.10.42.10.1 (L1) Ensure 'Scan all downloaded files and attachments' is set to 'Enabled' Enabled
1.10.1 18.9.45.8.2 (L1) Ensure 'Turn off real-time protection' is set to 'Disabled' Disabled
3.0.0 18.10.42.10.2 (L1) Ensure 'Turn off real-time protection' is set to 'Disabled' Disabled
1.10.1 18.9.45.8.3 (L1) Ensure 'Turn on behavior monitoring' is set to 'Enabled' Enabled
3.0.0 18.10.42.10.3 (L1) Ensure 'Turn on behavior monitoring' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Turn on script scanning' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.10.42.10.4 (L1) Ensure 'Turn on script scanning' is set to 'Enabled' Enabled
1.10.1 18.9.45.11.1 (L1) Ensure 'Scan removable drives' is set to 'Enabled' Enabled
3.0.0 18.10.42.13.2 (L1) Ensure 'Scan removable drives' is set to 'Enabled' Enabled
1.10.1 18.9.45.11.2 (L1) Ensure 'Turn on e-mail scanning' is set to 'Enabled' Enabled
3.0.0 18.10.42.13.3 (L1) Ensure 'Turn on e-mail scanning' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Allow auditing events in Microsoft Defender Application Guard' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.10.43.1 (L1) Ensure 'Allow auditing events in Microsoft Defender Application Guard' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Allow camera and microphone access in Microsoft Defender Application Guard' is set to 'Disabled' Does not exist in CIS 1.10.1
3.0.0 18.10.43.2 (L1) Ensure 'Allow camera and microphone access in Microsoft Defender Application Guard' is set to 'Disabled' Disabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Allow data persistence for Microsoft Defender Application Guard' is set to 'Disabled' Does not exist in CIS 1.10.1
3.0.0 18.10.43.3 (L1) Ensure 'Allow data persistence for Microsoft Defender Application Guard' is set to 'Disabled' Disabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Allow files to download and save to the host operating system from Microsoft Defender Application Guard' is set to 'Disabled' Does not exist in CIS 1.10.1
3.0.0 18.10.43.4 (L1) Ensure 'Allow files to download and save to the host operating system from Microsoft Defender Application Guard' is set to 'Disabled' Disabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Configure Microsoft Defender Application Guard clipboard settings: Clipboard behavior setting' is set to 'Enabled: Enable clipboard operation from an isolated session to the host' Does not exist in CIS 1.10.1
3.0.0 18.10.43.5 (L1) Ensure 'Configure Microsoft Defender Application Guard clipboard settings: Clipboard behavior setting' is set to 'Enabled: Enable clipboard operation from an isolated session to the host' Enabled: Enable clipboard operation from an isolated session to the host
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Turn on Microsoft Defender Application Guard in Managed Mode' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.10.43.6 (L1) Ensure 'Turn on Microsoft Defender Application Guard in Managed Mode' is set to 'Enabled' Enabled
1.10.1 18.9.48.4 (L1) Ensure 'Allow Sideloading of extension' is set to 'Disabled' Disabled
3.0.0 Deprecated in CIS 3.0 (L1) Ensure 'Allow Sideloading of extension' is set to 'Disabled' Deprecated in CIS 3.0
1.10.1 18.9.48.5 (L1) Ensure 'Configure cookies' is set to 'Enabled: Block only 3rd-party cookies' or higher Enabled: Block only 3rd-party cookies'
3.0.0 Deprecated in CIS 3.0 (L1) Ensure 'Configure cookies' is set to 'Enabled: Block only 3rd-party cookies' or higher Deprecated in CIS 3.0
1.10.1 18.9.48.6 (L1) Ensure 'Configure Password Manager' is set to 'Disabled' Disabled
3.0.0 Deprecated in CIS 3.0 (L1) Ensure 'Configure Password Manager' is set to 'Disabled' Deprecated in CIS 3.0
1.10.1 18.9.48.9 (L1) Ensure 'Configure the Adobe Flash Click-to-Run setting' is set to 'Enabled' Enabled
3.0.0 Deprecated in CIS 3.0 (L1) Ensure 'Configure the Adobe Flash Click-to-Run setting' is set to 'Enabled' Deprecated in CIS 3.0
1.10.1 18.9.48.11 (L1) Ensure 'Prevent bypassing Windows Defender SmartScreen prompts for files' is set to 'Enabled' Enabled
3.0.0 Deprecated in CIS 3.0 (L1) Ensure 'Prevent bypassing Windows Defender SmartScreen prompts for files' is set to 'Enabled' Deprecated in CIS 3.0
1.10.1 18.9.48.12 (L1) Ensure 'Prevent certificate error overrides' is set to 'Enabled' Enabled
3.0.0 Deprecated in CIS 3.0 (L1) Ensure 'Prevent certificate error overrides' is set to 'Enabled' Deprecated in CIS 3.0
1.10.1 18.9.55.1 (L1) Ensure 'Prevent the usage of OneDrive for file storage' is set to 'Enabled' Enabled
3.0.0  18.10.50.1 (L1) Ensure 'Prevent the usage of OneDrive for file storage' is set to 'Enabled' Enabled
1.10.1 18.9.62.2.2 (L1) Ensure 'Do not allow passwords to be saved' is set to 'Enabled' Enabled
3.0.0 18.10.56.2.3 (L1) Ensure 'Do not allow passwords to be saved' is set to 'Enabled' Enabled
1.10.1 18.9.62.3.3.2 (L1) Ensure 'Do not allow drive redirection' is set to 'Enabled' Enabled
3.0.0 18.10.56.3.3.3 (L1) Ensure 'Do not allow drive redirection' is set to 'Enabled' Enabled
1.10.1 18.9.62.3.9.1 (L1) Ensure 'Always prompt for password upon connection' is set to 'Enabled' Enabled
3.0.0 18.10.56.3.9.1 (L1) Ensure 'Always prompt for password upon connection' is set to 'Enabled' Enabled
1.10.1 18.9.62.3.9.2 (L1) Ensure 'Require secure RPC communication' is set to 'Enabled' Enabled
3.0.0 18.10.56.3.9.2 (L1) Ensure 'Require secure RPC communication' is set to 'Enabled' Enabled
1.10.1 18.9.62.3.9.3 (L1) Ensure 'Require use of specific security layer for remote (RDP) connections' is set to 'Enabled: SSL' Enabled: SSL
3.0.0 18.10.56.3.9.3 (L1) Ensure 'Require secure RPC communication' is set to 'Enabled: SSL' Enabled: SSL
1.10.1 18.9.62.3.9.4 (L1) Ensure 'Require user authentication for remote connections by using Network Level Authentication' is set to 'Enabled' Enabled
3.0.0 18.10.56.3.9.4 (L1) Ensure 'Require user authentication for remote connections by using Network Level Authentication' is set to 'Enabled' Enabled
1.10.1 18.9.62.3.9.5 (L1) Ensure 'Set client connection encryption level' is set to 'Enabled: High Level' Enabled: High Level
3.0.0 18.10.56.3.9.5 (L1) Ensure 'Set client connection encryption level' is set to 'Enabled: High Level' Enabled: High Level
1.10.1 18.9.62.3.11.1 (L1) Ensure 'Do not delete temp folders upon exit' is set to 'Disabled' Disabled
3.0.0 18.10.56.3.11.1 (L1) Ensure 'Do not delete temp folders upon exit' is set to 'Disabled' Disabled
1.10.1 18.9.63.1 (L1) Ensure 'Prevent downloading of enclosures' is set to 'Enabled' Enabled
3.0.0 18.10.57.1 (L1) Ensure 'Prevent downloading of enclosures' is set to 'Enabled' Enabled
1.10.1 18.9.64.3 (L1) Ensure 'Allow Cortana' is set to 'Disabled' Disabled
3.0.0 18.10.58.3 (L1) Ensure 'Allow Cortana' is set to 'Disabled' Disabled
1.10.1 18.9.64.4 (L1) Ensure 'Allow Cortana above lock screen' is set to 'Disabled' Disabled
3.0.0 18.10.58.4 (L1) Ensure 'Allow Cortana above lock screen' is set to 'Disabled' Disabled
1.10.1 18.9.64.5 (L1) Ensure 'Allow indexing of encrypted files' is set to 'Disabled' Disabled
3.0.0 18.10.58.5 (L1) Ensure 'Allow indexing of encrypted files' is set to 'Disabled' Disabled
1.10.1 18.9.64.6 (L1) Ensure 'Allow search and Cortana to use location' is set to 'Disabled' Disabled
3.0.0 18.10.58.6 (L1) Ensure 'Allow search and Cortana to use location' is set to 'Disabled' Disabled
1.10.1 18.9.72.2 (L1) Ensure 'Only display the private store within the Microsoft Store' is set to 'Enabled' Enabled
3.0.0 18.10.65.2 (L1) Ensure 'Only display the private store within the Microsoft Store' is set to 'Enabled' Enabled
1.10.1 18.9.72.3 (L1) Ensure 'Turn off Automatic Download and Install of updates' is set to 'Disabled' Disabled
3.0.0 18.10.65.3 (L1) Ensure 'Turn off Automatic Download and Install of updates' is set to 'Disabled' Disabled
1.10.1 18.9.72.4 (L1) Ensure 'Turn off the offer to update to the latest version of Windows' is set to 'Enabled' Enabled
3.0.0 18.10.65.4 (L1) Ensure 'Turn off the offer to update to the latest version of Windows' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Allow Widgets' is set to 'Disabled' Does not exist in CIS 1.10.1
3.0.0 18.10.71.1 (L1) Ensure 'Allow Widgets' is set to 'Disabled' Disabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Automatic Data Collection' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.10.75.1.1 (L1) Ensure 'Automatic Data Collection' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Notify Malicious' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.10.75.1.2 (L1) Ensure 'Notify Malicious' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Notify Password Reuse' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.10.75.1.3 (L1) Ensure 'Notify Password Reuse' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Notify Unsafe App' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.10.75.1.4 (L1) Ensure 'Notify Unsafe App' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Service Enabled' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.10.75.1.5 (L1) Ensure 'Service Enabled' is set to 'Enabled' Enabled
1.10.1 18.9.80.1.1 (L1) Ensure 'Configure Windows Defender SmartScreen' is set to 'Enabled: Warn and prevent bypass' Enabled: Warn and prevent bypass
3.0.0 18.10.75.2.1 (L1) Ensure 'Configure Windows Defender SmartScreen' is set to 'Enabled: Warn and prevent bypass' Enabled: Warn and prevent bypass
1.10.1 18.9.80.2.1 (L1) Ensure 'Configure Windows Defender SmartScreen' is set to 'Enabled' Enabled
3.0.0 18.10.75.2.1 (L1) Ensure 'Configure Windows Defender SmartScreen' is set to 'Enabled' Enabled: Warn and prevent bypass
1.10.1 18.9.80.2.2 (L1) Ensure 'Prevent bypassing Windows Defender SmartScreen prompts for sites' is set to 'Enabled' Enabled
3.0.0 Deprecated in CIS 3.0 (L1) Ensure 'Prevent bypassing Windows Defender SmartScreen prompts for sites' is set to 'Enabled' Deprecated in CIS 3.0
1.10.1 18.9.82.1 (L1) Ensure 'Enables or disables Windows Game Recording and Broadcasting' is set to 'Disabled' Disabled
3.0.0 18.10.77.1 (L1) Ensure 'Enables or disables Windows Game Recording and Broadcasting' is set to 'Disabled' Disabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Enable ESS with Supported Peripherals' is set to 'Enabled: 1' Does not exist in CIS 1.10.1
3.0.0 18.10.78.1 (L1) Ensure 'Enable ESS with Supported Peripherals' is set to 'Enabled: 1' Enabled: 1
1.10.1 18.9.84.2 (L1) Ensure 'Allow Windows Ink Workspace' is set to 'Enabled: On, but disallow access above lock' OR 'Disabled' but not 'Enabled: On' Enabled: On
3.0.0 18.10.79.2 (L1) Ensure 'Allow Windows Ink Workspace' is set to 'Enabled: On, but disallow access above lock' OR 'Disabled' but not 'Enabled: On' Enabled: On
1.10.1 18.9.85.1 (L1) Ensure 'Allow user control over installs' is set to 'Disabled' Disabled
3.0.0 18.10.80.1 (L1) Ensure 'Allow user control over installs' is set to 'Disabled' Disabled
1.10.1 18.9.85.2 (L1) Ensure 'Always install with elevated privileges' is set to 'Disabled' Disabled
3.0.0 18.10.80.2 (L1) Ensure 'Always install with elevated privileges' is set to 'Disabled' Disabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Enable MPR notifications for the system' is set to 'Disabled' Does not exist in CIS 1.10.1
3.0.0 18.10.81.1 (L1) Ensure 'Enable MPR notifications for the system' is set to 'Disabled' Disabled
1.10.1 18.9.86.1 (L1) Ensure 'Sign-in and lock last interactive user automatically after a restart' is set to 'Disabled' Disabled
3.0.0 18.10.81.2 (L1) Ensure 'Sign-in and lock last interactive user automatically after a restart' is set to 'Disabled' Disabled
1.10.1 18.9.95.1 (L1) Ensure 'Turn on PowerShell Script Block Logging' is set to 'Disabled' Disabled
3.0.0 Deprecated in CIS 3.0 (L1) Ensure 'Turn on PowerShell Script Block Logging' is set to 'Disabled' Deprecated in CIS 3.0
1.10.1 18.9.95.2 (L1) Ensure 'Turn on PowerShell Transcription' is set to 'Disabled' Disabled
3.0.0 Deprecated in CIS 3.0 (L1) Ensure 'Turn on PowerShell Transcription' is set to 'Disabled' Deprecated in CIS 3.0
1.10.1 18.9.97.1.1 (L1) Ensure 'Allow Basic authentication' is set to 'Disabled' Disabled
3.0.0 18.10.88.1.1 (L1) Ensure 'Allow Basic authentication' is set to 'Disabled' Disabled
1.10.1 18.9.97.1.2 (L1) Ensure 'Allow unencrypted traffic' is set to 'Disabled' Disabled
3.0.0 18.10.88.1.2 (L1) Ensure 'Allow unencrypted traffic' is set to 'Disabled' Disabled
1.10.1 18.9.97.1.3 (L1) Ensure 'Disallow Digest authentication' is set to 'Enabled' Enabled
3.0.0 18.10.88.1.3 (L1) Ensure 'Disallow Digest authentication' is set to 'Enabled' Enabled
1.10.1 18.9.97.2.1 (L1) Ensure 'Allow Basic authentication' is set to 'Disabled' Disabled
3.0.0 18.10.88.2.1 (L1) Ensure 'Allow Basic authentication' is set to 'Disabled' Disabled
1.10.1 18.9.97.2.3 (L1) Ensure 'Allow unencrypted traffic' is set to 'Disabled' Disabled
3.0.0 18.10.88.2.3 (L1) Ensure 'Allow unencrypted traffic' is set to 'Disabled' Disabled
1.10.1 18.9.97.2.4 (L1) Ensure 'Disallow WinRM from storing RunAs credentials' is set to 'Enabled' Enabled
3.0.0 18.10.88.2.4 (L1) Ensure 'Disallow WinRM from storing RunAs credentials' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Allow clipboard sharing with Windows Sandbox' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 18.10.90.1 (L1) Ensure 'Allow clipboard sharing with Windows Sandbox' is set to 'Enabled' Disabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Allow networking in Windows Sandbox' is set to 'Disabled' Does not exist in CIS 1.10.1
3.0.0 18.10.90.2 (L1) Ensure 'Allow networking in Windows Sandbox' is set to 'Disabled' Disabled
1.10.1 18.9.99.2.1 (L1) Ensure 'Prevent users from modifying settings' is set to 'Enabled' Enabled
3.0.0 18.10.91.2.1 (L1) Ensure 'Prevent users from modifying settings' is set to 'Enabled' Enabled
1.10.1 18.9.102.2 (L1) Ensure 'Configure Automatic Updates' is set to 'Enabled' Enabled
3.0.0 18.10.92.2.1 (L1) Ensure 'Configure Automatic Updates' is set to 'Enabled' Enabled
1.10.1 18.9.102.3 (L1) Ensure 'Configure Automatic Updates: Scheduled install day' is set to '0 - Every day' 0 - Every day
3.0.0 18.10.92.2.2 (L1) Ensure 'Configure Automatic Updates: Scheduled install day' is set to '0 - Every day' 0 - Every day
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Enable features introduced via servicing that are off by default' is set to 'Disabled' Does not exist in CIS 1.10.1
3.0.0 18.10.92.2.3 (L1) Ensure 'Enable features introduced via servicing that are off by default' is set to 'Disabled' Disabled
1.10.1 18.9.102.4 (L1) Ensure 'No auto-restart with logged on users for scheduled automatic updates installations' is set to 'Disabled' Disabled
3.0.0 18.10.92.1.1 (L1) Ensure 'No auto-restart with logged on users for scheduled automatic updates installations' is set to 'Disabled' Disabled
1.10.1 18.9.102.5 (L1) Ensure 'Remove access to “Pause updates” feature' is set to 'Enabled' Enabled
3.0.0 18.10.92.2.4 (L1) Ensure 'Remove access to “Pause updates” feature' is set to 'Enabled' Enabled
1.10.1 18.9.102.1.1 (L1) Ensure 'Manage preview builds' is set to 'Enabled: Disable preview builds' Enabled: Disable preview builds
3.0.0 18.10.92.4.1 (L1) Ensure 'Manage preview builds' is set to 'Enabled: Disable preview builds' Disabled
1.10.1 18.9.102.1.2 (L1) Ensure 'Select when Preview Builds and Feature Updates are received' is set to 'Enabled: Semi-Annual Channel, 180 or more days' Enabled: Semi-Annual Channel, 180 or more days
3.0.0 18.10.92.4.2 (L1) Ensure 'Select when Preview Builds and Feature Updates are received' is set to 'Enabled: Semi-Annual Channel, 180 or more days' Enabled: 180 or more days
1.10.1 18.9.102.1.3 (L1) Ensure 'Select when Quality Updates are received' is set to 'Enabled: 0 days' Enabled: 0 days
3.0.0 18.10.92.4.3 (L1) Ensure 'Select when Quality Updates are received' is set to 'Enabled: 0 days' Enabled: 0 days
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Enable optional updates' is set to 'Disabled' Does not exist in CIS 1.10.1
3.0.0 18.10.92.4.4 (L1) Ensure 'Enable optional updates' is set to 'Disabled' Disabled

19. Administrative Templates (User)

19.5 Start Menu and Taskbar

CIS Benchmark Version CIS Control Description Recommended Value
1.10.1 19.5.1.1 (L1) Ensure 'Turn off toast notifications on the lock screen' is set to 'Enabled' Enabled
3.0.0 19.5.1.1 (L1) Ensure 'Turn off toast notifications on the lock screen' is set to 'Enabled' Enabled

19.7 Windows Components

CIS Benchmark Version CIS Control Description Recommended Value
1.10.1 19.7.4.1 (L1) Ensure 'Do not preserve zone information in file attachments' is set to 'Disabled' Disabled
3.0.0 19.7.5.1 (L1) Ensure 'Do not preserve zone information in file attachments' is set to 'Disabled' Disabled
1.10.1 19.7.4.2 (L1) Ensure 'Notify antivirus programs when opening attachments' is set to 'Enabled' Enabled
3.0.0 19.7.5.2 (L1) Ensure 'Notify antivirus programs when opening attachments' is set to 'Enabled' Enabled
1.10.1 19.7.8.1 (L1) Ensure 'Configure Windows spotlight on lock screen' is set to 'Disabled' Disabled
3.0.0 19.7.8.1 (L1) Ensure 'Configure Windows spotlight on lock screen' is set to 'Disabled' Disabled
1.10.1 19.7.8.2 (L1) Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled' Enabled
3.0.0 19.7.8.2 (L1) Ensure 'Do not suggest third-party content in Windows spotlight' is set to 'Enabled' Enabled
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Turn off Spotlight collection on Desktop' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 19.7.8.5 (L1) Ensure 'Turn off Spotlight collection on Desktop' is set to 'Enabled' Enabled

19.7.26 Network Sharing

CIS Benchmark Version CIS Control Description Recommended Value
1.10.1 19.7.28.1 (L1) Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled' Enabled
3.0.0 19.7.26.1 (L1) Ensure 'Prevent users from sharing files within their profile.' is set to 'Enabled' Enabled

19.7.38 Windows Copilot

CIS Benchmark Version CIS Control Description Recommended Value
1.10.1 Does not exist in CIS 1.10.1 (L1) Ensure 'Turn off Windows Copilot' is set to 'Enabled' Does not exist in CIS 1.10.1
3.0.0 19.7.38.1 (L1) Ensure 'Turn off Windows Copilot' is set to 'Enabled' Enabled

19.7.42 Windows Installer

CIS Benchmark Version CIS Control Description Recommended Value
1.10.1 19.7.43.1 (L1) Ensure 'Always install with elevated privileges' is set to 'Disabled' Disabled
3.0.0 19.7.42.1 (L1) Ensure 'Always install with elevated privileges' is set to 'Disabled' Disabled