CIS Windows 10 Enterprise Benchmark
Secure configuration guidelines for Microsoft Windows 10 Enterprise
v3.0.0 November 2024Overview
▶This CIS Benchmark provides prescriptive guidance for establishing a secure configuration posture for Microsoft Windows 10 Enterprise. Recommendations cover account policies, local policies, Windows Firewall, audit policies, security options, and advanced hardening features including Credential Guard and BitLocker.
| Section | Area | Focus |
|---|---|---|
| 1 | Account Policies | Passwords, lockout |
| 2 | Local Policies | User rights, security options |
| 3 | Firewall | Domain, private, public |
| 4 | Audit | Logon, account management |
| 5 | Advanced | Defender, Credential Guard |
| 6 | Data Protection | BitLocker, privacy |
Profile Definitions
▶| Profile | Description | Intended Use |
|---|---|---|
| L1 | Level 1 — Standard | Essential security for all Windows 10 Enterprise deployments; minimal performance impact. |
| L2 | Level 2 — Hardened | Advanced hardening for PCI-DSS, HIPAA, or high-security environments. |
1 — Account Policies
▶1.1 Password Policy
▶This recommendation verifies that Minimum Password Length Is Set to 14 or More on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Minimum Password Length Is Set to 14 or More. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Minimum Password Length Is Set to 14 or More. Run gpupdate /force to apply.
This recommendation verifies that Password History Is Set to 24 or More on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Password History Is Set to 24 or More. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Password History Is Set to 24 or More. Run gpupdate /force to apply.
This recommendation verifies that Maximum Password Age Is Set to 365 or Fewer Days on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Maximum Password Age Is Set to 365 or Fewer Days. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Maximum Password Age Is Set to 365 or Fewer Days. Run gpupdate /force to apply.
This recommendation verifies that Minimum Password Age Is Set to 1 or More Days on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Minimum Password Age Is Set to 1 or More Days. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Minimum Password Age Is Set to 1 or More Days. Run gpupdate /force to apply.
This recommendation verifies that Password Must Meet Complexity Requirements Is Enabled on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Password Must Meet Complexity Requirements Is Enabled. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Password Must Meet Complexity Requirements Is Enabled. Run gpupdate /force to apply.
1.2 Account Lockout
▶This recommendation verifies that Account Lockout Duration Is Set to 15 or More Minutes on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Account Lockout Duration Is Set to 15 or More Minutes. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Account Lockout Duration Is Set to 15 or More Minutes. Run gpupdate /force to apply.
This recommendation verifies that Account Lockout Threshold Is Set to 5 or Fewer Attempts on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Account Lockout Threshold Is Set to 5 or Fewer Attempts. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Account Lockout Threshold Is Set to 5 or Fewer Attempts. Run gpupdate /force to apply.
This recommendation verifies that Reset Account Lockout Counter Is Set to 15 or More Minutes on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Reset Account Lockout Counter Is Set to 15 or More Minutes. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Reset Account Lockout Counter Is Set to 15 or More Minutes. Run gpupdate /force to apply.
2 — Local Policies
▶2.1 User Rights Assignment
▶This recommendation verifies that Access This Computer from the Network Is Configured on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Access This Computer from the Network Is Configured. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Access This Computer from the Network Is Configured. Run gpupdate /force to apply.
This recommendation verifies that Act as Part of the Operating System Is Set to No One on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Act as Part of the Operating System Is Set to No One. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Act as Part of the Operating System Is Set to No One. Run gpupdate /force to apply.
This recommendation verifies that Debug Programs Is Set to Administrators on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Debug Programs Is Set to Administrators. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Debug Programs Is Set to Administrators. Run gpupdate /force to apply.
This recommendation verifies that Deny Log On Locally Includes Guests on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Deny Log On Locally Includes Guests. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Deny Log On Locally Includes Guests. Run gpupdate /force to apply.
2.2 Security Options
▶This recommendation verifies that Accounts: Rename Administrator Account Is Configured on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Accounts: Rename Administrator Account Is Configured. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Accounts: Rename Administrator Account Is Configured. Run gpupdate /force to apply.
This recommendation verifies that Accounts: Rename Guest Account Is Configured on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Accounts: Rename Guest Account Is Configured. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Accounts: Rename Guest Account Is Configured. Run gpupdate /force to apply.
This recommendation verifies that Interactive Logon: Do Not Display Last Username Is Enabled on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Interactive Logon: Do Not Display Last Username Is Enabled. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Interactive Logon: Do Not Display Last Username Is Enabled. Run gpupdate /force to apply.
This recommendation verifies that Network Access: Do Not Allow Anonymous Enumeration of SAM Accounts Is Enabled on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Network Access: Do Not Allow Anonymous Enumeration of SAM Accounts Is Enabled. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Network Access: Do Not Allow Anonymous Enumeration of SAM Accounts Is Enabled. Run gpupdate /force to apply.
This recommendation verifies that User Account Control: Admin Approval Mode Is Enabled on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that User Account Control: Admin Approval Mode Is Enabled. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set User Account Control: Admin Approval Mode Is Enabled. Run gpupdate /force to apply.
3 — Windows Firewall
▶3.1 Domain Profile
▶This recommendation verifies that Windows Firewall Domain Profile Is Enabled on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Windows Firewall Domain Profile Is Enabled. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Windows Firewall Domain Profile Is Enabled. Run gpupdate /force to apply.
This recommendation verifies that Domain Inbound Connections Are Set to Block on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Domain Inbound Connections Are Set to Block. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Domain Inbound Connections Are Set to Block. Run gpupdate /force to apply.
This recommendation verifies that Domain Outbound Connections Are Set to Allow on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Domain Outbound Connections Are Set to Allow. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Domain Outbound Connections Are Set to Allow. Run gpupdate /force to apply.
This recommendation verifies that Domain Firewall Logging Is Configured on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Domain Firewall Logging Is Configured. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Domain Firewall Logging Is Configured. Run gpupdate /force to apply.
3.2 Private & Public Profile
▶This recommendation verifies that Windows Firewall Private Profile Is Enabled on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Windows Firewall Private Profile Is Enabled. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Windows Firewall Private Profile Is Enabled. Run gpupdate /force to apply.
This recommendation verifies that Windows Firewall Public Profile Is Enabled on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Windows Firewall Public Profile Is Enabled. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Windows Firewall Public Profile Is Enabled. Run gpupdate /force to apply.
This recommendation verifies that Public Inbound Connections Are Set to Block on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Public Inbound Connections Are Set to Block. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Public Inbound Connections Are Set to Block. Run gpupdate /force to apply.
This recommendation verifies that Private and Public Firewall Logging Is Configured on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Private and Public Firewall Logging Is Configured. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Private and Public Firewall Logging Is Configured. Run gpupdate /force to apply.
4 — Audit Policy
▶4.1 Account Management
▶This recommendation verifies that Audit Credential Validation Is Set to Success and Failure on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Audit Credential Validation Is Set to Success and Failure. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Audit Credential Validation Is Set to Success and Failure. Run gpupdate /force to apply.
This recommendation verifies that Audit Security Group Management Is Set to Success on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Audit Security Group Management Is Set to Success. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Audit Security Group Management Is Set to Success. Run gpupdate /force to apply.
This recommendation verifies that Audit User Account Management Is Set to Success and Failure on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Audit User Account Management Is Set to Success and Failure. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Audit User Account Management Is Set to Success and Failure. Run gpupdate /force to apply.
4.2 Logon & Object Access
▶This recommendation verifies that Audit Logon Is Set to Success and Failure on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Audit Logon Is Set to Success and Failure. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Audit Logon Is Set to Success and Failure. Run gpupdate /force to apply.
This recommendation verifies that Audit Account Lockout Is Set to Failure on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Audit Account Lockout Is Set to Failure. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Audit Account Lockout Is Set to Failure. Run gpupdate /force to apply.
This recommendation verifies that Audit Other Logon/Logoff Events Is Set to Success and Failure on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Audit Other Logon/Logoff Events Is Set to Success and Failure. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Audit Other Logon/Logoff Events Is Set to Success and Failure. Run gpupdate /force to apply.
This recommendation verifies that Audit Policy Change Is Set to Success and Failure on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Audit Policy Change Is Set to Success and Failure. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Audit Policy Change Is Set to Success and Failure. Run gpupdate /force to apply.
This recommendation verifies that Audit Sensitive Privilege Use Is Set to Success and Failure on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Audit Sensitive Privilege Use Is Set to Success and Failure. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Audit Sensitive Privilege Use Is Set to Success and Failure. Run gpupdate /force to apply.
5 — Advanced Security
▶5.1 Defender & Exploit Guard
▶This recommendation verifies that Microsoft Defender Antivirus Is Enabled on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Microsoft Defender Antivirus Is Enabled. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Microsoft Defender Antivirus Is Enabled. Run gpupdate /force to apply.
This recommendation verifies that Real-Time Protection Is Enabled on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Real-Time Protection Is Enabled. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Real-Time Protection Is Enabled. Run gpupdate /force to apply.
This recommendation verifies that Cloud-Delivered Protection Is Enabled on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Cloud-Delivered Protection Is Enabled. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Cloud-Delivered Protection Is Enabled. Run gpupdate /force to apply.
This recommendation verifies that Attack Surface Reduction Rules Are Configured on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Attack Surface Reduction Rules Are Configured. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Attack Surface Reduction Rules Are Configured. Run gpupdate /force to apply.
5.2 Credential & Device Guard
▶This recommendation verifies that Credential Guard Is Enabled on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Credential Guard Is Enabled. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Credential Guard Is Enabled. Run gpupdate /force to apply.
This recommendation verifies that Secure Boot Is Enabled on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Secure Boot Is Enabled. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Secure Boot Is Enabled. Run gpupdate /force to apply.
This recommendation verifies that Device Guard Is Configured on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Device Guard Is Configured. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Device Guard Is Configured. Run gpupdate /force to apply.
6 — Data Protection
▶6.1 BitLocker
▶This recommendation verifies that BitLocker Drive Encryption Is Enabled on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that BitLocker Drive Encryption Is Enabled. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set BitLocker Drive Encryption Is Enabled. Run gpupdate /force to apply.
This recommendation verifies that BitLocker Recovery Key Is Stored in AD on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that BitLocker Recovery Key Is Stored in AD. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set BitLocker Recovery Key Is Stored in AD. Run gpupdate /force to apply.
This recommendation ensures that BitLocker PIN Is Required at Startup on the Windows 10 Enterprise desktop operating system. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Windows 10 Enterprise desktop operating system may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that BitLocker PIN Is Required at Startup. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set BitLocker PIN Is Required at Startup. Run gpupdate /force to apply.
6.2 Privacy & Telemetry
▶This recommendation verifies that Diagnostic Data Is Set to Required on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Diagnostic Data Is Set to Required. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Diagnostic Data Is Set to Required. Run gpupdate /force to apply.
This setting ensures that Windows Ink Workspace Is Restricted on the Windows 10 Enterprise desktop operating system. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Windows 10 Enterprise desktop operating system is essential for defense in depth.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Windows Ink Workspace Is Restricted. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Windows Ink Workspace Is Restricted. Run gpupdate /force to apply.
This recommendation verifies that Cortana Is Disabled on the Windows 10 Enterprise desktop operating system. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.
Running unnecessary components on the Windows 10 Enterprise desktop operating system increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Cortana Is Disabled. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Cortana Is Disabled. Run gpupdate /force to apply.
This recommendation verifies that Consumer Experience Features Are Disabled on the Windows 10 Enterprise desktop operating system. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Windows 10 Enterprise desktop operating system vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Open Group Policy Editor (gpedit.msc) or run gpresult /r and verify that Consumer Experience Features Are Disabled. Alternatively, check the registry setting.
Configure via Group Policy: navigate to the appropriate policy path and set Consumer Experience Features Are Disabled. Run gpupdate /force to apply.