Ensure ‘Debug programs’ is set to ‘Administrators’ Details This policy setting determines which user accounts will have the right to attach a debugger to any process or...
Ensure ‘Deny access to this computer from the network’ to include ‘Guests, Local account’ Details This policy setting prohibits users from connecting to a computer from across the network, which would allow users to...
Ensure ‘Deny log on as a batch job’ to include ‘Guests’ Details This policy setting determines which accounts will not be able to log on to the computer as a batch...
Ensure ‘Deny log on as a service’ to include ‘Guests’ Details This security setting determines which service accounts are prevented from registering a process as a service. This user right...
Ensure ‘Deny log on locally’ to include ‘Guests’ Details This security setting determines which users are prevented from logging on at the computer. This policy setting supersedes the...
Ensure ‘Deny log on through Remote Desktop Services’ to include ‘Guests, Local account’ Details This policy setting determines whether users can log on as Remote Desktop clients. After the baseline workstation is joined...
Ensure ‘Enable computer and user accounts to be trusted for delegation’ is set to ‘No One’ Details This policy setting allows users to change the Trusted for Delegation setting on a computer object in Active Directory....
Ensure ‘Enforce password history’ is set to ’24 or more password(s)’ Details This policy setting determines the number of renewed, unique passwords that have to be associated with a user account...
Ensure ‘Force shutdown from a remote system’ is set to ‘Administrators’ Details This policy setting allows users to shut down Windows Vista-based and newer computers from remote locations on the network....
Ensure ‘Generate security audits’ is set to ‘LOCAL SERVICE, NETWORK SERVICE’ Details This policy setting determines which users or processes can generate audit records in the Security log. The recommended state...