Skip to content

Microsoft Windows 11 Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Unused accounts must be disabled or removed from the system after 35 days of inactivity.

    <VulnDiscussion>Outdated or unused accounts provide penetration points that may go undetected. Inactive accounts must be deleted if no longer...
    Rule Low Severity
  • SRG-OS-000312-GPOS-00123

    <GroupDescription></GroupDescription>
    Group
  • Software certificate installation files must be removed from Windows 11.

    &lt;VulnDiscussion&gt;Use of software certificates and their accompanying installation files for end users to access resources is less secure than ...
    Rule Medium Severity
  • Only accounts responsible for the administration of a system must have Administrator rights on the system.

    &lt;VulnDiscussion&gt;An account that does not have Administrator duties must not have Administrator rights. Such rights would allow the account to...
    Rule High Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules