III - Administrative Classified
Rules and Groups employed by this XCCDF Profile
-
SRG-OS-000066-GPOS-00034
Group -
Windows Server 2019 must have the DoD Interoperability Root Certificate Authority (CA) cross-certificates installed in the Untrusted Certificates Store on unclassified systems.
To ensure users do not experience denial of service when performing certificate-based authentication to DoD websites due to the system chaining to a root other than DoD Root CAs, the DoD Interopera...Rule Medium Severity -
SRG-OS-000066-GPOS-00034
Group -
Windows Server 2019 must have the US DoD CCEB Interoperability Root CA cross-certificates in the Untrusted Certificates Store on unclassified systems.
To ensure users do not experience denial of service when performing certificate-based authentication to DoD websites due to the system chaining to a root other than DoD Root CAs, the US DoD CCEB In...Rule Medium Severity -
SRG-OS-000067-GPOS-00035
Group -
Windows Server 2019 users must be required to enter a password to access private keys stored on the computer.
If the private key is discovered, an attacker can use the key to authenticate as an authorized user and gain access to the network infrastructure. The cornerstone of the PKI is the private key use...Rule Medium Severity -
SRG-OS-000069-GPOS-00037
Group -
Windows Server 2019 must have the built-in Windows password complexity policy enabled.
The use of complex passwords increases their strength against attack. The built-in Windows password complexity policy requires passwords to contain at least three of the four types of characters (n...Rule Medium Severity -
SRG-OS-000073-GPOS-00041
Group -
Windows Server 2019 reversible password encryption must be disabled.
Storing passwords using reversible encryption is essentially the same as storing clear-text versions of the passwords, which are easily compromised. For this reason, this policy must never be enabled.Rule High Severity -
SRG-OS-000073-GPOS-00041
Group -
Windows Server 2019 must be configured to prevent the storage of the LAN Manager hash of passwords.
The LAN Manager hash uses a weak encryption algorithm and there are several tools available that use this hash to retrieve account passwords. This setting controls whether a LAN Manager hash of the...Rule High Severity -
SRG-OS-000074-GPOS-00042
Group -
Windows Server 2019 unencrypted passwords must not be sent to third-party Server Message Block (SMB) servers.
Some non-Microsoft SMB servers only support unencrypted (plain-text) password authentication. Sending plain-text passwords across the network when authenticating to an SMB server reduces the overal...Rule Medium Severity -
SRG-OS-000075-GPOS-00043
Group -
Windows Server 2019 minimum password age must be configured to at least one day.
Permitting passwords to be changed in immediate succession within the same day allows users to cycle passwords through their history database. This enables users to effectively negate the purpose o...Rule Medium Severity -
SRG-OS-000076-GPOS-00044
Group -
Windows Server 2019 passwords for the built-in Administrator account must be changed at least every 60 days.
The longer a password is in use, the greater the opportunity for someone to gain unauthorized knowledge of the password. The built-in Administrator account is not generally used and its password mi...Rule Medium Severity -
SRG-OS-000076-GPOS-00044
Group -
Windows Server 2019 passwords must be configured to expire.
Passwords that do not expire or are reused increase the exposure of a password with greater probability of being discovered or cracked.Rule Medium Severity -
SRG-OS-000076-GPOS-00044
Group -
Windows Server 2019 maximum password age must be configured to 60 days or less.
The longer a password is in use, the greater the opportunity for someone to gain unauthorized knowledge of the passwords. Scheduled changing of passwords hinders the ability of unauthorized system ...Rule Medium Severity -
SRG-OS-000077-GPOS-00045
Group -
Windows Server 2019 password history must be configured to 24 passwords remembered.
A system is more vulnerable to unauthorized access when system users recycle the same password several times without being required to change to a unique password on a regularly scheduled basis. Th...Rule Medium Severity -
SRG-OS-000078-GPOS-00046
Group -
Windows Server 2019 manually managed application account passwords must be at least 14 characters in length.
Application/service account passwords must be of sufficient length to prevent being easily cracked. Application/service accounts that are manually managed must have passwords at least 14 characters...Rule Medium Severity -
SRG-OS-000078-GPOS-00046
Group -
Windows Server 2019 minimum password length must be configured to 14 characters.
Information systems not protected with strong password schemes (including passwords of minimum length) provide the opportunity for anyone to crack the password, thus gaining access to the system an...Rule Medium Severity -
SRG-OS-000080-GPOS-00048
Group -
Windows Server 2019 local volumes must use a format that supports NTFS attributes.
The ability to set access permissions and auditing is critical to maintaining the security and proper access controls of a system. To support this, volumes must be formatted using a file system tha...Rule High Severity -
SRG-OS-000080-GPOS-00048
Group -
Windows Server 2019 non-administrative accounts or groups must only have print permissions on printer shares.
Windows shares are a means by which files, folders, printers, and other resources can be published for network users to access. Improper configuration can permit access to devices and data beyond a...Rule Low Severity -
SRG-OS-000080-GPOS-00048
Group -
Windows Server 2019 Access this computer from the network user right must only be assigned to the Administrators, Authenticated Users, and Enterprise Domain Controllers groups on domain controllers.
Inappropriate granting of user rights can provide system, administrative, and other high-level capabilities. Accounts with the "Access this computer from the network" right may access resources on...Rule Medium Severity -
SRG-OS-000080-GPOS-00048
Group -
Windows Server 2019 Allow log on through Remote Desktop Services user right must only be assigned to the Administrators group on domain controllers.
Inappropriate granting of user rights can provide system, administrative, and other high-level capabilities. Accounts with the "Allow log on through Remote Desktop Services" user right can access ...Rule Medium Severity -
SRG-OS-000080-GPOS-00048
Group -
Windows Server 2019 Deny access to this computer from the network user right on domain controllers must be configured to prevent unauthenticated access.
Inappropriate granting of user rights can provide system, administrative, and other high-level capabilities. The "Deny access to this computer from the network" user right defines the accounts tha...Rule Medium Severity -
SRG-OS-000080-GPOS-00048
Group -
Windows Server 2019 Deny log on as a batch job user right on domain controllers must be configured to prevent unauthenticated access.
Inappropriate granting of user rights can provide system, administrative, and other high-level capabilities. The "Deny log on as a batch job" user right defines accounts that are prevented from lo...Rule Medium Severity -
SRG-OS-000080-GPOS-00048
Group -
Windows Server 2019 Deny log on as a service user right must be configured to include no accounts or groups (blank) on domain controllers.
Inappropriate granting of user rights can provide system, administrative, and other high-level capabilities. The "Deny log on as a service" user right defines accounts that are denied logon as a s...Rule Medium Severity -
SRG-OS-000080-GPOS-00048
Group -
Windows Server 2019 Deny log on locally user right on domain controllers must be configured to prevent unauthenticated access.
Inappropriate granting of user rights can provide system, administrative, and other high-level capabilities. The "Deny log on locally" user right defines accounts that are prevented from logging o...Rule Medium Severity -
SRG-OS-000080-GPOS-00048
Group -
Windows Server 2019 "Access this computer from the network" user right must only be assigned to the Administrators and Authenticated Users groups on domain-joined member servers and standalone or nondomain-joined systems.
Inappropriate granting of user rights can provide system, administrative, and other high-level capabilities. Accounts with the "Access this computer from the network" user right may access resourc...Rule Medium Severity -
SRG-OS-000080-GPOS-00048
Group -
Windows Server 2019 "Deny access to this computer from the network" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and local accounts and from unauthenticated access on all systems.
Inappropriate granting of user rights can provide system, administrative, and other high-level capabilities. The "Deny access to this computer from the network" user right defines the accounts tha...Rule Medium Severity -
SRG-OS-000080-GPOS-00048
Group -
Windows Server 2019 "Deny log on as a batch job" user right on domain-joined member servers must be configured to prevent access from highly privileged domain accounts and from unauthenticated access on all systems.
Inappropriate granting of user rights can provide system, administrative, and other high-level capabilities. The "Deny log on as a batch job" user right defines accounts that are prevented from lo...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.