Skip to content

III - Administrative Public

Rules and Groups employed by this XCCDF Profile

  • SRG-OS-000073-GPOS-00041

    Group
  • Windows Server 2019 must be configured to prevent the storage of the LAN Manager hash of passwords.

    The LAN Manager hash uses a weak encryption algorithm and there are several tools available that use this hash to retrieve account passwords. This setting controls whether a LAN Manager hash of the...
    Rule High Severity
  • SRG-OS-000074-GPOS-00042

    Group
  • Windows Server 2019 unencrypted passwords must not be sent to third-party Server Message Block (SMB) servers.

    Some non-Microsoft SMB servers only support unencrypted (plain-text) password authentication. Sending plain-text passwords across the network when authenticating to an SMB server reduces the overal...
    Rule Medium Severity
  • SRG-OS-000075-GPOS-00043

    Group
  • Windows Server 2019 minimum password age must be configured to at least one day.

    Permitting passwords to be changed in immediate succession within the same day allows users to cycle passwords through their history database. This enables users to effectively negate the purpose o...
    Rule Medium Severity
  • SRG-OS-000076-GPOS-00044

    Group
  • Windows Server 2019 passwords for the built-in Administrator account must be changed at least every 60 days.

    The longer a password is in use, the greater the opportunity for someone to gain unauthorized knowledge of the password. The built-in Administrator account is not generally used and its password mi...
    Rule Medium Severity
  • SRG-OS-000076-GPOS-00044

    Group
  • Windows Server 2019 passwords must be configured to expire.

    Passwords that do not expire or are reused increase the exposure of a password with greater probability of being discovered or cracked.
    Rule Medium Severity
  • SRG-OS-000076-GPOS-00044

    Group
  • Windows Server 2019 maximum password age must be configured to 60 days or less.

    The longer a password is in use, the greater the opportunity for someone to gain unauthorized knowledge of the passwords. Scheduled changing of passwords hinders the ability of unauthorized system ...
    Rule Medium Severity
  • SRG-OS-000077-GPOS-00045

    Group
  • Windows Server 2019 password history must be configured to 24 passwords remembered.

    A system is more vulnerable to unauthorized access when system users recycle the same password several times without being required to change to a unique password on a regularly scheduled basis. Th...
    Rule Medium Severity
  • SRG-OS-000078-GPOS-00046

    Group
  • Windows Server 2019 manually managed application account passwords must be at least 14 characters in length.

    Application/service account passwords must be of sufficient length to prevent being easily cracked. Application/service accounts that are manually managed must have passwords at least 14 characters...
    Rule Medium Severity
  • SRG-OS-000078-GPOS-00046

    Group
  • Windows Server 2019 minimum password length must be configured to 14 characters.

    Information systems not protected with strong password schemes (including passwords of minimum length) provide the opportunity for anyone to crack the password, thus gaining access to the system an...
    Rule Medium Severity
  • SRG-OS-000080-GPOS-00048

    Group
  • Windows Server 2019 local volumes must use a format that supports NTFS attributes.

    The ability to set access permissions and auditing is critical to maintaining the security and proper access controls of a system. To support this, volumes must be formatted using a file system tha...
    Rule High Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules