Skip to content

Latest commit

 

History

History
28 lines (25 loc) · 6.88 KB

security-general-checks.md

File metadata and controls

28 lines (25 loc) · 6.88 KB

Security general checks

Legend



Area Test Possible approach Details
Built-in Accounts Verify Administrator account should have Account is sensitive and cannot be delegated [Enabled] Docs.Microsoft.com
Built-in Accounts Verify Administrator account should have Smart card is required for interactive logon [Enabled] Docs.Microsoft.com
Built-in Accounts Verify CONTOSO\Administrator account for all workstations and member server has Deny access to this computer from the network [Enabled] Settings in Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignments Docs.Microsoft.com
Built-in Accounts Verify CONTOSO\Administrator account for all workstations and member server has Deny log on as a batch job [Enabled] Settings in Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignments Docs.Microsoft.com
Built-in Accounts Verify CONTOSO\Administrator account for all workstations and member server has Deny log on as a service [Enabled] Settings in Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignments Docs.Microsoft.com
Built-in Accounts Verify CONTOSO\Administrator account for all workstations and member server has Deny log on through Remote Desktop Services [Enabled] Settings in Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignments Docs.Microsoft.com
Built-in Accounts Verify CONTOSO\Administrator account for all Domain Controllers has Deny access to this computer from the network [Enabled] Settings in Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignments Docs.Microsoft.com
Built-in Accounts Verify CONTOSO\Administrator account for all Domain Controllers has Deny log on as a batch job [Enabled] Settings in Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignments Docs.Microsoft.com
Built-in Accounts Verify CONTOSO\Administrator account for all Domain Controllers has Deny log on as a service [Enabled] Settings in Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignments Docs.Microsoft.com
Built-in Accounts Verify CONTOSO\Administrator account for all Domain Controllers has Deny log on through Remote Desktop Services [Enabled] Settings in Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignments Docs.Microsoft.com
Built-in Groups Verify Enterpise Admins Group has only CONTOSO\Administrator account as memberOf
Built-in Accounts Verify Enterpise Admins Group for all workstations and member server has Deny access to this computer from the network [Enabled] Settings in Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignments Docs.Microsoft.com
Built-in Accounts Verify Enterpise Admins Group for all workstations and member server has Deny log on as a batch job [Enabled] Settings in Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignments Docs.Microsoft.com
Built-in Accounts Verify Enterpise Admins Group for all workstations and member server has Deny log on as a service [Enabled] Settings in Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignments Docs.Microsoft.com
Built-in Accounts Verify Enterpise Admins Group for all workstations and member server has Deny log on locally [Enabled] Settings in Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignments Docs.Microsoft.com
Built-in Accounts Verify Enterpise Admins Group for all workstations and member server has Deny log on through Remote Desktop Services [Enabled] Settings in Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignments Docs.Microsoft.com