
| Additional Restrictions for Anonymous Connections Security Objective: Set restrictions on anonymous connections to the computer. Computer Setting: Do not allow enumeration of SAM accounts and shares |  | |

| Allow Server Operators to Schedule Tasks (Domain Controllers Only) Security Objective: Determines if Server Operators are allowed to submit jobs by means of the AT schedule facility. Computer Setting: Disabled (The AT schedule facility is not part of the Evaluated Configuration.) |  | |

| Allow System to be Shut Down Without Logon Without Having to Log On Security Objective: Set a computer to allow shutdown without requiring a user to logon. Computer Setting: Disabled |  | |

| Allowed to Eject Removable NTFS Media Security Objective: Set the accounts allowed to eject removable NTFS media from the computer. Computer Setting: Accounts defined in the policy: _________________________ (Recommended: Administrators) | |  |

| Amount of Idle Time Required Before Disconnecting a Session Security Objective: Set the amount of continuous idle time that must pass in a Server Message Block (SMB) session before the session is disconnected due to inactivity. Computer Setting: _____ minutes (Recommended: Do not change the default setting of 15 minutes.) | |  |

| Audit the Access of Global System Objects Security Objective: Allows access of global system objects to be audited. Computer Setting: Enabled Disabled
(Recommended: Enabled, only when there is a strict audit management process in place.) | |  |

| Audit the Use of Backup and Restore Privilege Security Objective: Allow auditing of Backup and Restore user rights. Computer Setting: Enabled Disabled
(Recommended: Enabled, only when there is a strict audit management process in place.) | |  |

| Automatically Log Off Users When Logon Time Expires Security Objective: When enabled, disconnects users that are connected to the local machine outside of their user account's valid logon hours. Can only be set on DCs. Computer Setting: Enabled Disabled
(Recommended: Enabled) | |  |

| Automatically Log Off Users When Logon Time Expires (Local) Security Objective: When enabled, disconnects users that are connected to the local machine outside of their user account's valid logon hours. Computer Setting: Enabled Disabled
(Recommended: Enabled) | |  |

| Clear Virtual Memory Pagefile When System Shuts Down Security Objective: Determines whether the virtual memory pagefile should be cleared when the system is shut down. Computer Setting: Enabled |  | |

| Digitally Sign Client Communications (Always) Security Objective: Determines whether the computer will always digitally sign client communications. Computer Setting: Disabled |  | |

| Digitally Sign Client Communications (When Possible) Security Objective: If enabled, causes the SMB client to perform SMB packet signing only when communicating with an SMB server that is enabled or required to perform SMB packet signing. Computer Setting: Enabled |  | |

| Digitally Sign Server Communications (Always) Security Objective: If enabled, requires the SMB server to perform SMB packet signing. Computer Setting: Disabled |  | |

| Digitally Sign Server Communications (When Possible) Security Objective: If enabled, causes the SMB server to perform SMB packet signing when necessary. Computer Setting: Enabled |  | |

| Disable CTRL+ALT+DEL Requirement for Logon Security Objective: Determines whether pressing CTRL+ALT+DEL is required before a user can log on. Computer Setting: Disabled (A "Disabled" setting actually enables/requires the use of CTRL+ALT+DEL) |  | |

| Do Not Display Last User Name in Logon Screen Security Objective: Determines whether the name of the last user to logon to the computer is displayed in the Windows logon screen. Computer Setting: Enabled Disabled
(Recommended: Enabled) | |  |

| LAN Manager Authentication Level Security Objective: Determines which challenge/response authentication protocol is used for network logons. Computer Setting: Selected Option: _______________________________________ (Recommended: Send NTLMv2 response only/refuse LM & NTLM) | |  |

| Message Text for Users Attempting to Log On Security Objective: Specifies a text message that is displayed to users when they log on. Computer Setting: Message text: __________________________________ ___________________________________ ___________________________________ ___________________________________ (Recommended: Set a warning banner in accordance to local policy requirements.) | |  |

| Message Title for Users Attempting to Log On Security Objective: Specifies a title that appears in the title bar of the window containing the message text for users attempting to log on. Computer Setting: Message title: _____________________________________ (Recommended: Set a warning banner in accordance to local policy requirements.) | |  |

| Number of Previous Logons to Cache (In Case Domain Controller is not Available) Security Objective: Determines the number of times a user can log on to a Windows domain using cached account information. Computer Setting: Cache: 0 logons |  | |

| Prevent System Maintenance of Computer Account Password Security Objective: Determines whether the computer account password should be prevented from being reset every week. If this policy is enabled, the machine is prevented from requesting a weekly password change. Computer Setting: Enabled Disabled
(Recommended: Verify that local policies are set at the default of Disabled, and that Domain Policies are either Disabled or Not Defined.) | |  |

| Prevent Users from Installing Print Drivers Security Objective: Determines whether members of the Users group are prevented from installing print drivers. Computer Setting: Enabled |  | |

| Prompt User to Change Password Before Expiration Security Objective: Determines how far in advance Windows 2000 should warn users that their password is about to expire. Computer Setting: _____ days (Recommended: Default setting of 14 days is adequate.) | |  |

| Recovery Console: Allow Automatic Administrative Logon Security Objective: If set, the Recovery Console does not require a password and will automatically log on to the system. Computer Setting: Disabled (The Recovery Console is not part of the Evaluated Configuration.) |  | |

| Recovery Console: Allow Floppy Copy and Access to all Drives and all Folders Security Objective: Enabling this option enables the Recovery Console SET command. Computer Setting: Enabled Disabled
(Recommended: Do not enable this option. The Recovery Console is not part of the Evaluated Configuration.) | |  |

| Rename Administrator Account Security Objective: Associates a different account name with the security identifier (SID) for the account "Administrator". Computer Setting: (Recommended: Change and safeguard the recorded account name. Do not record it in this document.) | |  |

| Rename Guest Account Security Objective: Associates a different account name with the security identifier (SID) for the account Guest. Computer Setting: (Recommended: Change and safeguard the recorded account name. Do not record it in this document.) | |  |

| Restrict CD-ROM Access to Locally Logged-On User Only Security Objective: If enabled, this policy allows only the interactively logged-on user to access removable CD-ROM media. Computer Setting: Enabled |  | |

| Restrict Floppy Access to Locally Logged-On User Only Security Objective: If enabled, this policy allows only the interactively logged-on user to access removable floppy media. Computer Setting: Enabled |  | |

| Secure Channel: Digitally Encrypt or Sign Secure Channel Data (Always) Security Objective: If this policy is enabled, all outgoing secure channel traffic must be either signed or encrypted. Computer Setting: Enabled Disabled
(Recommended: By default this option is Disabled. Do not change the default setting.) | |  |

| Secure Channel: Digitally Encrypt or Sign Secure Channel Data (When Possible) Security Objective: If this policy is enabled, all outgoing secure channel traffic should be encrypted. Computer Setting: Enabled Disabled
(Recommended: By default this option is Enabled. Do not change the default setting.) | |  |

| Secure Channel: Digitally Sign Secure Channel Data (When Possible) Security Objective: If this policy is enabled, all outgoing secure channel traffic should be signed. Computer Setting: Enabled Disabled
(Recommended: By default this option is Enabled. Do not change the default setting.) | |  |

| Secure Channel: Require Strong (Windows 2000 or later) Session Key Security Objective: If this policy is enabled, all outgoing secure channel traffic will require a strong (Windows2000 or later) encryption key. Computer Setting: Enabled Disabled
(Recommended: By default this option is Disabled. Generally, do not change the default setting. This policy should only be enabled if "all" DCs in a trusted domain support strong keys.) | |  |

| Secure System Partition (For RISC Platforms Only) Security Objective: If this policy is enabled, only administrative access is allowed to a RISC-based system partition (which must be FAT) while the operating system is running. Computer Setting: Not Defined (This policy does not apply to the Evaluated Configuration.) | |  |

| Send Unencrypted Password to Connect to Third-Party SMB Servers Security Objective: If enabled, the SMB redirector is allowed to send clear-text passwords to non-Microsoft SMB servers, which do not support password encryption during authentication. Computer Setting: Enabled Disabled
(Recommended: By default this option is Disabled. Do not change the default setting.) | |  |

| Shut Down System Immediately if Unable to Log Security Audits Security Objective: Determines whether the system should shut down if it is unable to log security events. Computer Setting: Enabled Disabled
Note: Use this security policy on servers and Domain Controllers only after implementing strict procedures for archiving and clearing the audit logs on a regular basis. (Recommended: Enabled. Requires archiving and clearing the logs on a regular basis.) | |  |

| Smart Card Removal Behavior Security Objective: Determines what should happen when the smart card for a logged-on user is removed from the smart card reader. Computer Setting: ___________________________________ (Recommended: If using smart cards, set to Lock Workstation. However, the integration of smart card technology is not part of the evaluated configuration.) | |  |

| Strengthen Default Permissions for Global System Objects (e.g., Symbolic Links) Security Objective: If this policy is enabled, the default DACL is stronger, allowing non-admin users to read shared objects, but not modify shared objects that they did not create. Computer Setting: Enabled |  | |

| Unsigned Driver Installation Behavior Security Objective: Determines what should happen when an attempt is made to install a device driver that has not been certified by the Windows Hardware Quality Lab. Computer Setting: ___________________________________ (Recommended: Set to Warn but allow installation.) | |  |

| Unsigned Non-Driver Installation Behavior Security Objective: Determines what should happen when an attempt is made to install any nondevice driver software that has not been certified. Computer Setting: ___________________________________ (Recommended: Set to Warn but allow installation.) | |  |