|
142 | 142 | # Ensure \'Deny log on as a batch job\' to include \'Guests\' |
143 | 143 | # tag 'CIS Microsoft Windows Server 2012 R2 Benchmark v2.3.0 - 03-30-2018': '2.2.18' |
144 | 144 | # tag 'CIS Microsoft Windows Server 2016 RTM (Release 1607) Benchmark v1.1.0 - 10-31-2018': '2.2.22' |
145 | | -default['security_policy']['rights']['SeDenyServiceLogonRight'] = '*S-1-5-32-546' |
| 145 | +default['security_policy']['rights']['SeDenyBatchLogonRight'] = '*S-1-5-32-546' |
146 | 146 |
|
147 | 147 | # Ensure \'Deny log on as a service\' to include \'Guests\' |
148 | 148 | # tag 'CIS Microsoft Windows Server 2012 R2 Benchmark v2.3.0 - 03-30-2018': '2.2.19' |
149 | 149 | # tag 'CIS Microsoft Windows Server 2016 RTM (Release 1607) Benchmark v1.1.0 - 10-31-2018': '2.2.23' |
150 | | -default['security_policy']['rights']['SeDenyInteractiveLogonRight'] = '*S-1-5-32-546' |
| 150 | +default['security_policy']['rights']['SeDenyServiceLogonRight'] = '*S-1-5-32-546' |
151 | 151 |
|
152 | 152 | # Ensure \'Deny log on locally\' to include \'Guests\' |
153 | 153 | # tag 'CIS Microsoft Windows Server 2012 R2 Benchmark v2.3.0 - 03-30-2018': '2.2.20' |
154 | 154 | # tag 'CIS Microsoft Windows Server 2016 RTM (Release 1607) Benchmark v1.1.0 - 10-31-2018': '2.2.24' |
155 | | -default['security_policy']['rights']['SeMachineAccountPrivilege'] = '*S-1-5-32-546' |
| 155 | +default['security_policy']['rights']['SeDenyInteractiveLogonRight'] = '*S-1-5-32-546' |
156 | 156 |
|
157 | 157 | # Configure \'Deny log on through Remote Desktop Services\' |
158 | 158 | # tag 'CIS Microsoft Windows Server 2012 R2 Benchmark v2.3.0 - 03-30-2018': '2.2.21' |
159 | 159 | # tag 'CIS Microsoft Windows Server 2016 RTM (Release 1607) Benchmark v1.1.0 - 10-31-2018': ['2.2.25', '2.2.26'] |
160 | | -default['security_policy']['rights']['SeMachineAccountPrivilege'] = '*S-1-5-32-546' |
| 160 | +default['security_policy']['rights']['SeDenyRemoteInteractiveLogonRight'] = '*S-1-5-32-546' |
161 | 161 |
|
162 | 162 | # Configure \'Enable computer and user accounts to be trusted for delegation\' |
163 | 163 | # tag 'CIS Microsoft Windows Server 2012 R2 Benchmark v2.3.0 - 03-30-2018': '2.2.22' |
|
197 | 197 | # Ensure \'Log on as a batch job\' is set to \'Administrators\' (DC only) |
198 | 198 | # tag 'CIS Microsoft Windows Server 2012 R2 Benchmark v2.3.0 - 03-30-2018': '2.2.29' |
199 | 199 | # tag 'CIS Microsoft Windows Server 2016 RTM (Release 1607) Benchmark v1.1.0 - 10-31-2018': '2.2.36' |
200 | | -if ((node['default']['ms_or_dc'] == 'DC') && (node['default']['level_1_or_2'] == 2)) |
201 | | - default['security_policy']['rights']['SeBatchLogonRight'] = '*S-1-5-32-544, *S-1-5-32-551' |
202 | | -end |
| 200 | +default['security_policy']['rights']['SeBatchLogonRight'] = '*S-1-5-32-544, *S-1-5-32-551' if node['windows_hardening']['ms_or_dc'] == 'DC' && node['windows_hardening']['level_1_or_2'] == 2 |
203 | 201 |
|
204 | 202 | # Configure \'Manage auditing and security log\' |
205 | 203 | # tag 'CIS Microsoft Windows Server 2012 R2 Benchmark v2.3.0 - 03-30-2018': '2.2.30' |
|
249 | 247 | # Ensure \'Synchronize directory service data\' is set to \'No One\' (DC only) |
250 | 248 | # tag 'CIS Microsoft Windows Server 2012 R2 Benchmark v2.3.0 - 03-30-2018': '2.2.39' |
251 | 249 | # tag 'CIS Microsoft Windows Server 2016 RTM (Release 1607) Benchmark v1.1.0 - 10-31-2018': '2.2.47' |
252 | | -if node['default']['ms_or_dc'] == 'DC' |
253 | | - default['security_policy']['rights']['SeSyncAgentPrivilege'] = '' |
254 | | -end |
| 250 | + |
| 251 | +default['security_policy']['rights']['SeSyncAgentPrivilege'] = '' if node['windows_hardening']['ms_or_dc'] == 'DC' |
255 | 252 |
|
256 | 253 | # Ensure \'Take ownership of files or other objects\' is set to \'Administrators\' |
257 | 254 | # tag 'CIS Microsoft Windows Server 2012 R2 Benchmark v2.3.0 - 03-30-2018': '2.2.40' |
258 | 255 | # tag 'CIS Microsoft Windows Server 2016 RTM (Release 1607) Benchmark v1.1.0 - 10-31-2018': '2.2.48' |
259 | 256 | default['security_policy']['rights']['SeTakeOwnershipPrivilege'] = '*S-1-5-32-544' |
260 | 257 |
|
261 | | -# |
262 | | - |
263 | | - |
264 | | - |
265 | | -default['security_policy']['rights']['SeMachineAccountPrivilege'] = '*S-1-5-32-544' |
| 258 | +# Ensure \'Network access: Allow anonymous SID/Name translation\' is set to \'Disabled\' |
| 259 | +# tag 'CIS Microsoft Windows Server 2012 R2 Benchmark v2.3.0 - 03-30-2018': '2.3.10.1' |
| 260 | +# tag 'CIS Microsoft Windows Server 2016 RTM (Release 1607) Benchmark v1.1.0 - 10-31-2018': '2.3.10.1' |
| 261 | +default['security_policy']['access']['LSAAnonymousNameLookup'] = 0 |
0 commit comments