Disable Unnecessary System Services for PAWs

Target Scope

  • Applicable Systems: Privileged Access Workstations (PAWs) used for Tier 0 directory administration.
  • Operating Systems: Windows 10 Enterprise (1607+) and Windows 11 Enterprise.

Implementation Details

  • Priority: Medium
  • GPO Path / Registry Location:
    • GPO Path: Computer Configuration\Policies\Windows Settings\Security Settings\System Services
    • Registry Location: HKLM\SYSTEM\CurrentControlSet\Services\<ServiceName>\Start

Rationale

To minimize the attack surface of standard client endpoints and member servers, all unnecessary system services must be disabled. Operating system services that are not required for core administrative tasks or business functionality introduce unnecessary entry points for network exposure, resource utilization, and privilege escalation vulnerabilities.

On Tier 0 administrative workstations (PAWs), enforcing the principle of least functionality is even more critical.


Legacy Impact & Compatibility

  • Infra Compatibility: Administrative functions relying on legacy RPC Locator or SSDP-based discovery of network printers/devices may be affected.
  • WSL Functionality: Disabling LxssManager prevents running Windows Subsystem for Linux (WSL) containers on PAWs. This is the desired security behavior, as PAWs should not host developer Linux kernels or unvetted container instances.
  • Mobile Hotspotting: Disabling icssvc and SharedAccess prevents users from creating cellular hot-spotting configurations or sharing their network cards. This is a desired security behavior.

Service Hardening Requirements

The following services must be stopped and disabled:

  1. REQ-PAW-037 - Disable Computer Browser Service for PAWs (Browser)
  2. REQ-PAW-038 - Disable Infrared Monitor Service for PAWs (irmon)
  3. REQ-PAW-039 - Disable Internet Connection Sharing (ICS) Service for PAWs (SharedAccess)
  4. REQ-PAW-040 - Disable LxssManager Service for PAWs (LxssManager)
  5. REQ-PAW-041 - Disable Microsoft FTP Service for PAWs (FTPSVC)
  6. REQ-PAW-042 - Disable OpenSSH SSH Server Service for PAWs (sshd)
  7. REQ-PAW-043 - Disable Remote Procedure Call (RPC) Locator Service for PAWs (RpcLocator)
  8. REQ-PAW-044 - Disable Routing and Remote Access Service for PAWs (RemoteAccess)
  9. REQ-PAW-045 - Disable Simple TCP/IP Services for PAWs (simptcp)
  10. REQ-PAW-046 - Disable Special Administration Console Helper Service for PAWs (sacsvr)
  11. REQ-PAW-047 - Disable SSDP Discovery Service for PAWs (SSDPSRV)
  12. REQ-PAW-048 - Disable UPnP Device Host Service for PAWs (upnphost)
  13. REQ-PAW-049 - Disable Web Management Service for PAWs (WMSvc)
  14. REQ-PAW-050 - Disable Windows Media Player Network Sharing Service for PAWs (WMPNetworkSvc)
  15. REQ-PAW-051 - Disable Windows Mobile Hotspot Service for PAWs (icssvc)
  16. REQ-PAW-052 - Disable World Wide Web Publishing Service for PAWs (W3SVC)
  17. REQ-PAW-053 - Disable Xbox Accessory Management Service for PAWs (XboxGipSvc)
  18. REQ-PAW-054 - Disable Xbox Live Auth Manager Service for PAWs (XblAuthManager)
  19. REQ-PAW-055 - Disable Xbox Live Game Save Service for PAWs (XblGameSave)
  20. REQ-PAW-056 - Disable Xbox Live Networking Service for PAWs (XboxNetApiSvc)
  21. REQ-PAW-166 - Disable WebClient Service for PAWs (WebClient)

Sources & Compliance References

  • CIS Microsoft Windows Client Benchmark: Section 5.3, 5.8, 5.9, 5.11, 5.12, 5.14, 5.25, 5.27, 5.29, 5.31, 5.32, 5.33, 5.34, 5.37, 5.38, 5.43, 5.44 to 5.47
  • ANSSI Active Directory Hardening Guide: Recommendations on limiting active background services on sensitive systems.
  • DoD Windows 11 Computer STIG v2r6: Services disable requirements

results matching ""

    No results matching ""