Microsoft Security Baselines Compliance Mapping Matrix

This document maps the focus areas of the Microsoft Security Baselines (Domain Controller, Member Server, and Windows Client baselines) to the technical security controls present in this guidebook.

Mapped Microsoft Security Baseline Focus Areas

Focus Area Baseline Requirement Description Baseline Category Status Mapped Technical Control(s)
Credential Guard Deploy Windows Defender Credential Guard to isolate and protect LSASS credentials (disabled on Domain Controllers as per Microsoft recommendations). Credential Isolation Covered REQ-DC-007, REQ-PAW-010, REQ-END-010
LSA Protection Configure Local Security Authority (LSA) to run as a protected process (LSA Protection). Credential Isolation Covered REQ-DC-006, REQ-PAW-002, REQ-END-023
Protocol Deprecation Disable legacy protocols (SMBv1, NTLMv1, digest authentication) across servers and endpoints. Legacy Protocols Covered REQ-DC-001, REQ-DC-003, REQ-DC-014, REQ-END-026
AppLocker Deploy AppLocker application control policies to restrict unauthorized software execution. Application Control Covered REQ-DC-021, REQ-PAW-001, REQ-END-027
Windows Defender Application Control Deploy Windows Defender Application Control (WDAC) and Driver Blocklists. Application Control Covered REQ-DC-022, REQ-DC-034, REQ-PAW-012, REQ-PAW-036, REQ-END-011, REQ-END-036
BitLocker Enforce BitLocker drive encryption with TPM and Startup PIN configurations. Data Protection Covered REQ-PAW-004, REQ-END-012
DMA Protection Enable hardware virtualization-based security and Kernel DMA Protection. Hardware Integrity Covered REQ-PAW-006, REQ-END-014
Secure Boot Enforce UEFI Secure Boot and hardware platform security settings. Hardware Integrity Covered REQ-PAW-005, REQ-END-009
Audit Policies Configure advanced security audit policies (DC, member server, and client baselines). Auditing & Logging Covered REQ-LOG-001
PowerShell Logging Configure PowerShell script block logging and transcription. Auditing & Logging Covered REQ-LOG-002
UAC Policies Configure User Account Control (UAC) baseline settings. Account Controls Covered REQ-END-002
Removable Storage Deploy GPOs to block external removable storage devices (USB mass storage). Data Protection Covered REQ-END-004
Point and Print Configure Point and Print restrictions to prevent PrintNightmare exploits. Services Hardening Covered REQ-END-025, REQ-PAW-015
SYSVOL replication Migrate SYSVOL replication from FRS to DFS Replication (DFSR). DC Hardening Covered REQ-DC-015
adminSDHolder Harden adminSDHolder object permissions to prevent privilege persistence. DC Hardening Covered REQ-DC-016, REQ-DC-024
Services minimization Disable unnecessary system services on Domain Controllers and Endpoints. Services Hardening Covered REQ-DC-012, REQ-END-024
dSHeuristics Hardening Configure the forest-wide dSHeuristics attribute to block anonymous operations, secure adminSDHolder, and enforce KB5008383 protections. DC Hardening Covered REQ-DC-024

Microsoft Baseline Controls Outside Guidebook Scope

The following Microsoft Security Baseline recommendations are not covered by this guidebook as they are more suited for cloud-managed, internet-connected, or hybrid environments:

Focus Area Baseline Requirement Description Category Status Notes
Microsoft Defender for Endpoint Cloud-based EDR enrollment and configuration Endpoint Defense Not Covered Out of scope due to the strict air-gapped (offline) requirement of the environment.
Windows Update for Business Cloud-based patch management and updates Patch Management Not Covered Out of scope. Patching must be managed via offline WSUS tiering.
Microsoft Defender SmartScreen Cloud-based reputation screening for downloads Edge / Web Security Not Covered No internet connection is present to contact Microsoft reputation services.

results matching ""

    No results matching ""