Microsoft Security Baselines Compliance Mapping Matrix
This document maps the focus areas of the Microsoft Security Baselines (Domain Controller, Member Server, and Windows Client baselines) to the technical security controls present in this guidebook.
Mapped Microsoft Security Baseline Focus Areas
| Focus Area | Baseline Requirement Description | Baseline Category | Status | Mapped Technical Control(s) |
|---|---|---|---|---|
| Credential Guard | Deploy Windows Defender Credential Guard to isolate and protect LSASS credentials (disabled on Domain Controllers as per Microsoft recommendations). | Credential Isolation | Covered | REQ-DC-007, REQ-PAW-010, REQ-END-010 |
| LSA Protection | Configure Local Security Authority (LSA) to run as a protected process (LSA Protection). | Credential Isolation | Covered | REQ-DC-006, REQ-PAW-002, REQ-END-023 |
| Protocol Deprecation | Disable legacy protocols (SMBv1, NTLMv1, digest authentication) across servers and endpoints. | Legacy Protocols | Covered | REQ-DC-001, REQ-DC-003, REQ-DC-014, REQ-END-026 |
| AppLocker | Deploy AppLocker application control policies to restrict unauthorized software execution. | Application Control | Covered | REQ-DC-021, REQ-PAW-001, REQ-END-027 |
| Windows Defender Application Control | Deploy Windows Defender Application Control (WDAC) and Driver Blocklists. | Application Control | Covered | REQ-DC-022, REQ-DC-034, REQ-PAW-012, REQ-PAW-036, REQ-END-011, REQ-END-036 |
| BitLocker | Enforce BitLocker drive encryption with TPM and Startup PIN configurations. | Data Protection | Covered | REQ-PAW-004, REQ-END-012 |
| DMA Protection | Enable hardware virtualization-based security and Kernel DMA Protection. | Hardware Integrity | Covered | REQ-PAW-006, REQ-END-014 |
| Secure Boot | Enforce UEFI Secure Boot and hardware platform security settings. | Hardware Integrity | Covered | REQ-PAW-005, REQ-END-009 |
| Audit Policies | Configure advanced security audit policies (DC, member server, and client baselines). | Auditing & Logging | Covered | REQ-LOG-001 |
| PowerShell Logging | Configure PowerShell script block logging and transcription. | Auditing & Logging | Covered | REQ-LOG-002 |
| UAC Policies | Configure User Account Control (UAC) baseline settings. | Account Controls | Covered | REQ-END-002 |
| Removable Storage | Deploy GPOs to block external removable storage devices (USB mass storage). | Data Protection | Covered | REQ-END-004 |
| Point and Print | Configure Point and Print restrictions to prevent PrintNightmare exploits. | Services Hardening | Covered | REQ-END-025, REQ-PAW-015 |
| SYSVOL replication | Migrate SYSVOL replication from FRS to DFS Replication (DFSR). | DC Hardening | Covered | REQ-DC-015 |
| adminSDHolder | Harden adminSDHolder object permissions to prevent privilege persistence. | DC Hardening | Covered | REQ-DC-016, REQ-DC-024 |
| Services minimization | Disable unnecessary system services on Domain Controllers and Endpoints. | Services Hardening | Covered | REQ-DC-012, REQ-END-024 |
| dSHeuristics Hardening | Configure the forest-wide dSHeuristics attribute to block anonymous operations, secure adminSDHolder, and enforce KB5008383 protections. | DC Hardening | Covered | REQ-DC-024 |
Microsoft Baseline Controls Outside Guidebook Scope
The following Microsoft Security Baseline recommendations are not covered by this guidebook as they are more suited for cloud-managed, internet-connected, or hybrid environments:
| Focus Area | Baseline Requirement Description | Category | Status | Notes |
|---|---|---|---|---|
| Microsoft Defender for Endpoint | Cloud-based EDR enrollment and configuration | Endpoint Defense | Not Covered | Out of scope due to the strict air-gapped (offline) requirement of the environment. |
| Windows Update for Business | Cloud-based patch management and updates | Patch Management | Not Covered | Out of scope. Patching must be managed via offline WSUS tiering. |
| Microsoft Defender SmartScreen | Cloud-based reputation screening for downloads | Edge / Web Security | Not Covered | No internet connection is present to contact Microsoft reputation services. |