| Ensure 'Allow log on locally' is set to 'Administrators' |
CIS |
BUILTIN\Users, BUILTIN\Administrators |
After you apply the policy, the Domain only accounts cannot log in to
the machine and perform operations. We recommend you to add
BUILTIN\Users and
BUILTIN\Administrators. You can enable this
policy based on the IT policy and operational requirements.
|
| Ensure 'Deny access to this computer from the network' to include
'Guests, Local account and member of Administrators group' (MS
only)
|
CIS |
Guests |
This policy may have operational impacts specifically for day 0/1
activities. We recommend setting the value to Guests. You can
override this policy based on the IT policy and operational
requirements.
|
| Ensure 'Deny log on through Remote Desktop Services is set to
'Guests, Local account' (MS only)
|
CIS |
Guests |
This policy may have operational impacts specifically for day 0/1
activities. We recommend you setting the value to Guests. You can
override this policy based on the IT policy and operational
requirements.
|
| 'Prevent ignoring certificate errors' to be set as 'Enabled' |
Microsoft |
Disabled |
CCE web applications such as Websetup cannot be accessed using
Internet Explorer. Accessing these web applications with other supported
browsers like Mozilla Firefox and Google Chrome will not be impacted due
to this policy. We recommend setting the value to
Disabled.
|
| 'Turn on Enhanced Protected Mode' to be set as 'Enabled' |
Microsoft |
Disabled |
CCE web applications such as Websetup cannot be accessed using
Internet Explorer. Accessing these web applications with other supported
browsers like Mozilla Firefox and Google Chrome will not be impacted due
to this policy. We recommend setting the value to
Disabled.
|
| Ensure 'Accounts: Administrator account status' is set to 'Disabled'
(MS only)
|
CIS |
Enabled |
This policy has operational impacts. For example, if a member server goes out of domain for any reason, with this policy in
place ,we need to use unrecommended safe mode login to add back the member server to the domain. Other operations will have
similar impact too.
|
|
Ensure 'MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended)' is set to 'Disabled'
|
CIS
|
Enabled
|
Unified ICM and Unified CVP 15.0(1) upgrade via Orchestration requires Automatic Logon to be enabled to control the upgrade
remotely from Cloud Connect. Set this to Enabled only if Orchestration is used for Unified ICM or Unified CVP 15.0(1) upgrade. Post the upgrade, you can set this configuration
to Disabled.
|