Intune Endpoint Hardening
Ctrlk
  • Intune Endpoint Hardening
    • 2. Local Policies
      • 2.2 User Rights Assignment
      • 2.3 Security Options
        • 2.3.1 Accounts
        • 2.3.2 Audit
        • 2.3.3 DCOM
        • 2.3.4 Devices
        • 2.3.5 Domain controller
        • 2.3.6 Domain member
          • *2.3.6.1 (L1) Ensure 'Domain member: Digitally encrypt or sign secure channel data (always)' is set
          • *2.3.6.2 (L1) Ensure 'Domain member: Digitally encrypt secure channel data (when possible)' is set
          • *2.3.6.3 (L1) Ensure 'Domain member: Digitally sign secure channel data (when possible)' is set to
          • *2.3.6.4 (L1) Ensure 'Domain member: Disable machine account password changes' is set to 'Disabled'
          • *2.3.6.5 (L1) Ensure 'Domain member: Maximum machine account password age' is set to '30 or fewer d
          • *2.3.6.6 (L1) Ensure 'Domain member: Require strong (Windows 2000 or later) session key' is set to
        • 2.3.7 Interactive logon
        • 2.3.8 Microsoft network client
        • 2.3.9 Microsoft network server
    • Account Protection
    • Auditing and Logs
    • Identification and Authentication
    • 17. Advanced Audit Policy Configuration
    • 18. Administrative Templates (Computer)
Powered by GitBook
On this page
  1. Intune Endpoint Hardening
  2. 2. Local Policies
  3. 2.3 Security Options

2.3.6 Domain member

2.3.6 Domain member

*2.3.6.1 (L1) Ensure 'Domain member: Digitally encrypt or sign secure channel data (always)' is set*2.3.6.2 (L1) Ensure 'Domain member: Digitally encrypt secure channel data (when possible)' is set*2.3.6.3 (L1) Ensure 'Domain member: Digitally sign secure channel data (when possible)' is set to*2.3.6.4 (L1) Ensure 'Domain member: Disable machine account password changes' is set to 'Disabled'*2.3.6.5 (L1) Ensure 'Domain member: Maximum machine account password age' is set to '30 or fewer d*2.3.6.6 (L1) Ensure 'Domain member: Require strong (Windows 2000 or later) session key' is set to
Previous2.3.5 Domain controllerNext*2.3.6.1 (L1) Ensure 'Domain member: Digitally encrypt or sign secure channel data (always)' is set

Last updated 2 years ago