Microsoft Windows 10
The Windows Remote Management (WinRM) service must not use Basic authentication
Description
Basic authentication uses plain text passwords that could be used to compromise a system.
Check
If the following registry value does not exist or is not configured as specified, this is a finding:Registry Hive: HKEY_LOCAL_MACHINERegistry Path: \SOFTWARE\Policies\Microsoft\Windows\WinRM\Service\Value Name: AllowBasicValue Type: REG_DWORDValue: 0
Fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Remote Management (WinRM) >> WinRM Service >> "Allow Basic authentication" to "Disabled".Severity Override Guidance: The AO can allow the severity override if they have reviewed the overall protection. This would only be allowed temporarily for implementation as documented and approved. â¦.Allowing Basic authentication to be used for the sole creation of Office 365 DoD tenants.â¦.A documented mechanism and or script that can disable Basic authentication once administration completes. â¦.Use of a Privileged Access Workstation (PAW) and adherence to the Clean Source principle for administration.