| Hostname | IP Address | Status | Assigned To | Last Scan | Actions |
|---|---|---|---|---|---|
| MONT-SW-89108 | 22.19.120.22 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: F00AB6308F2F40793871577252596AC96D27494C ~~~~~ Confirm-SecureBootUEFI = True Comments |
|||||
| MONT-SW-89134 | 22.19.120.21 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: F00AB6308F2F40793871577252596AC96D27494C ~~~~~ Confirm-SecureBootUEFI = True Comments |
|||||
| MONT-WS-92010 | 164.231.187.45 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: F00AB6308F2F40793871577252596AC96D27494C ~~~~~ Confirm-SecureBootUEFI = True Comments |
|||||
| MONT-WS-92040 | 164.231.187.72 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: F00AB6308F2F40793871577252596AC96D27494C ~~~~~ Confirm-SecureBootUEFI = True Comments |
|||||
Check Text
Some older systems may not have UEFI firmware. This is currently a CAT III; it will be raised in severity at a future date when broad support of Windows 10 hardware and firmware requirements are expected to be met. Devices that have UEFI firmware must have Secure Boot enabled. For virtual desktop implementations (VDIs) where the virtual desktop instance is deleted or refreshed upon logoff, this is NA. Run "System Information". Under "System Summary", if "Secure Boot State" does not display "On", this is finding.
Fix Text
Enable Secure Boot in the system firmware.
| Hostname | IP Address | Status | Assigned To | Last Scan | Actions |
|---|---|---|---|---|---|
| MONT-SW-89108 | 22.19.120.22 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT APPLICABLE on 12/17/2025 ResultHash: 35876C8966B85EC1E2B626A04F1F3A7173B7D72A ~~~~~ System is a 'Standalone Workstation' so this requirement is NA. Comments |
|||||
| MONT-SW-89134 | 22.19.120.21 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT APPLICABLE on 12/17/2025 ResultHash: 35876C8966B85EC1E2B626A04F1F3A7173B7D72A ~~~~~ System is a 'Standalone Workstation' so this requirement is NA. Comments |
|||||
| MONT-WS-92010 | 164.231.187.45 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: 106343AF06C0F1D35AA0C5EC4043166CEEB1AAB2 ~~~~~ Non-Compliant Accounts: ============== All local accounts are Built-in (disabled) or administrators. Compliant Accounts: ============== Name: X_Admin SID: S-1-5-21-2586659569-2484290388-2027984285-500 Enabled: False Type: User IsAdmin: True Name: Visitor SID: S-1-5-21-2586659569-2484290388-2027984285-501 Enabled: False Type: User IsAdmin: False Name: DefaultAccount SID: S-1-5-21-2586659569-2484290388-2027984285-503 Enabled: False Type: User IsAdmin: False Name: WDAGUtilityAccount SID: S-1-5-21-2586659569-2484290388-2027984285-504 Enabled: False Type: User IsAdmin: False Name: defaultuser0 SID: S-1-5-21-2586659569-2484290388-2027984285-1019 Enabled: False Type: User IsAdmin: False Name: dod_admin SID: S-1-5-21-2586659569-2484290388-2027984285-1001 Enabled: True Type: User IsAdmin: True Comments |
|||||
| MONT-WS-92040 | 164.231.187.72 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: BE4A06A27D52056F100522E435DF42CD00EC9F14 ~~~~~ Non-Compliant Accounts: ============== All local accounts are Built-in (disabled) or administrators. Compliant Accounts: ============== Name: X_Admin SID: S-1-5-21-3703204072-2228436765-3422267048-500 Enabled: False Type: User IsAdmin: True Name: Visitor SID: S-1-5-21-3703204072-2228436765-3422267048-501 Enabled: False Type: User IsAdmin: False Name: DefaultAccount SID: S-1-5-21-3703204072-2228436765-3422267048-503 Enabled: False Type: User IsAdmin: False Name: WDAGUtilityAccount SID: S-1-5-21-3703204072-2228436765-3422267048-504 Enabled: False Type: User IsAdmin: False Name: defaultuser0 SID: S-1-5-21-3703204072-2228436765-3422267048-1019 Enabled: False Type: User IsAdmin: False Name: dod_admin SID: S-1-5-21-3703204072-2228436765-3422267048-1001 Enabled: True Type: User IsAdmin: True Comments |
|||||
Check Text
For standalone or nondomain-joined systems, this is Not Applicable. Run "Computer Management". Navigate to System Tools >> Local Users and Groups >> Users. If local users other than the accounts listed below exist on a workstation in a domain, this is a finding. Built-in Administrator account (Disabled) Built-in Guest account (Disabled) Built-in DefaultAccount (Disabled) Built-in defaultuser0 (Disabled) Built-in WDAGUtilityAccount (Disabled) Local administrator account(s) All of the built-in accounts may not exist on a system, depending on the Windows 10 version.
Fix Text
Limit local user accounts on domain-joined systems. Remove any unauthorized local accounts.
| Hostname | IP Address | Status | Assigned To | Last Scan | Actions |
|---|---|---|---|---|---|
| MONT-SW-89108 | 22.19.120.22 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: 0478878E3F4F00BC13BC64CB667E9AFD673A0682 ~~~~~ 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is Disabled Registry Path: HKLM:\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters Value Name: EnableICMPRedirect Value: 0x00000000 (0) Type: REG_DWORD Comments |
|||||
| MONT-SW-89134 | 22.19.120.21 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: 0478878E3F4F00BC13BC64CB667E9AFD673A0682 ~~~~~ 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is Disabled Registry Path: HKLM:\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters Value Name: EnableICMPRedirect Value: 0x00000000 (0) Type: REG_DWORD Comments |
|||||
| MONT-WS-92010 | 164.231.187.45 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: 0478878E3F4F00BC13BC64CB667E9AFD673A0682 ~~~~~ 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is Disabled Registry Path: HKLM:\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters Value Name: EnableICMPRedirect Value: 0x00000000 (0) Type: REG_DWORD Comments |
|||||
| MONT-WS-92040 | 164.231.187.72 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: 0478878E3F4F00BC13BC64CB667E9AFD673A0682 ~~~~~ 'MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes' is Disabled Registry Path: HKLM:\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters Value Name: EnableICMPRedirect Value: 0x00000000 (0) Type: REG_DWORD Comments |
|||||
Check Text
If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ Value Name: EnableICMPRedirect Value Type: REG_DWORD Value: 0
Fix Text
Configure the policy value for Computer Configuration >> Administrative Templates >> MSS (Legacy) >> "MSS: (EnableICMPRedirect) Allow ICMP redirects to override OSPF generated routes" to "Disabled". This policy setting requires the installation of the MSS-Legacy custom templates included with the STIG package. "MSS-Legacy.admx" and " MSS-Legacy.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
| Hostname | IP Address | Status | Assigned To | Last Scan | Actions |
|---|---|---|---|---|---|
| MONT-SW-89108 | 22.19.120.22 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: C8E96AA0CB60DE462BAA29FCA852ED95506E2C53 ~~~~~ 'MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers' is Enabled Registry Path: HKLM:\SYSTEM\CurrentControlSet\Services\Netbt\Parameters Value Name: NoNameReleaseOnDemand Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
| MONT-SW-89134 | 22.19.120.21 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: C8E96AA0CB60DE462BAA29FCA852ED95506E2C53 ~~~~~ 'MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers' is Enabled Registry Path: HKLM:\SYSTEM\CurrentControlSet\Services\Netbt\Parameters Value Name: NoNameReleaseOnDemand Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
| MONT-WS-92010 | 164.231.187.45 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: C8E96AA0CB60DE462BAA29FCA852ED95506E2C53 ~~~~~ 'MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers' is Enabled Registry Path: HKLM:\SYSTEM\CurrentControlSet\Services\Netbt\Parameters Value Name: NoNameReleaseOnDemand Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
| MONT-WS-92040 | 164.231.187.72 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: C8E96AA0CB60DE462BAA29FCA852ED95506E2C53 ~~~~~ 'MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers' is Enabled Registry Path: HKLM:\SYSTEM\CurrentControlSet\Services\Netbt\Parameters Value Name: NoNameReleaseOnDemand Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
Check Text
If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SYSTEM\CurrentControlSet\Services\Netbt\Parameters\ Value Name: NoNameReleaseOnDemand Value Type: REG_DWORD Value: 1
Fix Text
Configure the policy value for Computer Configuration >> Administrative Templates >> MSS (Legacy) >> "MSS: (NoNameReleaseOnDemand) Allow the computer to ignore NetBIOS name release requests except from WINS servers" to "Enabled". This policy setting requires the installation of the MSS-Legacy custom templates included with the STIG package. "MSS-Legacy.admx" and " MSS-Legacy.adml" must be copied to the \Windows\PolicyDefinitions and \Windows\PolicyDefinitions\en-US directories respectively.
| Hostname | IP Address | Status | Assigned To | Last Scan | Actions |
|---|---|---|---|---|---|
| MONT-SW-89108 | 22.19.120.22 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT APPLICABLE on 12/17/2025 ResultHash: B25A1A2ECA2675D310A41F0056F41DBFCEAB243E ~~~~~ Operating system is 'Windows 10 Enterprise LTSC 2021' so this requirement is NA. Comments |
|||||
| MONT-SW-89134 | 22.19.120.21 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT APPLICABLE on 12/17/2025 ResultHash: B25A1A2ECA2675D310A41F0056F41DBFCEAB243E ~~~~~ Operating system is 'Windows 10 Enterprise LTSC 2021' so this requirement is NA. Comments |
|||||
| MONT-WS-92010 | 164.231.187.45 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT APPLICABLE on 10/23/2025 ResultHash: B25A1A2ECA2675D310A41F0056F41DBFCEAB243E ~~~~~ Operating system is 'Windows 10 Enterprise LTSC 2021' so this requirement is NA. Comments |
|||||
| MONT-WS-92040 | 164.231.187.72 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT APPLICABLE on 10/23/2025 ResultHash: B25A1A2ECA2675D310A41F0056F41DBFCEAB243E ~~~~~ Operating system is 'Windows 10 Enterprise LTSC 2021' so this requirement is NA. Comments |
|||||
Check Text
Windows 10 LTSC\B versions do not support the Microsoft Store and modern apps; this is NA for those systems. If the following registry value does not exist or is not configured as specified, this is a finding. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ Value Name: MSAOptional Value Type: REG_DWORD Value: 0x00000001 (1)
Fix Text
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> App Runtime >> "Allow Microsoft accounts to be optional" to "Enabled".
| Hostname | IP Address | Status | Assigned To | Last Scan | Actions |
|---|---|---|---|---|---|
| MONT-SW-89108 | 22.19.120.22 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: 334CD2718F72D0A72C789D4EC35DDD8F555104A5 ~~~~~ 'Turn off Inventory Collector' is Enabled Registry Path: HKLM:\SOFTWARE\Policies\Microsoft\Windows\AppCompat Value Name: DisableInventory Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
| MONT-SW-89134 | 22.19.120.21 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: 334CD2718F72D0A72C789D4EC35DDD8F555104A5 ~~~~~ 'Turn off Inventory Collector' is Enabled Registry Path: HKLM:\SOFTWARE\Policies\Microsoft\Windows\AppCompat Value Name: DisableInventory Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
| MONT-WS-92010 | 164.231.187.45 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: 334CD2718F72D0A72C789D4EC35DDD8F555104A5 ~~~~~ 'Turn off Inventory Collector' is Enabled Registry Path: HKLM:\SOFTWARE\Policies\Microsoft\Windows\AppCompat Value Name: DisableInventory Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
| MONT-WS-92040 | 164.231.187.72 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: 334CD2718F72D0A72C789D4EC35DDD8F555104A5 ~~~~~ 'Turn off Inventory Collector' is Enabled Registry Path: HKLM:\SOFTWARE\Policies\Microsoft\Windows\AppCompat Value Name: DisableInventory Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
Check Text
If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Policies\Microsoft\Windows\AppCompat\ Value Name: DisableInventory Value Type: REG_DWORD Value: 1
Fix Text
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Application Compatibility >> "Turn off Inventory Collector" to "Enabled".
| Hostname | IP Address | Status | Assigned To | Last Scan | Actions |
|---|---|---|---|---|---|
| MONT-SW-89108 | 22.19.120.22 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: DEA095E45CF9BF8C7FF2F5C4225B750C66E2B6B7 ~~~~~ 'Turn off Microsoft consumer experiences' is Enabled Registry Path: HKLM:\SOFTWARE\Policies\Microsoft\Windows\CloudContent Value Name: DisableWindowsConsumerFeatures Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
| MONT-SW-89134 | 22.19.120.21 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: DEA095E45CF9BF8C7FF2F5C4225B750C66E2B6B7 ~~~~~ 'Turn off Microsoft consumer experiences' is Enabled Registry Path: HKLM:\SOFTWARE\Policies\Microsoft\Windows\CloudContent Value Name: DisableWindowsConsumerFeatures Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
| MONT-WS-92010 | 164.231.187.45 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: DEA095E45CF9BF8C7FF2F5C4225B750C66E2B6B7 ~~~~~ 'Turn off Microsoft consumer experiences' is Enabled Registry Path: HKLM:\SOFTWARE\Policies\Microsoft\Windows\CloudContent Value Name: DisableWindowsConsumerFeatures Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
| MONT-WS-92040 | 164.231.187.72 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: DEA095E45CF9BF8C7FF2F5C4225B750C66E2B6B7 ~~~~~ 'Turn off Microsoft consumer experiences' is Enabled Registry Path: HKLM:\SOFTWARE\Policies\Microsoft\Windows\CloudContent Value Name: DisableWindowsConsumerFeatures Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
Check Text
Windows 10 v1507 LTSB version does not include this setting; it is NA for those systems. If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Policies\Microsoft\Windows\CloudContent\ Value Name: DisableWindowsConsumerFeatures Type: REG_DWORD Value: 0x00000001 (1)
Fix Text
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Cloud Content >> "Turn off Microsoft consumer experiences" to "Enabled".
| Hostname | IP Address | Status | Assigned To | Last Scan | Actions |
|---|---|---|---|---|---|
| MONT-SW-89108 | 22.19.120.22 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: 1B980AE1F7833483336844BAEADF9F0CAF0BD5B9 ~~~~~ 'Download Mode' is Enabled: (Any option except 'Internet') Registry Path: HKLM:\SOFTWARE\Policies\Microsoft\Windows\DeliveryOptimization Value Name: DODownloadMode Value: 0x00000002 (2) Type: REG_DWORD Comments |
|||||
| MONT-SW-89134 | 22.19.120.21 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: 1B980AE1F7833483336844BAEADF9F0CAF0BD5B9 ~~~~~ 'Download Mode' is Enabled: (Any option except 'Internet') Registry Path: HKLM:\SOFTWARE\Policies\Microsoft\Windows\DeliveryOptimization Value Name: DODownloadMode Value: 0x00000002 (2) Type: REG_DWORD Comments |
|||||
| MONT-WS-92010 | 164.231.187.45 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: 1B980AE1F7833483336844BAEADF9F0CAF0BD5B9 ~~~~~ 'Download Mode' is Enabled: (Any option except 'Internet') Registry Path: HKLM:\SOFTWARE\Policies\Microsoft\Windows\DeliveryOptimization Value Name: DODownloadMode Value: 0x00000002 (2) Type: REG_DWORD Comments |
|||||
| MONT-WS-92040 | 164.231.187.72 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: 1B980AE1F7833483336844BAEADF9F0CAF0BD5B9 ~~~~~ 'Download Mode' is Enabled: (Any option except 'Internet') Registry Path: HKLM:\SOFTWARE\Policies\Microsoft\Windows\DeliveryOptimization Value Name: DODownloadMode Value: 0x00000002 (2) Type: REG_DWORD Comments |
|||||
Check Text
If the following registry value does not exist or is not configured as specified, this is a finding. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Policies\Microsoft\Windows\DeliveryOptimization\ Value Name: DODownloadMode Value Type: REG_DWORD Value: 0x00000000 (0) - No peering (HTTP Only) 0x00000001 (1) - Peers on same NAT only (LAN) 0x00000002 (2) - Local Network / Private group peering (Group) 0x00000063 (99) - Simple download mode, no peering (Simple) 0x00000064 (100) - Bypass mode, Delivery Optimization not used (Bypass) A value of 0x00000003 (3), Internet, is a finding. v1507 LTSB: Domain joined systems: Verify the registry value above. If the value is not 0x00000000 (0) or 0x00000001 (1), this is a finding. Standalone or nondomain-joined systems (configured in Settings): If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config\ Value Name: DODownloadMode Value Type: REG_DWORD Value: 0x00000000 (0) - Off 0x00000001 (1) - LAN
Fix Text
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Delivery Optimization >> "Download Mode" to "Enabled" with any option except "Internet" selected. Acceptable selections include: Bypass (100) Group (2) HTTP only (0) LAN (1) Simple (99) v1507 (LTSB) does not include this group policy setting locally. For domain-joined systems, configure through domain group policy as "HTTP only (0)" or "Lan (1)". For standalone or nondomain-joined systems, configure using Settings >> Update & Security >> Windows Update >> Advanced Options >> "Choose how updates are delivered" with either "Off" or "PCs on my local network" selected.
| Hostname | IP Address | Status | Assigned To | Last Scan | Actions |
|---|---|---|---|---|---|
| MONT-SW-89108 | 22.19.120.22 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: 6F4214738B47BDD9718A7512C9266DEA4E4E23C6 ~~~~~ 'Turn off heap termination on corruption' is Not Configured in group policy which is acceptable per the STIG. Registry Path: HKLM:\SOFTWARE\Policies\Microsoft\Windows\Explorer Value Name: NoHeapTerminationOnCorruption (Not found) Comments |
|||||
| MONT-SW-89134 | 22.19.120.21 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: 6F4214738B47BDD9718A7512C9266DEA4E4E23C6 ~~~~~ 'Turn off heap termination on corruption' is Not Configured in group policy which is acceptable per the STIG. Registry Path: HKLM:\SOFTWARE\Policies\Microsoft\Windows\Explorer Value Name: NoHeapTerminationOnCorruption (Not found) Comments |
|||||
| MONT-WS-92010 | 164.231.187.45 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: 6F4214738B47BDD9718A7512C9266DEA4E4E23C6 ~~~~~ 'Turn off heap termination on corruption' is Not Configured in group policy which is acceptable per the STIG. Registry Path: HKLM:\SOFTWARE\Policies\Microsoft\Windows\Explorer Value Name: NoHeapTerminationOnCorruption (Not found) Comments |
|||||
| MONT-WS-92040 | 164.231.187.72 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: 6F4214738B47BDD9718A7512C9266DEA4E4E23C6 ~~~~~ 'Turn off heap termination on corruption' is Not Configured in group policy which is acceptable per the STIG. Registry Path: HKLM:\SOFTWARE\Policies\Microsoft\Windows\Explorer Value Name: NoHeapTerminationOnCorruption (Not found) Comments |
|||||
Check Text
The default behavior is for File Explorer heap termination on corruption to be enabled. If the registry Value Name below does not exist, this is not a finding. If it exists and is configured with a value of "0", this is not a finding. If it exists and is configured with a value of "1", this is a finding. Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Policies\Microsoft\Windows\Explorer\ Value Name: NoHeapTerminationOnCorruption Value Type: REG_DWORD Value: 0x00000000 (0) (or if the Value Name does not exist)
Fix Text
The default behavior is for File Explorer heap termination on corruption to be enabled. If this needs to be corrected, configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> File Explorer >> "Turn off heap termination on corruption" to "Not Configured" or "Disabled".
| Hostname | IP Address | Status | Assigned To | Last Scan | Actions |
|---|---|---|---|---|---|
| MONT-SW-89108 | 22.19.120.22 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 Username: MONT-SW-89108\Scan.Admin UserSID: S-1-5-21-4163428051-2768110797-3591193048-1016 ResultHash: 8C1493AE761559D80F64571BC10E6034D9814EFD ~~~~~ 'Do not suggest third-party content in Windows spotlight' is Enabled Registry Path: HKCU:\SOFTWARE\Policies\Microsoft\Windows\CloudContent Value Name: DisableThirdPartySuggestions Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
| MONT-SW-89134 | 22.19.120.21 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 Username: MONT-SW-89134\dod_admin UserSID: S-1-5-21-4004422625-1934610219-1178763574-1001 ResultHash: 8C1493AE761559D80F64571BC10E6034D9814EFD ~~~~~ 'Do not suggest third-party content in Windows spotlight' is Enabled Registry Path: HKCU:\SOFTWARE\Policies\Microsoft\Windows\CloudContent Value Name: DisableThirdPartySuggestions Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
| MONT-WS-92010 | 164.231.187.45 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 Username: MONTFORD-POINT\D.Admin UserSID: S-1-5-21-1360995287-4027491577-3040029667-1104 ResultHash: 8C1493AE761559D80F64571BC10E6034D9814EFD ~~~~~ 'Do not suggest third-party content in Windows spotlight' is Enabled Registry Path: HKCU:\SOFTWARE\Policies\Microsoft\Windows\CloudContent Value Name: DisableThirdPartySuggestions Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
| MONT-WS-92040 | 164.231.187.72 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 Username: MONTFORD-POINT\W.Admin UserSID: S-1-5-21-1360995287-4027491577-3040029667-1106 ResultHash: 8C1493AE761559D80F64571BC10E6034D9814EFD ~~~~~ 'Do not suggest third-party content in Windows spotlight' is Enabled Registry Path: HKCU:\SOFTWARE\Policies\Microsoft\Windows\CloudContent Value Name: DisableThirdPartySuggestions Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
Check Text
If the following registry value does not exist or is not configured as specified, this is a finding. If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_CURRENT_USER Registry Path: \SOFTWARE\Policies\Microsoft\Windows\CloudContent\ Value Name: DisableThirdPartySuggestions Type: REG_DWORD Value: 0x00000001 (1)
Fix Text
Configure the policy value for User Configuration >> Administrative Templates >> Windows Components >> Cloud Content >> "Do not suggest third-party content in Windows spotlight" to "Enabled
| Hostname | IP Address | Status | Assigned To | Last Scan | Actions |
|---|---|---|---|---|---|
| MONT-SW-89108 | 22.19.120.22 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: 8D6ADB1CE377DE42DE0BD6F753A46706DCD5D69D ~~~~~ 'Domain member: Disable machine account password changes' is Disabled Registry Path: HKLM:\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters Value Name: DisablePasswordChange Value: 0x00000000 (0) Type: REG_DWORD Comments |
|||||
| MONT-SW-89134 | 22.19.120.21 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: 8D6ADB1CE377DE42DE0BD6F753A46706DCD5D69D ~~~~~ 'Domain member: Disable machine account password changes' is Disabled Registry Path: HKLM:\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters Value Name: DisablePasswordChange Value: 0x00000000 (0) Type: REG_DWORD Comments |
|||||
| MONT-WS-92010 | 164.231.187.45 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: 8D6ADB1CE377DE42DE0BD6F753A46706DCD5D69D ~~~~~ 'Domain member: Disable machine account password changes' is Disabled Registry Path: HKLM:\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters Value Name: DisablePasswordChange Value: 0x00000000 (0) Type: REG_DWORD Comments |
|||||
| MONT-WS-92040 | 164.231.187.72 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: 8D6ADB1CE377DE42DE0BD6F753A46706DCD5D69D ~~~~~ 'Domain member: Disable machine account password changes' is Disabled Registry Path: HKLM:\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters Value Name: DisablePasswordChange Value: 0x00000000 (0) Type: REG_DWORD Comments |
|||||
Check Text
If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SYSTEM\CurrentControlSet\Services\Netlogon\Parameters\ Value Name: DisablePasswordChange Value Type: REG_DWORD Value: 0
Fix Text
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Domain member: Disable machine account password changes" to "Disabled".
| Hostname | IP Address | Status | Assigned To | Last Scan | Actions |
|---|---|---|---|---|---|
| MONT-SW-89108 | 22.19.120.22 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: FAE72969A576C11785DDAD15FA1C5F2F963658CF ~~~~~ 'Domain member: Maximum machine account password age' is Enabled: (30 or less but not 0) Registry Path: HKLM:\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters Value Name: MaximumPasswordAge Value: 0x0000001e (30) Type: REG_DWORD Comments |
|||||
| MONT-SW-89134 | 22.19.120.21 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: FAE72969A576C11785DDAD15FA1C5F2F963658CF ~~~~~ 'Domain member: Maximum machine account password age' is Enabled: (30 or less but not 0) Registry Path: HKLM:\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters Value Name: MaximumPasswordAge Value: 0x0000001e (30) Type: REG_DWORD Comments |
|||||
| MONT-WS-92010 | 164.231.187.45 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: FAE72969A576C11785DDAD15FA1C5F2F963658CF ~~~~~ 'Domain member: Maximum machine account password age' is Enabled: (30 or less but not 0) Registry Path: HKLM:\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters Value Name: MaximumPasswordAge Value: 0x0000001e (30) Type: REG_DWORD Comments |
|||||
| MONT-WS-92040 | 164.231.187.72 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: FAE72969A576C11785DDAD15FA1C5F2F963658CF ~~~~~ 'Domain member: Maximum machine account password age' is Enabled: (30 or less but not 0) Registry Path: HKLM:\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters Value Name: MaximumPasswordAge Value: 0x0000001e (30) Type: REG_DWORD Comments |
|||||
Check Text
This is the default configuration for this setting (30 days). If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SYSTEM\CurrentControlSet\Services\Netlogon\Parameters\ Value Name: MaximumPasswordAge Value Type: REG_DWORD Value: 0x0000001e (30) (or less, excluding 0)
Fix Text
This is the default configuration for this setting (30 days). Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Domain member: Maximum machine account password age" to "30" or less (excluding 0 which is unacceptable).
| Hostname | IP Address | Status | Assigned To | Last Scan | Actions |
|---|---|---|---|---|---|
| MONT-SW-89108 | 22.19.120.22 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: 94854FF1D86F23AA1E8C8DA8BD0A2FDD0916B300 ~~~~~ 'Interactive logon: Message title for users attempting to log on' is Configured Properly Registry Path: HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System Value Name: LegalNoticeCaption Value: US Department of Defense Warning Statement Type: REG_SZ Comments |
|||||
| MONT-SW-89134 | 22.19.120.21 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: 94854FF1D86F23AA1E8C8DA8BD0A2FDD0916B300 ~~~~~ 'Interactive logon: Message title for users attempting to log on' is Configured Properly Registry Path: HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System Value Name: LegalNoticeCaption Value: US Department of Defense Warning Statement Type: REG_SZ Comments |
|||||
| MONT-WS-92010 | 164.231.187.45 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: 94854FF1D86F23AA1E8C8DA8BD0A2FDD0916B300 ~~~~~ 'Interactive logon: Message title for users attempting to log on' is Configured Properly Registry Path: HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System Value Name: LegalNoticeCaption Value: US Department of Defense Warning Statement Type: REG_SZ Comments |
|||||
| MONT-WS-92040 | 164.231.187.72 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: 94854FF1D86F23AA1E8C8DA8BD0A2FDD0916B300 ~~~~~ 'Interactive logon: Message title for users attempting to log on' is Configured Properly Registry Path: HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System Value Name: LegalNoticeCaption Value: US Department of Defense Warning Statement Type: REG_SZ Comments |
|||||
Check Text
If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ Value Name: LegalNoticeCaption Value Type: REG_SZ Value: See message title above "DoD Notice and Consent Banner", "US Department of Defense Warning Statement" or a site-defined equivalent, this is a finding. If a site-defined title is used, it can in no case contravene or modify the language of the banner text required in WN10-SO-000075.
Fix Text
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Interactive logon: Message title for users attempting to log on" to "DoD Notice and Consent Banner", "US Department of Defense Warning Statement", or a site-defined equivalent. If a site-defined title is used, it can in no case contravene or modify the language of the banner text required in WN10-SO-000075.
| Hostname | IP Address | Status | Assigned To | Last Scan | Actions |
|---|---|---|---|---|---|
| MONT-SW-89108 | 22.19.120.22 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: C727B8F0E8A8C71CA56259690EAC8B0994E0B55A ~~~~~ 'Interactive logon: Number of previous logons to cache (in case domain controller is not available)' is Enabled: (10 or less) Registry Path: HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Value Name: CachedLogonsCount Value: 10 Type: REG_SZ Comments |
|||||
| MONT-SW-89134 | 22.19.120.21 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: C727B8F0E8A8C71CA56259690EAC8B0994E0B55A ~~~~~ 'Interactive logon: Number of previous logons to cache (in case domain controller is not available)' is Enabled: (10 or less) Registry Path: HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Value Name: CachedLogonsCount Value: 10 Type: REG_SZ Comments |
|||||
| MONT-WS-92010 | 164.231.187.45 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: C727B8F0E8A8C71CA56259690EAC8B0994E0B55A ~~~~~ 'Interactive logon: Number of previous logons to cache (in case domain controller is not available)' is Enabled: (10 or less) Registry Path: HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Value Name: CachedLogonsCount Value: 10 Type: REG_SZ Comments |
|||||
| MONT-WS-92040 | 164.231.187.72 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: C727B8F0E8A8C71CA56259690EAC8B0994E0B55A ~~~~~ 'Interactive logon: Number of previous logons to cache (in case domain controller is not available)' is Enabled: (10 or less) Registry Path: HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Value Name: CachedLogonsCount Value: 10 Type: REG_SZ Comments |
|||||
Check Text
This is the default configuration for this setting (10 logons to cache). If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\ Value Name: CachedLogonsCount Value Type: REG_SZ Value: 10 (or less) This setting only applies to domain-joined systems, however, it is configured by default on all systems.
Fix Text
This is the default configuration for this setting (10 logons to cache). Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Interactive logon: Number of previous logons to cache (in case domain controller is not available)" to "10" logons or less. This setting only applies to domain-joined systems, however, it is configured by default on all systems.
| Hostname | IP Address | Status | Assigned To | Last Scan | Actions |
|---|---|---|---|---|---|
| MONT-SW-89108 | 22.19.120.22 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: 0383A2D7E4FA7F9B6839578C9365C007DDDD1BA2 ~~~~~ 'System objects: Strengthen default permissions of internal system objects (e.g. Symbolic links)' is Enabled Registry Path: HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager Value Name: ProtectionMode Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
| MONT-SW-89134 | 22.19.120.21 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 ResultHash: 0383A2D7E4FA7F9B6839578C9365C007DDDD1BA2 ~~~~~ 'System objects: Strengthen default permissions of internal system objects (e.g. Symbolic links)' is Enabled Registry Path: HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager Value Name: ProtectionMode Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
| MONT-WS-92010 | 164.231.187.45 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: 0383A2D7E4FA7F9B6839578C9365C007DDDD1BA2 ~~~~~ 'System objects: Strengthen default permissions of internal system objects (e.g. Symbolic links)' is Enabled Registry Path: HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager Value Name: ProtectionMode Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
| MONT-WS-92040 | 164.231.187.72 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 ResultHash: 0383A2D7E4FA7F9B6839578C9365C007DDDD1BA2 ~~~~~ 'System objects: Strengthen default permissions of internal system objects (e.g. Symbolic links)' is Enabled Registry Path: HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager Value Name: ProtectionMode Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
Check Text
If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \SYSTEM\CurrentControlSet\Control\Session Manager\ Value Name: ProtectionMode Value Type: REG_DWORD Value: 1
Fix Text
Configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "System objects: Strengthen default permissions of internal system objects (e.g. Symbolic links)" to "Enabled".
| Hostname | IP Address | Status | Assigned To | Last Scan | Actions |
|---|---|---|---|---|---|
| MONT-SW-89108 | 22.19.120.22 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 Username: MONT-SW-89108\Scan.Admin UserSID: S-1-5-21-4163428051-2768110797-3591193048-1016 ResultHash: 682F3C26FA3E45B02382214B8E1C03EAF6E80E8C ~~~~~ 'Turn off toast notifications on the lock screen' is Enabled Registry Path: HKCU:\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\PushNotifications Value Name: NoToastApplicationNotificationOnLockScreen Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
| MONT-SW-89134 | 22.19.120.21 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) found this to be NOT A FINDING on 12/17/2025 Username: MONT-SW-89134\dod_admin UserSID: S-1-5-21-4004422625-1934610219-1178763574-1001 ResultHash: 682F3C26FA3E45B02382214B8E1C03EAF6E80E8C ~~~~~ 'Turn off toast notifications on the lock screen' is Enabled Registry Path: HKCU:\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\PushNotifications Value Name: NoToastApplicationNotificationOnLockScreen Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
| MONT-WS-92010 | 164.231.187.45 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 Username: MONTFORD-POINT\D.Admin UserSID: S-1-5-21-1360995287-4027491577-3040029667-1104 ResultHash: 682F3C26FA3E45B02382214B8E1C03EAF6E80E8C ~~~~~ 'Turn off toast notifications on the lock screen' is Enabled Registry Path: HKCU:\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\PushNotifications Value Name: NoToastApplicationNotificationOnLockScreen Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
| MONT-WS-92040 | 164.231.187.72 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) found this to be NOT A FINDING on 10/23/2025 Username: MONTFORD-POINT\W.Admin UserSID: S-1-5-21-1360995287-4027491577-3040029667-1106 ResultHash: 682F3C26FA3E45B02382214B8E1C03EAF6E80E8C ~~~~~ 'Turn off toast notifications on the lock screen' is Enabled Registry Path: HKCU:\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\PushNotifications Value Name: NoToastApplicationNotificationOnLockScreen Value: 0x00000001 (1) Type: REG_DWORD Comments |
|||||
Check Text
If the following registry value does not exist or is not configured as specified, this is a finding: Registry Hive: HKEY_CURRENT_USER Registry Path: \SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\PushNotifications\ Value Name: NoToastApplicationNotificationOnLockScreen Value Type: REG_DWORD Value: 1
Fix Text
Configure the policy value for User Configuration >> Administrative Templates >> Start Menu and Taskbar >> Notifications >> "Turn off toast notifications on the lock screen" to "Enabled".