| Hostname | IP Address | Status | Assigned To | Last Scan | Actions |
|---|---|---|---|---|---|
| MONT-SW-89108 | 22.19.120.22 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) was unable to determine a Status but found the below configuration on 12/17/2025: ResultHash: 20E099B9F72979B59022E9A2A9ED1BDEE0865FF1 ~~~~~ The following are members of the local Administrators group: ============== Name: MONT-SW-89108\AMPerl.IAAdmin objectClass: User objectSID: S-1-5-21-4163428051-2768110797-3591193048-1018 Name: MONT-SW-89108\dod_admin objectClass: User objectSID: S-1-5-21-4163428051-2768110797-3591193048-1001 Name: MONT-SW-89108\jtbegarek.iaadmin objectClass: User objectSID: S-1-5-21-4163428051-2768110797-3591193048-1024 Name: MONT-SW-89108\Scan.Admin objectClass: User objectSID: S-1-5-21-4163428051-2768110797-3591193048-1016 Name: MONT-SW-89108\tljones.iaadmin objectClass: User objectSID: S-1-5-21-4163428051-2768110797-3591193048-1023 Name: MONT-SW-89108\xAdministrator objectClass: User objectSID: S-1-5-21-4163428051-2768110797-3591193048-500 Comments |
|||||
| MONT-SW-89134 | 22.19.120.21 | 2026-03-04 | |||
Finding DetailsEvaluate-STIG 1.2510.0 (Scan-Windows10_Checks) was unable to determine a Status but found the below configuration on 12/17/2025: ResultHash: 755D0E653E43EF30F999A01A9B8C1F315C41FADD ~~~~~ The following are members of the local Administrators group: ============== Name: MONT-SW-89134\AMPerl.IAAdmin objectClass: User objectSID: S-1-5-21-4004422625-1934610219-1178763574-1021 Name: MONT-SW-89134\dod_admin objectClass: User objectSID: S-1-5-21-4004422625-1934610219-1178763574-1001 Name: MONT-SW-89134\jtbegarek.iaadmin objectClass: User objectSID: S-1-5-21-4004422625-1934610219-1178763574-1026 Name: MONT-SW-89134\scan.admin objectClass: User objectSID: S-1-5-21-4004422625-1934610219-1178763574-1022 Name: MONT-SW-89134\tljones.iaadmin objectClass: User objectSID: S-1-5-21-4004422625-1934610219-1178763574-1024 Name: MONT-SW-89134\xAdministrator objectClass: User objectSID: S-1-5-21-4004422625-1934610219-1178763574-500 Comments |
|||||
| MONT-WS-92010 | 164.231.187.45 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) was unable to determine a Status but found the below configuration on 10/23/2025: ResultHash: 8CF8EB2216BA99A2A79DC17F45300F57F0A47C32 ~~~~~ The following are members of the local Administrators group: ============== Name: MONTFORD-POINT\Workstation Administrator Group objectClass: Group objectSID: S-1-5-21-1360995287-4027491577-3040029667-1110 Name: MONT-WS-92010\dod_admin objectClass: User objectSID: S-1-5-21-2586659569-2484290388-2027984285-1001 Name: MONT-WS-92010\X_Admin objectClass: User objectSID: S-1-5-21-2586659569-2484290388-2027984285-500 Comments |
|||||
| MONT-WS-92040 | 164.231.187.72 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-Windows10_Checks) was unable to determine a Status but found the below configuration on 10/23/2025: ResultHash: 3E830C5BCEA1AA12EC57417D52A215ACB2E2E5E1 ~~~~~ The following are members of the local Administrators group: ============== Name: MONTFORD-POINT\Workstation Administrator Group objectClass: Group objectSID: S-1-5-21-1360995287-4027491577-3040029667-1110 Name: MONT-WS-92040\dod_admin objectClass: User objectSID: S-1-5-21-3703204072-2228436765-3422267048-1001 Name: MONT-WS-92040\X_Admin objectClass: User objectSID: S-1-5-21-3703204072-2228436765-3422267048-500 Comments |
|||||
Check Text
Run "Computer Management". Navigate to System Tools >> Local Users and Groups >> Groups. Review the members of the Administrators group. Only the appropriate administrator groups or accounts responsible for administration of the system may be members of the group. For domain-joined workstations, the Domain Admins group must be replaced by a domain workstation administrator group. Standard user accounts must not be members of the local administrator group. If prohibited accounts are members of the local administrators group, this is a finding. The built-in Administrator account or other required administrative accounts would not be a finding.
Fix Text
Configure the system to include only administrator groups or accounts that are responsible for the system in the local Administrators group. For domain-joined workstations, the Domain Admins group must be replaced by a domain workstation administrator group. Remove any standard user accounts.