Forum Discussion

MEB2004's avatar
MEB2004
Copper Contributor
Aug 23, 2024

Security Baseline 23H2 issue with Hardened UNC Paths

I am testing the 23H2 Security Baseline and ran the CIS Benchmark assessment. A setting that previously passed with the November 2021 baseline is now failing. It is the Hardened UNC Paths under Administrative Templates - Network - Network Provider. The attached screenshot named Hardened UNC Paths...png shows the setting configured in the baseline. The screenshot named Registry.png shows the registry after the baseline is applied.

 

The entry for \\*\SYSVOL does not show up and the entry for \\*\NETLOGON is wrong. When adding the entry to the registry for this setting, Microsoft swapped the Name and Data values.

 

The screenshot Registry from Nov 2021 baseline.png is what it should look like and this passes the CIS Benchmark assessment.

 

Can anyone else confirm this? I plan to open a ticket for this issue.

  • NicklasOlsen's avatar
    NicklasOlsen
    Iron Contributor
    Do you use settings catalog or the administrative template option in Intune?
    • MEB2004's avatar
      MEB2004
      Copper Contributor

      NicklasOlsen I am using the Security Baseline 23H2, not a configuration profile. That is a good idea though. I will change the setting in the Security Baseline to Not Configured and create a configuration profile and see if that works. 

      • NicklasOlsen's avatar
        NicklasOlsen
        Iron Contributor
        Sorry, I misread the original post.
        Try to see if that makes any difference; if it does, it will be very interesting!

Resources