CIS Microsoft Windows 10 Enterprise Release 1909 Benchmark
18.9.98Windows Remote Shell
This section contains settings related to Windows Remote Shell (WinRS).
This Group Policy section is provided by the Group Policy template WindowsRemoteShell.admx/adml that is included with all versions of the Microsoft Windows Administrative Templates. 18.9.98.1 (L2) Ensure 'Allow Remote Shell Access' is set to 'Disabled' (Scored)
ProfileApplicability:
Level 2 (L2) - High Security/Sensitive Data Environment (limited functionality)
Description:
This policy setting allows you to manage configuration of remote access to all supported shells to execute scripts and commands.
The recommended state for this setting is: Disabled .
Note: The GPME help text for this setting is incorrectly worded, implying that configuring it to Enabled will reject new Remote Shell connections, and setting it to Disabled will allow Remote Shell connections. The opposite is true (and is consistent with the title of the setting). This is a wording mistake by Microsoft in the Administrative Template.
Rationale:
Any feature is a potential avenue of attack, those that enable inbound network connections are particularly risky. Only enable the use of the Windows Remote Shell on trusted networks and when feasible employ additional controls such as IPsec.
Audit:
Navigate to the UI Path articulated in the Remediation section and confirm it is set as prescribed. This group policy object is backed by the following registry location:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WinRM\Service\WinRS:Al lowRemoteShellAccess
1167 | P a g e
Made with FlippingBook - Online magazine maker