Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Struggling with two settings that i can't get the audit to accept as set. 
Has anyone got these working? 
 
Many thanks



18.11.1 Ensure 'Disable HTTP proxy features: Disable WPAD' is set to 'Enabled: Checked'

Description:

This policy setting determines whether Web Proxy Auto-Discovery protocol (WPAD) is disabled on the system. WPAD is used to discover Proxy Auto-Config (PAC) files from the local network.

The recommended state for this setting is: Enabled: Checked .

Note: When this recommendation is set as prescribed, applications can still resolve the name WPAD by calling Domain Name System (DNS) directly.

WPAD could expose the system to Man-In-The-Middle (MITM) attacks. If an organization depends on HTTP proxy configuration, it is recommended that other client configuration mechanisms be used instead, such as Group Policy.
 

18.11.2 Ensure 'Disable HTTP proxy features: Disable proxy authentication' is set to 'Enabled: Disable authentication over loopback interfaces' or higher

Description:

This policy setting determines whether Windows can authenticate over a loopback interface.

The recommended state for this setting is: Enabled: Disable authentication over loopback interfaces . Configuring this setting to Disable all authentication protocols and loopback authentication also conforms to the benchmark.

It is best to limit the sign-in interface to only known and trusted services, so malicious actors can't impersonate them.

 

To establish the recommended configuration via GP, set the following UI path to Enabled: Disable authentication over loopback interfaces or Disable all authentication protocols and loopback authentication :

Posted

Not many people using CIS on here!

 

What is the issue? The settings are configured in the GPO template but the CIS validation / audit tool doesn't agree?

Posted

I'm using CIS CAT Lite and its audit tool doesn't agree that the settings are set.

 

Are you using CIS ?

Many thanks

Posted

We are using CIS Level 2 - GPO for Servers, Intune for most endpoints. We do have an offline environment that has hardened Windows 11 clients. I can confirm if complaint and report back.

  • 2 weeks later...
Posted
On 28/04/2026 at 12:30, FN-GM said:

We are using CIS Level 2 - GPO for Servers, Intune for most endpoints. We do have an offline environment that has hardened Windows 11 clients. I can confirm if complaint and report back.

Did you ever have time to check? 

 

Thanks

Posted
On 06/05/2026 at 23:44, tri_94 said:

Did you ever have time to check? 

 

Thanks

 

Sorry mate, I haven't had chance. We had a major accident at work and it's been a bit all over the place since. I am back in the office next week and will try to remember.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...