Skip to main content

Local Security Policies

Win - OIB - SC - Device Security - D - Local Security Policies - v3.0

CMMC Control Mapping Matrix

The Layer 1 default. Hardens UAC behavior, NTLM session security, anonymous SAM access, SMB signing, and related local security options while keeping the built-in Administrator account enabled (the LAPS v3.1 policy rotates its password). Universally compatible across Windows 10 and Windows 11 — no 24H2+ dependency. The only meaningful difference from the (24H2+) v3.6 variant below is the Accounts Enable Administrator Account Status row, which is Enable here and Disable there.

NameValue
Basics
NameWin - OIB - SC - Device Security - D - Local Security Policies - v3.0
DescriptionOIB Layer 1 default. Keeps the built-in Administrator account enabled. Universally compatible (pre-24H2 and 24H2+).
Profile typeSettings catalog
Platform supportedWindows 10 and later
Created09 August 2023 15:01:22
Last modified05 December 2024 19:42:06
Scope tagsDefault
Table 43. Basics - Win - OIB - SC - Device Security - D - Local Security Policies - v3.0
NameValue
Local Policies Security Options
Accounts Enable Administrator Account StatusEnable
Accounts Enable Guest Account StatusDisable
Accounts Limit Local Account Use Of Blank Passwords To Console Logon OnlyEnabled
Interactive Logon Smart Card Removal BehaviorLock Workstation
Microsoft Network Client Digitally Sign Communications AlwaysEnable
Microsoft Network Client Send Unencrypted Password To Third Party SMB ServersDisable
Microsoft Network Server Digitally Sign Communications AlwaysEnable
Network Access Do Not Allow Anonymous Enumeration Of SAM AccountsEnabled
Network Access Do Not Allow Anonymous Enumeration Of Sam Accounts And SharesEnabled
Network Access Restrict Anonymous Access To Named Pipes And SharesEnable
Network Access Restrict Clients Allowed To Make Remote Calls To SAMO:BAG:BAD:(A;;RC;;;BA)
Network Security Do Not Store LAN Manager Hash Value On Next Password ChangeEnable
Network Security LAN Manager Authentication LevelSend NTLMv2 responses only. Refuse LM and NTLM
Network Security Minimum Session Security For NTLMSSP Based ClientsRequire NTLM and 128-bit encryption
Network Security Minimum Session Security For NTLMSSP Based ServersRequire NTLM and 128-bit encryption
User Account Control Behavior Of The Elevation Prompt For AdministratorsPrompt for consent on the secure desktop
User Account Control Behavior Of The Elevation Prompt For Standard UsersPrompt for credentials on the secure desktop
User Account Control Detect Application Installations And Prompt For ElevationEnable
User Account Control Only Elevate UI Access Applications That Are Installed In Secure LocationsEnabled: Application runs with UIAccess integrity only if it resides in secure location.
User Account Control Run All Administrators In Admin Approval ModeEnabled
User Account Control Switch To The Secure Desktop When Prompting For ElevationEnabled
User Account Control Use Admin Approval ModeEnable
User Account Control Virtualize File And Registry Write Failures To Per User LocationsEnabled
Table 44. Settings - Win - OIB - SC - Device Security - D - Local Security Policies - v3.0

Win - OIB - SC - Device Security - D - Local Security Policies (24H2+) - v3.6

Optional advanced variant — uniform Win11 24H2+ fleets only, paired with (24H2+) LAPS

This is the (24H2+) variant that disables the built-in Administrator account. Must be paired with (24H2+) LAPS, which provisions a custom managed admin account to replace it. Deploying (24H2+) LSP without (24H2+) LAPS leaves devices with no local admin account at all — recovery requires WinRE console or a separate Intune policy to re-enable. See the matched-pair note in Chapter 12 → Layered Deployment Strategy.

NameValue
Basics
NameWin - OIB - SC - Device Security - D - Local Security Policies (24H2+) - v3.6
DescriptionNOTE: For 24H2+ devices only. Disables built-in Administrator account.
Profile typeSettings catalog
Platform supportedWindows 10 and later
Created01 April 2025 15:02:22
Last modified12 May 2025 14:28:34
Scope tagsDefault
Table 43a. Basics - Win - OIB - SC - Device Security - D - Local Security Policies (24H2+) - v3.6
NameValue
Local Policies Security Options
Accounts Enable Administrator Account StatusDisable
Accounts Enable Guest Account StatusDisable
Accounts Limit Local Account Use Of Blank Passwords To Console Logon OnlyEnabled
Interactive Logon Smart Card Removal BehaviorLock Workstation
Microsoft Network Client Digitally Sign Communications AlwaysEnable
Microsoft Network Client Send Unencrypted Password To Third Party SMB ServersDisable
Microsoft Network Server Digitally Sign Communications AlwaysEnable
Network Access Do Not Allow Anonymous Enumeration Of SAM AccountsEnabled
Network Access Do Not Allow Anonymous Enumeration Of Sam Accounts And SharesEnabled
Network Access Restrict Anonymous Access To Named Pipes And SharesEnable
Network Access Restrict Clients Allowed To Make Remote Calls To SAMO:BAG:BAD:(A;;RC;;;BA)
Network Security Do Not Store LAN Manager Hash Value On Next Password ChangeEnable
Network Security LAN Manager Authentication LevelSend NTLMv2 responses only. Refuse LM and NTLM
Network Security Minimum Session Security For NTLMSSP Based ClientsRequire NTLM and 128-bit encryption
Network Security Minimum Session Security For NTLMSSP Based ServersRequire NTLM and 128-bit encryption
User Account Control Behavior Of The Elevation Prompt For AdministratorsPrompt for consent on the secure desktop
User Account Control Behavior Of The Elevation Prompt For Standard UsersPrompt for credentials on the secure desktop
User Account Control Detect Application Installations And Prompt For ElevationEnable
User Account Control Only Elevate UI Access Applications That Are Installed In Secure LocationsEnabled: Application runs with UIAccess integrity only if it resides in secure location.
User Account Control Run All Administrators In Admin Approval ModeEnabled
User Account Control Switch To The Secure Desktop When Prompting For ElevationEnabled
User Account Control Use Admin Approval ModeEnable
User Account Control Virtualize File And Registry Write Failures To Per User LocationsEnabled
Table 44a. Settings - Win - OIB - SC - Device Security - D - Local Security Policies (24H2+) - v3.6

📩 Don't Miss the Next Solution

Join the list to see the real-time solutions I'm delivering to my GCC High clients.