Skip to main content

Local Security Policies

Win - OIB - SC - Device Security - D - Local Security Policies - v3.0

The Layer 1 default. Hardens UAC behavior, NTLM session security, anonymous SAM access, SMB signing, and related local security options while keeping the built-in Administrator account enabled (the LAPS v3.1 policy rotates its password). Universally compatible across Windows 10 and Windows 11, no 24H2+ dependency. The only difference from the (24H2+) v3.6 variant below is Accounts Enable Administrator Account Status: Enable here, Disable there.

NameValue
Basics
NameWin - OIB - SC - Device Security - D - Local Security Policies - v3.0
DescriptionOIB Layer 1 default. Keeps the built-in Administrator account enabled. Universally compatible (pre-24H2 and 24H2+).
Profile typeSettings catalog
Platform supportedWindows 10 and later
Created09 August 2023 15:01:22
Last modified05 December 2024 19:42:06
Scope tagsDefault
Table 43. Basics - Win - OIB - SC - Device Security - D - Local Security Policies - v3.0
NameValue
Local Policies Security Options
Accounts Enable Administrator Account StatusEnable
Accounts Enable Guest Account StatusDisable
Accounts Limit Local Account Use Of Blank Passwords To Console Logon OnlyEnabled
Interactive Logon Smart Card Removal BehaviorLock Workstation
Microsoft Network Client Digitally Sign Communications AlwaysEnable
Microsoft Network Client Send Unencrypted Password To Third Party SMB ServersDisable
Microsoft Network Server Digitally Sign Communications AlwaysEnable
Network Access Do Not Allow Anonymous Enumeration Of SAM AccountsEnabled
Network Access Do Not Allow Anonymous Enumeration Of Sam Accounts And SharesEnabled
Network Access Restrict Anonymous Access To Named Pipes And SharesEnable
Network Access Restrict Clients Allowed To Make Remote Calls To SAMO:BAG:BAD:(A;;RC;;;BA)
Network Security Do Not Store LAN Manager Hash Value On Next Password ChangeEnable
Network Security LAN Manager Authentication LevelSend NTLMv2 responses only. Refuse LM and NTLM
Network Security Minimum Session Security For NTLMSSP Based ClientsRequire NTLM and 128-bit encryption
Network Security Minimum Session Security For NTLMSSP Based ServersRequire NTLM and 128-bit encryption
User Account Control Behavior Of The Elevation Prompt For AdministratorsPrompt for consent on the secure desktop
User Account Control Behavior Of The Elevation Prompt For Standard UsersPrompt for credentials on the secure desktop
User Account Control Detect Application Installations And Prompt For ElevationEnable
User Account Control Only Elevate UI Access Applications That Are Installed In Secure LocationsEnabled: Application runs with UIAccess integrity only if it resides in secure location.
User Account Control Run All Administrators In Admin Approval ModeEnabled
User Account Control Switch To The Secure Desktop When Prompting For ElevationEnabled
User Account Control Use Admin Approval ModeEnable
User Account Control Virtualize File And Registry Write Failures To Per User LocationsEnabled
Table 44. Settings - Win - OIB - SC - Device Security - D - Local Security Policies - v3.0

The OIB import ships this profile without the two interactive-logon banner settings; Interactive Logon Message Title and Interactive Logon Message Text are added per tenant, the customization called out in the CMMC Control Mapping Matrix. The wording below satisfies 3.1.9's system use notification and is adapted from the standard DoD Notice and Consent Banner, which assessors recognize on sight. Substitute the organization's legal name and abbreviation (and fix the a/an article to match), and have counsel approve before deployment: consent-to-monitoring language has legal effect, and jurisdictions differ.

Message title:

[ORG] Warning and Consent Banner

Message text:

You are accessing a [Organization Name] ([ORG]) Information System (IS) that is provided for [ORG]-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions:

  • [ORG] routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and Security (SI) investigations.
  • At any time, [ORG] may inspect and seize data stored on this IS.
  • Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any [ORG] authorized purpose.
  • This IS includes security measures (e.g., authentication and access controls) to protect [ORG] interests--not for your personal benefit or privacy.
  • Notwithstanding the above, using this IS does not constitute consent to PM, LE or SI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential.

Win - OIB - SC - Device Security - D - Local Security Policies (24H2+) - v3.6

Optional advanced variant: uniform Win11 24H2+ fleets only, paired with (24H2+) LAPS

This is the (24H2+) variant that disables the built-in Administrator account. Must be paired with (24H2+) LAPS, which provisions a custom managed admin account to replace it. Deploying (24H2+) LSP without (24H2+) LAPS leaves devices with no local admin account at all: recovery requires WinRE console or a separate Intune policy to re-enable. See the matched-pair note in Chapter 12 → Layered Deployment Strategy.

NameValue
Basics
NameWin - OIB - SC - Device Security - D - Local Security Policies (24H2+) - v3.6
DescriptionNOTE: For 24H2+ devices only. Disables built-in Administrator account.
Profile typeSettings catalog
Platform supportedWindows 10 and later
Created01 April 2025 15:02:22
Last modified12 May 2025 14:28:34
Scope tagsDefault
Table 43a. Basics - Win - OIB - SC - Device Security - D - Local Security Policies (24H2+) - v3.6
NameValue
Local Policies Security Options
Accounts Enable Administrator Account StatusDisable
Accounts Enable Guest Account StatusDisable
Accounts Limit Local Account Use Of Blank Passwords To Console Logon OnlyEnabled
Interactive Logon Smart Card Removal BehaviorLock Workstation
Microsoft Network Client Digitally Sign Communications AlwaysEnable
Microsoft Network Client Send Unencrypted Password To Third Party SMB ServersDisable
Microsoft Network Server Digitally Sign Communications AlwaysEnable
Network Access Do Not Allow Anonymous Enumeration Of SAM AccountsEnabled
Network Access Do Not Allow Anonymous Enumeration Of Sam Accounts And SharesEnabled
Network Access Restrict Anonymous Access To Named Pipes And SharesEnable
Network Access Restrict Clients Allowed To Make Remote Calls To SAMO:BAG:BAD:(A;;RC;;;BA)
Network Security Do Not Store LAN Manager Hash Value On Next Password ChangeEnable
Network Security LAN Manager Authentication LevelSend NTLMv2 responses only. Refuse LM and NTLM
Network Security Minimum Session Security For NTLMSSP Based ClientsRequire NTLM and 128-bit encryption
Network Security Minimum Session Security For NTLMSSP Based ServersRequire NTLM and 128-bit encryption
User Account Control Behavior Of The Elevation Prompt For AdministratorsPrompt for consent on the secure desktop
User Account Control Behavior Of The Elevation Prompt For Standard UsersPrompt for credentials on the secure desktop
User Account Control Detect Application Installations And Prompt For ElevationEnable
User Account Control Only Elevate UI Access Applications That Are Installed In Secure LocationsEnabled: Application runs with UIAccess integrity only if it resides in secure location.
User Account Control Run All Administrators In Admin Approval ModeEnabled
User Account Control Switch To The Secure Desktop When Prompting For ElevationEnabled
User Account Control Use Admin Approval ModeEnable
User Account Control Virtualize File And Registry Write Failures To Per User LocationsEnabled
Table 44a. Settings - Win - OIB - SC - Device Security - D - Local Security Policies (24H2+) - v3.6

📩 Don't Miss the Next Solution

Join the list to see the real-time solutions I'm delivering to my GCC High clients.