fleet/changes
Josh Brower 6d633427d8
Feature/win11 cis v3 (#18862)
Changelog

ADD:

ADD - 18.10.75.1 (L1) Ensure 'Automatic Data Collection' is set to
'Enabled'
ADD - 18.10.92.2 (L1) Ensure 'Enable features introduced via servicing
that are off by default' is set to 'Disabled'
ADD - 18.10.92.4 (L1) Ensure 'Enable optional updates' is set to
'Disabled'
ADD - 18.8 (L2) Ensure 'Remove Personalized Website Recommendations from
the Recommended section in the Start Menu' is set to 'Enabled'
ADD - 18.9.19 (L1) 'Configure security policy processing: Do not apply
during periodic background processing' is set to 'False'
ADD - 18.9.19 (L1) 'Configure security policy processing: Process even
if the Group Policy objects have not changed' is set to 'True'
ADD - 18.9.25 (L1) Ensure 'Configure password backup directory' is set
to 'Enabled: Active Directory' or 'Enabled: Azure Active Directory'
ADD - 18.9.25 (L1) Ensure 'Enable password encryption' is set to
'Enabled'
ADD - 18.9.25 (L1) Ensure 'Post-authentication actions: Actions' is set
to 'Enabled: Reset the password and logoff the managed account' or
higher
ADD - 18.9.25 (L1) Ensure 'Post-authentication actions: Grace period
(hours)' is set to 'Enabled: 8 or fewer hours, but not 0'
ADD - 19.7.38 (L1) Ensure 'Turn off Windows Copilot' is set to 'Enabled'
ADD - 2.3.11 (L1) Ensure 'Network security: Restrict NTLM: Audit
Incoming NTLM Traffic' is set to 'Enable auditing for all accounts'
ADD - 2.3.11 (L1) Ensure 'Network security: Restrict NTLM: Outgoing NTLM
traffic to remote servers' is set to 'Audit all' or higher

REMOVE:

REMOVE - 18.10.76.3 (L1) Ensure 'Prevent bypassing Windows Defender
SmartScreen prompts for sites' is set to 'Enabled'
REMOVE - 5 (L1) Ensure 'Internet Connection Sharing (ICS)
(SharedAccess)' is set to 'Disabled'
REMOVE - 9.1 (L1) Ensure 'Windows Firewall: Domain: Outbound
connections' is set to 'Allow (default)'
REMOVE - 9.2 (L1) Ensure 'Windows Firewall: Private: Outbound
connections' is set to 'Allow (default)'
REMOVE - 9.3 (L1) Ensure 'Windows Firewall: Public: Outbound
connections' is set to 'Allow (default)'

UPDATE:

UPDATE - 18.10.42.7 (L2 -> L1) Ensure 'Enable file hash computation
feature' is set to 'Enabled'
UPDATE - 18.10.86 (L1 -> L2) Ensure 'Turn on PowerShell Script Block
Logging' is set to 'Enabled'
UPDATE - 18.10.86 (L1 -> L2) Ensure 'Turn on PowerShell Transcription'
is set to 'Enabled'
UPDATE - 18.5 'MSS: (AutoAdminLogon) Enable Automatic Logon (not
recommended)' TO 'MSS: (AutoAdminLogon) Enable Automatic Logon'
UPDATE - 18.5 'MSS: (DisableIPSourceRouting IPv6) IP source routing
protection level (protects against packet spoofing)' TO 'MSS:
(DisableIPSourceRouting IPv6) IP source routing protection level'
UPDATE - 18.5 'MSS: (DisableIPSourceRouting) IP source routing
protection level (protects against packet spoofing)' TO 'MSS:
(DisableIPSourceRouting) IP source routing protection level'
UPDATE - 18.5 'MSS: (PerformRouterDiscovery) Allow IRDP to detect and
configure Default Gateway addresses (could lead to DoS)' TO 'MSS:
(PerformRouterDiscovery) Allow IRDP to detect and configure Default
Gateway addresses'
UPDATE - 18.5 'MSS: (SafeDllSearchMode) Enable Safe DLL search mode
(recommended)' TO 'MSS: (SafeDllSearchMode) Enable Safe DLL search mode'
UPDATE - 18.5 'MSS: (ScreenSaverGracePeriod) The time in seconds before
the screen saver grace period expires (0 recommended)' TO 'MSS:
(ScreenSaverGracePeriod) The time in seconds before the screen saver
grace period expires'
UPDATE - 18.5 'MSS: (KeepAliveTime) How often keep-alive packets are
sent in milliseconds' is set to 'Enabled: 300,000 or 5 minutes
(recommended)' TO 'Enabled: 300,000 or 5 minutes'
UPDATE - 18.9.50.1 (L2 -> L1) Ensure 'Enable Windows NTP Client' is set
to 'Enabled'
UPDATE - 18.9.50.1 (L2 -> L1) Ensure 'Enable Windows NTP Server' is set
to 'Disabled'

---------

Co-authored-by: Sharon Katz <121527325+sharon-fdm@users.noreply.github.com>
Co-authored-by: Sharon Katz <sharon@fleetdm.com>
2024-06-06 12:50:45 -04:00
..
.keep Issue 1009 calculate diff software (#1305) 2021-07-08 13:57:43 -03:00
10383-mdm-saved-certs-ui Update UI for MDM settings to support new macOS workflows (#19297) 2024-05-30 09:10:26 -05:00
11942-duplicated-software Improved software ingestion performance by deduplicating incoming software. (#19325) 2024-05-30 13:14:49 -05:00
14722-activity-feed-webhooks Activity feed webhooks backend (#19261) 2024-05-24 11:25:27 -05:00
16795-update-go update to go1.22.3 + dependencies (#19142) 2024-05-23 16:23:38 -03:00
17309-support-env-vars-profiles Support environment variables in config profiles (#18891) 2024-05-28 13:44:43 -03:00
17513-bulk-host-opts-filters Support status and label filters in bulk opts (#17723) 2024-05-28 08:53:16 -06:00
17587-software-self-service-ui Update UI for software self-service features (#19244) 2024-05-31 11:09:53 +01:00
17860-improve-license-expiration-banner Fleet UI: Updated styles to license expiration banner (#18856) 2024-05-29 09:41:07 -04:00
18053-ubuntu-kernel-vuln-detection Ubuntu Kernel Vulns Part 2: Matching (#19303) 2024-05-29 06:59:12 -06:00
18119-iphone-ipad-support iPhone/iPad support (#19221) 2024-05-28 19:17:14 -03:00
18447-firefox-esr Software Detail Query Overrides (#19132) 2024-05-30 10:10:16 -06:00
18461-windows-lock chore: changes file 2024-05-20 12:09:52 -04:00
18515-remove-host-ids-from-list-labels Exclude host_ids field from label responses when it is empty, which is the case for the list labels endpoint (#19190) 2024-05-23 13:29:46 -07:00
18732-switch-teams-reset-page [released bugs] UI fix: 4 software/policy tables reset to page 0 when switching teams (#19035) 2024-06-03 09:42:34 -04:00
18741-form-field-tooltip-positions UI – Place all TooltipWrapper tooltips on the bottom (#19002) 2024-05-24 14:30:54 -07:00
18833-filter-software-by-self-service Software SS: add self-service filter to list software titles and list host's/device's software (#19186) 2024-05-27 10:53:41 -04:00
18834-add-self-service-install-endpoint Self service install endpoint (#19294) 2024-05-29 11:01:48 -04:00
18834-fleetctl-add-self-service-field Software SS: add CLI support for self_service (#19205) 2024-05-27 10:31:16 -04:00
18838-additional-db-optimizations Move CalculateAggregatedPerfStatsPercentiles reads to the replica (#19206) 2024-05-31 07:08:31 -05:00
18847-software-self-install-activities Software SS: activities (#19292) 2024-05-28 10:44:06 -04:00
18862-upgradeCIS-win11 Feature/win11 cis v3 (#18862) 2024-06-06 12:50:45 -04:00
18881-queries-table-filter-bugs UI – Queries table: Fix issues with filter/sorting, optimize render behavior (#18973) 2024-05-23 13:30:24 -07:00
18912-controls-language-and-cta-button-fix Fleet UI: Fix language and CTA button for controls page for non global admins (#19367) 2024-05-31 09:20:30 -04:00
19001-builtin-label-names-selecting-targets Fleet UI: Fix built in label names for select targets page (#19362) 2024-05-31 09:28:33 -04:00
19014-certs-endpoints chore: changes file 2024-05-23 18:32:42 -04:00
19052-activity-feed-webhooks UI – Activity feed webhook automation modal (#19285) 2024-05-28 13:18:02 -07:00
19072-additional-stats additional stats (#19078) 2024-05-24 15:06:10 -04:00
19152-gitops-duplicate-enroll-secret fleetctl gitops --dry-run now errors on duplicate (or conflicting) global/team enroll secrets. (#19344) 2024-05-31 07:01:13 -05:00
19171-host-query-bug-fixes [small released bugs] Fleet UI: Host queries styling fixes (#19175) 2024-05-29 12:48:51 -04:00
19179-bm add logic to manage ABM assets (#19293) 2024-05-28 12:10:32 -03:00
19267-bugfix-ui-wipe-menu Hide wipe action from observers in UI (#19381) 2024-05-31 09:56:58 -05:00
19272-live-query-lag Live queries work with replication lag. (#19368) 2024-06-03 08:22:45 -05:00
19311-scep-renew prevent a bug causing SCEP renewals to fail (#19313) 2024-05-28 20:31:53 -03:00
19464-private-key-errors chore: changes file 2024-06-03 17:25:39 -04:00
add-tuxedo-os add linux platform tuxedo (#19011) 2024-05-29 13:54:07 -03:00
issue-18847-add-ui-activities-for-self-service Add UI for self service activities (#19305) 2024-05-29 11:50:39 +01:00
jve-fix-lock-script-typo chore: changes file 2024-05-28 17:49:19 -04:00
jve-pk-docs chore: changes file 2024-05-29 10:41:29 -04:00
post-apns-cert feat: upload and delete APNS certs (#19275) 2024-05-27 11:13:08 -03:00
save-certs-encrypted chore: changes file 2024-05-28 11:58:04 -04:00