Microsoft Windows 11 STIG Compliance Checklist
18 items · Security · Hard difficulty · 4 hours
Essential steps to implement and validate Windows 11 STIG compliance.
-
Gather STIG resources from DISA
Collect official resources, downloads, and guidance before changes.
-
Download SCAP 1.3 content
Get SCAP 1.3 Benchmark (Microsoft Windows 11 STIG Ver 2, Rel 7).
-
Download standalone XCCDF files
Fetch XCCDF for Chef and standalone XCCDF versions for automation.
-
Download Intune policies
Obtain the Intune Policy package (latest update included).
-
Download Group Policy Objects (GPOs)
Grab provided GPOs (January 2026 or latest) for domain systems.
-
Download SCC automated content
Download SCC/SCCM automated content (e.g., SCC 5.14 Windows).
-
Review STIG and SRG to map controls to systems
Identify which requirements apply to Enterprise vs Professional.
-
Inventory target systems and editions
Document domain-joined vs standalone, OS editions, and hardware (TPM).
-
Apply baseline Group Policy and Intune policies
Deploy and test GPOs/Intune policies in a lab before production.
-
Configure secure boot, TPM, and enable BitLocker
Ensure device firmware settings and disk encryption are enabled.
-
Enforce Windows Update and patch management
Apply latest patches and configure automatic update policies.
-
Disable SMBv1 and remove unnecessary services/features
Harden systems by removing legacy protocols and unused roles.
-
Enforce strong authentication and MFA
Require multi-factor authentication and tighten credential policies.
-
Configure auditing, event log retention, and log forwarding
Set log retention and forward critical events to a centralized SIEM.
-
Test STIG compliance with SCAP/XCCDF and automated scans
Run scans, compare results to the STIG benchmark, and export reports.
-
Remediate findings and document approved exceptions
Fix issues, track mitigations, and record any formal exceptions.
-
Maintain and track DISA updates, resource SHAs, and version changes
Monitor DISA change history and update resources when published.
-
Submit feedback or change requests to DISA if needed
Send comments or proposed revisions to the DISA contact email.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.