Windows 10 STIG Checklist
19 items · Security · Hard difficulty · 3 hours
Implement the Windows 10 STIG and bring endpoints into DoD-aligned compliance.
-
Download the Microsoft Windows 10 STIG and associated resources
Get SCAP 1.3 content, GPO packages, Intune policies, and SCC automated content.
-
Review the STIG version, release notes, and change history
Confirm Version 3, Release 7 and recent updates or resource sunsets.
-
Identify target systems and confirm Windows 10 edition
Document which endpoints are Enterprise vs Professional and domain-joined.
-
Backup system images and critical data before changes
Create restore points or full image backups to prevent data loss.
-
Import GPOs into Active Directory
Load the provided GPO package and link to appropriate OUs.
-
Import and assign Intune policies to enrolled devices
Use the provided Intune policy package for mobile/modern-managed endpoints.
-
Load and run SCC automated content to baseline systems
Use SCC content to automate baseline checks where available.
-
Scan endpoints with the SCAP 1.3 benchmark for STIG compliance
Run SCAP benchmark scans to produce detailed compliance findings.
-
Review scan results and prioritize remediation tasks
Categorize findings by severity and impact before fixing.
-
Remediate high-severity findings (patches, configs, disable services)
Apply fixes for critical items first, then move to lower severities.
-
Verify account and password policy settings
Confirm domain/local account settings match STIG requirements.
-
Enforce password complexity and history
Enable complexity requirements and configure password history.
-
Set minimum password length and account lockout thresholds
Configure minimum length, lockout count, and duration per STIG.
-
Disable or secure Guest and local administrator accounts
Remove roaming Guest usage and secure built-in admin accounts.
-
Disable legacy and insecure services (SMBv1, TELNET, etc.)
Turn off deprecated protocols and services referenced by the STIG.
-
Enable and configure Windows Firewall and Defender settings
Ensure profiles, rules, and real-time protection are properly set.
-
Apply OS updates and cumulative security patches
Install required updates and reboot systems as needed.
-
Document remediation actions, baselines, and approved exceptions
Keep records of changes, justifications, and exception approvals.
-
Schedule regular reassessments and update STIG resources
Plan periodic scans and refresh GPO, Intune, and SCC packages.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.