Windows Defender Firewall STIG Compliance Checklist
23 items · Security · Medium difficulty · 2 hours
Apply and verify the Windows Defender Firewall STIG quickly.
-
Download the latest STIG and supporting SCAP/GPO/Intune/SCC resources
Get SCAP 1.2 content, standalone XCCDF, GPO package, Intune policies, and SCC tools.
-
Review the STIG baseline settings and change history
Read baseline controls, exceptions, and recent DISA updates before changes.
-
Import the STIG GPO package into Group Policy Management
Import and verify GPOs match the STIG package before linking.
-
Import the STIG Intune policy into Microsoft Intune (if used)
Import and assign Intune baseline policies where applicable.
-
Apply the Windows Defender Firewall baseline to target systems
Deploy the approved baseline via GPO, Intune, or local configuration.
-
Configure Firewall profiles per STIG
Ensure Domain, Private, and Public profiles follow STIG settings.
-
Set Domain profile to 'On' and apply STIG profile settings
Enable and enforce domain-profile specific rules and logging.
-
Set Private profile to 'On' and apply STIG profile settings
Enable and enforce private-network rules per baseline.
-
Set Public profile to 'On' and apply STIG profile settings
Enable and enforce public-network restrictions per baseline.
-
Set default inbound action to 'Block' and default outbound to 'Allow'
Implement STIG default actions unless exception rules exist.
-
Block unsolicited inbound connections for all profiles
Ensure policy prevents inbound traffic that wasn't requested.
-
Remove or disable unnecessary inbound rules
Minimize attack surface by eliminating unused exceptions.
-
Create explicit allow rules for required services and document justification
Record why each exception exists, owner, and time-limited scope.
-
Enable and configure Windows Defender Firewall logging
Set log path, file size and retention per STIG recommendations.
-
Restrict ICMP responses (ping) according to the STIG
Disable or limit echo replies as specified by the baseline.
-
Enable connection security (IPsec) rules where required
Apply IPsec policies for protected traffic per STIG guidance.
-
Enforce rule ordering and confirm GPO precedence
Validate that higher-precedence policies are applied as intended.
-
Test firewall behavior with controlled port scans and application tests
Verify allowed services work and blocked ports remain closed.
-
Run SCAP/XCCDF benchmark scan to validate compliance
Use the downloaded SCAP/XCCDF content to produce a compliance report.
-
Remediate scan findings and re-run scans until compliant
Triage findings, apply fixes, and re-scan to confirm remediation.
-
Backup applied GPOs and export the current firewall policy
Store backups securely for rollback and audit purposes.
-
Document changes, exceptions, and point of contact
Record rationale, owners, and references to the STIG document.
-
Schedule regular checks for STIG resource updates and reapply as needed
Monitor DISA updates and refresh GPO/Intune/SCC resources regularly.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.