Private/SecurityBaseline-Adless.csv.txt

Source: https://aka.ms/SecBaseAdless
DownloadedAtUtc: 2026-09-23T16:40:18.0260598Z
UpstreamSha256: 1B3A6A6FD869656466F2F8C2A4858D40D068984D540A154EB75FB4004B31ED11
Sha256: 48B76F6129AD7A142654E4A98F5DED41DD3E8267ABA71F07EB4860A595E7EDA9
LocalCorrectionDate: 2026-09-29
LocalCorrectionRelease: 0.7.1
UpstreamStatus: Pending upstream; no upstream fix or PR is claimed.
UpstreamFile: https://github.com/Azure-Samples/AzureLocal/blob/main/security/SecurityBaseline_2506Adless.csv
Corrections:
- RemotelyAccessibleRegistryPaths: Registry Key = HKLM:\SYSTEM\CurrentControlSet\Control\SecurePipeServers\WinReg\AllowedExactPaths
- RemotelyAccessibleRegistryPathsAndSubpaths: Registry Key = HKLM:\SYSTEM\CurrentControlSet\Control\SecurePipeServers\WinReg\AllowedPaths
- DeviceGuardRequirePlatformSecurityFeatures: Validation = Get-ItemProperty "HKLM:\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" -Name "RequirePlatformSecurityFeatures"
Scope: Only these three CSV cells differ from the upstream base. Remote registry values remain Machine / REG_MULTI_SZ, and their Validation fields remain blank. IDs, expectations, severity, applicability and row counts are unchanged.
Reference: https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-deviceguard#requireplatformsecurityfeatures
Refresh: Replace with a verified corrected upstream snapshot when available; update both hashes and provenance in the module. No runtime CSV download or registry override is used.