Private/SecurityBaseline-DomainJoined.csv.txt

Source: https://aka.ms/SecBaseDomJoin
DownloadedAtUtc: 2026-09-23T16:40:18.4268184Z
UpstreamSha256: 3BF4A3615B6E1FFE0EDD56F0540B8F4C71A553E258A67844DA0C9D1B5BBBF3BD
Sha256: D044FD88EB0A068FFB0E0E63A6C02267C9C839D2D4F4873B14298DF07A357F59
LocalCorrectionDate: 2026-09-29
LocalCorrectionRelease: 0.7.1
UpstreamStatus: Pending upstream; no upstream fix or PR is claimed.
UpstreamFile: https://github.com/Azure-Samples/AzureLocal/blob/main/security/SecurityBaseline_2506domjoin.csv
Corrections:
- RemotelyAccessibleRegistryPaths: Registry Key = HKLM:\SYSTEM\CurrentControlSet\Control\SecurePipeServers\WinReg\AllowedExactPaths
- RemotelyAccessibleRegistryPathsAndSubpaths: Registry Key = HKLM:\SYSTEM\CurrentControlSet\Control\SecurePipeServers\WinReg\AllowedPaths
- DeviceGuardRequirePlatformSecurityFeatures: Validation = Get-ItemProperty "HKLM:\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" -Name "RequirePlatformSecurityFeatures"
Scope: Only these three CSV cells differ from the upstream base. Remote registry values remain Machine / REG_MULTI_SZ, and their Validation fields remain blank. IDs, expectations, severity, applicability and row counts are unchanged.
Reference: https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-deviceguard#requireplatformsecurityfeatures
Refresh: Replace with a verified corrected upstream snapshot when available; update both hashes and provenance in the module. No runtime CSV download or registry override is used.