Tests/sample.json

{
"kind": "SecurityWindowsBaselineConfiguration",
"properties": {
"RulesetsCollection": {
  "BaselineRuleset": [
     {
      "Rules": {
        "BaselineRegistryRule": [
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Control\\Lsa",
        "ValueName": "LmCompatibilityLevel",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "d82136e2-16cc-4fb8-b6ca-559b11c08029",
        "OriginalId": "ec468e43-6141-4bfe-970f-ca02d37d0ca7",
        "CceId": "CCE-36173-3",
        "Name": "Network security: LAN Manager authentication level",
        "Type": "Registry",
        "ExpectedValue": "555",
        "Severity": "Critical",
        "AnalyzeOperation": "Equals",
        "Enabled": false
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Control\\Lsa\\MSV1_0",
        "ValueName": "allownullsessionfallback",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "97ca378a-4ba3-4e4a-9dd7-fa3777102a1a",
        "OriginalId": "763c80f9-f87a-4246-ab22-d0817891d5d3",
        "CceId": "CCE-37035-3",
        "Name": "Network security: Allow LocalSystem NULL session fallback",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": false
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Services\\LanmanWorkstation\\Parameters",
        "ValueName": "EnablePlainTextPassword",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "95ba349a-7f09-4f12-8b9b-1f92d85594ff",
        "OriginalId": "b1b4a762-3114-438b-92cf-90f021714790",
        "CceId": "CCE-37863-8",
        "Name": "Microsoft network client: Send unencrypted password to third-party SMB servers",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Critical",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Control\\Lsa",
        "ValueName": "UseMachineId",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "d54aab9e-4ccb-41d2-a9c7-5cbb97dbf327",
        "OriginalId": "f4a2c795-7dc3-4deb-b76f-ef54c49da0d9",
        "CceId": "CCE-38341-4",
        "Name": "Network security: Allow Local System to use computer identity for NTLM",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Control\\Lsa",
        "ValueName": "NoLMHash",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "c09401f6-00f2-488d-ab5b-936c1b19206a",
        "OriginalId": "794f9728-56e1-4e5e-b697-7079757f4ac3",
        "CceId": "CCE-36326-7",
        "Name": "Network security: Do not store LAN Manager hash value on next password change",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Critical",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Control\\Lsa\\MSV1_0",
        "ValueName": "NTLMMinServerSec",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "3eb53013-936e-405d-9a95-401dd026ab0b",
        "OriginalId": "17463ab9-ffc1-40ab-8b09-e8054ba4504c",
        "CceId": "CCE-37835-6",
        "Name": "Network security: Minimum session security for NTLM SSP based (including secure RPC) servers",
        "Type": "Registry",
        "ExpectedValue": "537395200",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "String",
        "KeyPath": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon",
        "ValueName": "scremoveoption",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "b2a792ce-f9c2-43b4-a244-952fb4674b9f",
        "OriginalId": "402dc351-392a-4816-a26a-65a7bcc94087",
        "CceId": "CCE-38333-1",
        "Name": "Interactive logon: Smart card removal behavior",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Control\\Lsa\\MSV1_0",
        "ValueName": "NTLMMinClientSec",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "ed1c0841-b58b-4179-8573-e5748aae66fa",
        "OriginalId": "9969a7db-5fd1-4713-9a26-9862c15359e9",
        "CceId": "CCE-37553-5",
        "Name": "Network security: Minimum session security for NTLM SSP based (including secure RPC) clients",
        "Type": "Registry",
        "ExpectedValue": "537395200",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "String",
        "KeyPath": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon",
        "ValueName": "cachedlogonscount",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "e214578e-2387-4899-894f-2ffc99b86cc3",
        "OriginalId": "adfc53c0-573a-4b06-8a91-4dc91e830362",
        "CceId": "CCE-37439-7",
        "Name": "Interactive logon: Number of previous logons to cache (in case domain controller is not available)",
        "Type": "Registry",
        "ExpectedValue": "4",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Control\\Lsa",
        "ValueName": "EveryoneIncludesAnonymous",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "da87147e-54c1-4fa4-8a88-8e48fbaf4e47",
        "OriginalId": "e197f79b-a454-407c-9307-7b3210313e61",
        "CceId": "CCE-36148-5",
        "Name": "Network access: Let Everyone permissions apply to anonymous users",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Critical",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Control\\Lsa",
        "ValueName": "RestrictAnonymous",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "63006b09-c981-434c-b77d-07191efe3c87",
        "OriginalId": "fbfb6cc4-d294-4884-bc3d-7f74deeb6462",
        "CceId": "CCE-36077-6",
        "Name": "Network access: Do not allow anonymous enumeration of SAM accounts and shares",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Critical",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Control\\Lsa",
        "ValueName": "RestrictAnonymousSAM",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "5983527c-f84a-4a69-bdaf-21cdceff37d9",
        "OriginalId": "c4f13e60-0fae-4766-bba1-00b4c33d54b7",
        "CceId": "CCE-36316-8",
        "Name": "Network access: Do not allow anonymous enumeration of SAM accounts",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Critical",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Control\\Session Manager\\Memory Management",
        "ValueName": "ClearPageFileAtShutdown",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "cd8e0aad-d3c3-4c71-a1aa-5726f6307b8e",
        "OriginalId": "c8c43367-6343-4ae7-9387-c4f24303b90d",
        "CceId": "CCE-38335-6",
        "Name": "Shutdown: Clear virtual memory pagefile",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
        "ValueName": "ShutdownWithoutLogon",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "8a92a3c6-30e1-46c3-9af0-d359f2d9811c",
        "OriginalId": "3849d4a1-188c-43d8-ad75-c73a82a8e0fe",
        "CceId": "CCE-36788-8",
        "Name": "Shutdown: Allow system to be shut down without having to log on",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Control\\Session Manager\\Kernel",
        "ValueName": "ObCaseInsensitive",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "a6b659e0-a942-408b-b72e-34900002ae49",
        "OriginalId": "7ab41c58-8c4a-4781-9cdd-a6dc5c40fc66",
        "CceId": "CCE-37885-1",
        "Name": "System objects: Require case insensitivity for non-Windows subsystems",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Control\\Lsa",
        "ValueName": "ForceGuest",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "d168a0da-385c-42ef-841a-4b2bdb347746",
        "OriginalId": "7c6c01fd-5c0d-4398-9de0-0a8855c4cd95",
        "CceId": "CCE-37623-6",
        "Name": "Network access: Sharing and security model for local accounts",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
        "ValueName": "DisableCAD",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "8d93d233-07e3-4ab5-881f-388844069274",
        "OriginalId": "8ae83b84-b0fd-4b08-85a5-ff3f897a2db2",
        "CceId": "CCE-37637-6",
        "Name": "Interactive logon: Do not require CTRL+ALT+DEL",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "String",
        "KeyPath": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon",
        "ValueName": "AllocateDASD",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "924f5851-efcf-4fe2-8fb3-1bfd8153516f",
        "OriginalId": "71d6ee80-22f8-44e3-99ad-cbc707218ff8",
        "CceId": "CCE-37701-0",
        "Name": "Devices: Allowed to format and eject removable media",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Policies\\Microsoft\\Windows\\Safer\\CodeIdentifiers",
        "ValueName": "AuthenticodeEnabled",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "9be3e136-3b43-4a91-8277-c854efb80327",
        "OriginalId": "6e47e304-7197-4791-b16d-9a6ad3306ad4",
        "CceId": "CCE-37172-4",
        "Name": "System settings: Use Certificate Rules on Windows Executables for Software Restriction Policies",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "String",
        "KeyPath": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon",
        "ValueName": "AutoAdminLogon",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "1728e7f5-addc-41e2-9455-ae4d0a39d5f8",
        "OriginalId": "b1d27dc2-b5e3-4dc5-9d3b-d634e7a25353",
        "CceId": "CCE-37067-6",
        "Name": "MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended)",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "SYSTEM\\CurrentControlSet\\Control\\Session Manager",
        "ValueName": "SafeDllSearchMode",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "17e433c2-be93-477c-90d3-ebfc256dcaa8",
        "OriginalId": "c836e4ce-c2f0-410c-bbf2-2550e8d24ba8",
        "CceId": "CCE-36351-5",
        "Name": "MSS: (SafeDllSearchMode) Enable Safe DLL search mode (recommended)",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Setup\\RecoveryConsole",
        "ValueName": "securitylevel",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "1e913999-77c9-4cc0-960e-c7ce9d7507cd",
        "OriginalId": "1b4d4248-73f1-4950-be5c-8c2fd6d47002",
        "CceId": "CCE-37624-4",
        "Name": "Recovery console: Allow automatic administrative logon",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Services\\LanManServer\\Parameters",
        "ValueName": "restrictnullsessaccess",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "72dd6b79-12f7-4255-bdf6-79a2095563c9",
        "OriginalId": "0f319931-aa36-4313-9320-86311c0fa623",
        "CceId": "CCE-36021-4",
        "Name": "Network access: Restrict anonymous access to Named Pipes and Shares",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Setup\\RecoveryConsole",
        "ValueName": "setcommand",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "f447923e-f8fb-4116-8aea-7caa4b911175",
        "OriginalId": "e44bb6b6-6bf3-417b-a329-cb9604cde378",
        "CceId": "CCE-37307-6",
        "Name": "Recovery console: Allow floppy copy and access to all drives and all folders",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Control\\Lsa",
        "ValueName": "scenoapplylegacyauditpolicy",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "abb6eb2b-b785-4a43-975a-47ac1c93ea76",
        "OriginalId": "b881554b-111f-46a8-9079-b9eeb9ea60f6",
        "CceId": "CCE-37850-5",
        "Name": "Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Critical",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "String",
        "KeyPath": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon",
        "ValueName": "ScreenSaverGracePeriod",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "11b49c17-741d-4884-b5d6-bd5083950697",
        "OriginalId": "d3fe2010-6fe1-401c-81e8-a635d540af09",
        "CceId": "CCE-37993-3",
        "Name": "MSS: (ScreenSaverGracePeriod) The time in seconds before the screen saver grace period expires (0 recommended)",
        "Type": "Registry",
        "ExpectedValue": "5",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
        "ValueName": "InactivityTimeoutSecs",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "582a4f50-aab8-4cba-bba5-28eff6603436",
        "OriginalId": "8f489e6b-a616-43ac-af90-2eba4099d43e",
        "CceId": "CCE-38235-8",
        "Name": "Interactive logon: Machine inactivity limit",
        "Type": "Registry",
        "ExpectedValue": "900",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Services\\LanManServer\\Parameters",
        "ValueName": "enableforcedlogoff",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "92355bf7-0d7f-4263-99d3-333183dd22e5",
        "OriginalId": "68c3ff44-f8a7-4059-81d7-56749f60665b",
        "CceId": "CCE-37972-7",
        "Name": "Microsoft network server: Disconnect clients when logon hours expire",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
        "ValueName": "DontDisplayLastUserName",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "1c449a3c-20c5-40e6-9742-d90052f1f60c",
        "OriginalId": "6b285a31-21ae-4b0c-813c-a8cc812c694d",
        "CceId": "CCE-36056-0",
        "Name": "Interactive logon: Do not display last user name",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
        "ValueName": "MaxDevicePasswordFailedAttempts",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "0196ee31-5772-4783-b28d-4481af0d7ad1",
        "OriginalId": "12e02fe8-cf46-415b-8e52-9b8472d8f303",
        "CceId": "CCE-36264-0",
        "Name": "Interactive logon: Machine account lockout threshold",
        "Type": "Registry",
        "ExpectedValue": "10",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Control\\Print\\Providers\\LanMan Print Services\\Servers",
        "ValueName": "AddPrinterDrivers",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "53f493fb-f11a-44e9-9adb-3069d66a9844",
        "OriginalId": "a9411a96-e13f-4b37-ab31-b84a06d63460",
        "CceId": "CCE-37942-0",
        "Name": "Devices: Prevent users from installing printer drivers",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Services\\Netlogon\\Parameters",
        "ValueName": "requirestrongkey",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "29a1e869-c0c9-4af8-a962-dfc56940496b",
        "OriginalId": "577a19bc-6d69-45f1-9806-b413d522b05a",
        "CceId": "CCE-37614-5",
        "Name": "Domain member: Require strong (Windows 2000 or later) session key",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Critical",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Policies\\Microsoft\\WindowsFirewall\\DomainProfile",
        "ValueName": "DisableUnicastResponsesToMulticastBroadcast",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "1347db54-edff-4589-b69b-37d4d2254ec0",
        "OriginalId": "567434c1-c73f-4a24-8553-eaf1fd70fc90",
        "CceId": "CCE-37859-6",
        "Name": "Windows Firewall: Domain: Allow unicast response",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Policies\\Microsoft\\WindowsFirewall\\DomainProfile",
        "ValueName": "AllowLocalPolicyMerge",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "b184d7c3-98b4-41b2-b0eb-f339ea09eb80",
        "OriginalId": "0a80cfc2-0dcd-4566-b4be-6d8224961f83",
        "CceId": "CCE-37860-4",
        "Name": "Windows Firewall: Domain: Apply local firewall rules",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Policies\\Microsoft\\WindowsFirewall\\PrivateProfile",
        "ValueName": "EnableFirewall",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "52c38897-671e-4e6d-a678-b939626a078a",
        "OriginalId": "d493f92b-2fe2-4489-a4e6-03fd2e3710cd",
        "CceId": "CCE-38239-0",
        "Name": "Windows Firewall: Private: Firewall state",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Services\\Tcpip6\\Parameters",
        "ValueName": "DisableIPSourceRouting",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "09f5958c-7373-47b8-b3ee-ed1fdb66bc26",
        "OriginalId": "21d226de-3201-414e-a16a-b626b6d0cc26",
        "CceId": "CCE-36871-2",
        "Name": "MSS: (DisableIPSourceRouting IPv6) IP source routing protection level (protects against packet spoofing)",
        "Type": "Registry",
        "ExpectedValue": "2",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Policies\\Microsoft\\WindowsFirewall\\PrivateProfile",
        "ValueName": "AllowLocalIPsecPolicyMerge",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "4369ece9-cb45-45c3-81d5-ff1b000cfee9",
        "OriginalId": "f5513338-0fa1-484e-83fb-9a5bd3954d44",
        "CceId": "CCE-36063-6",
        "Name": "Windows Firewall: Private: Apply local connection security rules",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Policies\\Microsoft\\WindowsFirewall\\PrivateProfile",
        "ValueName": "DisableUnicastResponsesToMulticastBroadcast",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "eca3c424-296a-4f30-9a0d-b864c79d7496",
        "OriginalId": "3fe3c052-d096-4bc2-8d03-7ddb03f3b1f6",
        "CceId": "CCE-37134-4",
        "Name": "Windows Firewall: Private: Allow unicast response",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Policies\\Microsoft\\WindowsFirewall\\PublicProfile",
        "ValueName": "AllowLocalPolicyMerge",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "213245bc-f46a-4015-83af-4811a20d6f3d",
        "OriginalId": "968787a1-6a19-4c96-82dd-ca531f84666d",
        "CceId": "CCE-37861-2",
        "Name": "Windows Firewall: Public: Apply local firewall rules",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Policies\\Microsoft\\WindowsFirewall\\PublicProfile",
        "ValueName": "AllowLocalIPsecPolicyMerge",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "613d4370-3623-49b3-b8a7-e70d2887ce7d",
        "OriginalId": "849952c3-4163-4e4d-9320-138c4af87134",
        "CceId": "CCE-36268-1",
        "Name": "Windows Firewall: Public: Apply local connection security rules",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Policies\\Microsoft\\WindowsFirewall\\PublicProfile",
        "ValueName": "EnableFirewall",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "895eb34a-7e3f-4ea1-a246-7b83a6c1fed8",
        "OriginalId": "856f9866-0378-4952-a164-4d524770bb2a",
        "CceId": "CCE-37862-0",
        "Name": "Windows Firewall: Public: Firewall state",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Policies\\Microsoft\\WindowsFirewall\\PrivateProfile",
        "ValueName": "DefaultOutboundAction",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "b48391da-4d8e-4ade-8649-6623f2ee2a8c",
        "OriginalId": "691c581a-3b42-408b-abbe-f0bea9de3156",
        "CceId": "CCE-38332-3",
        "Name": "Windows Firewall: Private: Outbound connections",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Policies\\Microsoft\\WindowsFirewall\\DomainProfile",
        "ValueName": "DefaultOutboundAction",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "052284a8-7e89-4814-879c-7cfe253054ba",
        "OriginalId": "62c711b9-cd72-4fd2-8596-bb90387278da",
        "CceId": "CCE-36146-9",
        "Name": "Windows Firewall: Domain: Outbound connections",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Policies\\Microsoft\\WindowsFirewall\\DomainProfile",
        "ValueName": "EnableFirewall",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "fdec9505-d189-4598-85cd-9bda510be673",
        "OriginalId": "2e65a105-5cb1-473d-b0ca-c933415d91be",
        "CceId": "CCE-36062-8",
        "Name": "Windows Firewall: Domain: Firewall state",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Policies\\Microsoft\\WindowsFirewall\\PublicProfile",
        "ValueName": "DisableUnicastResponsesToMulticastBroadcast",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "2c88ed3a-ec64-4c63-8591-f5f1fc5354bd",
        "OriginalId": "01cfd956-48cc-4ad6-94ff-b8f7ca488a91",
        "CceId": "CCE-36324-2",
        "Name": "Windows Firewall: Public: Allow unicast response",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Policies\\Microsoft\\WindowsFirewall\\DomainProfile",
        "ValueName": "AllowLocalIPsecPolicyMerge",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "56a5bfb9-41d8-48d9-85bd-41ef1ee622a7",
        "OriginalId": "db12a482-5822-44ba-b35d-e944d3ddd528",
        "CceId": "CCE-38040-2",
        "Name": "Windows Firewall: Domain: Apply local connection security rules",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Policies\\Microsoft\\WindowsFirewall\\PrivateProfile",
        "ValueName": "DisableNotifications",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "c6128934-d4ff-4437-ad3b-ef56c40585b1",
        "OriginalId": "0091ec7e-714b-4bb3-9a36-a73412c6c1f9",
        "CceId": "CCE-37621-0",
        "Name": "Windows Firewall: Private: Display a notification",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Services\\Tcpip\\Parameters",
        "ValueName": "DisableIPSourceRouting",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "842f1fe1-17d8-4461-a3fd-358df93aa4ca",
        "OriginalId": "21e5ee29-51b2-4719-b979-af03e47a128e",
        "CceId": "CCE-36535-3",
        "Name": "MSS: (DisableIPSourceRouting) IP source routing protection level (protects against packet spoofing)",
        "Type": "Registry",
        "ExpectedValue": "2",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Policies\\Microsoft\\WindowsFirewall\\DomainProfile",
        "ValueName": "DisableNotifications",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "39a665ad-cde0-4e47-b9a1-6aab4b3bb8ae",
        "OriginalId": "27abca4f-4873-490c-87b6-e84d2533ba13",
        "CceId": "CCE-38041-0",
        "Name": "Windows Firewall: Domain: Display a notification",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Policies\\Microsoft\\WindowsFirewall\\PublicProfile",
        "ValueName": "DisableNotifications",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "c3ead565-6501-43c6-a8b6-f721d8a2bc30",
        "OriginalId": "902a957b-c9b3-4302-883a-394555087509",
        "CceId": "CCE-38043-6",
        "Name": "Windows Firewall: Public: Display a notification",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Policies\\Microsoft\\WindowsFirewall\\PublicProfile",
        "ValueName": "DefaultOutboundAction",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "e95dcf65-a945-4dea-a264-70f9111d2c63",
        "OriginalId": "75208064-559a-4412-8ca6-5da2d0e10cfd",
        "CceId": "CCE-37434-8",
        "Name": "Windows Firewall: Public: Outbound connections",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Policies\\Microsoft\\WindowsFirewall\\PrivateProfile",
        "ValueName": "AllowLocalPolicyMerge",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "7c5e28d9-7ac0-4ae8-9aea-5aae596d7c78",
        "OriginalId": "533bf252-df1b-4b5a-9320-8da18b19bcd2",
        "CceId": "CCE-37438-9",
        "Name": "Windows Firewall: Private: Apply local firewall rules",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
        "ValueName": "FilterAdministratorToken",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "050cca7d-3bd4-4e04-a700-11e8a9787602",
        "OriginalId": "5fbabdf6-6786-46f6-b959-596af69f2650",
        "CceId": "CCE-36494-3",
        "Name": "User Account Control: Admin Approval Mode for the Built-in Administrator account",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
        "ValueName": "EnableSecureUIAPaths",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "f10e52c4-b6cb-478a-a0c2-4ab238e8be43",
        "OriginalId": "0d380cb0-a162-4dbb-b54b-d41a2a7f9036",
        "CceId": "CCE-37057-7",
        "Name": "User Account Control: Only elevate UIAccess applications that are installed in secure locations",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
        "ValueName": "ConsentPromptBehaviorAdmin",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "f4b16962-1063-4dad-ad43-815005345072",
        "OriginalId": "48974513-39ec-472c-9ee8-5cb8abf3cb64",
        "CceId": "CCE-37029-6",
        "Name": "User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode",
        "Type": "Registry",
        "ExpectedValue": "2",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
        "ValueName": "EnableUIADesktopToggle",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "10213290-9da5-4802-a9ed-019b0e1aee6b",
        "OriginalId": "444439f0-8c54-4a1f-9e91-03533d9a69fb",
        "CceId": "CCE-36863-9",
        "Name": "User Account Control: Allow UIAccess applications to prompt for elevation without using the secure desktop",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
        "ValueName": "EnableVirtualization",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "1a433676-2364-48e2-81f5-c962ef31c7e2",
        "OriginalId": "f50c62f4-6c34-466b-b495-54c834820a24",
        "CceId": "CCE-37064-3",
        "Name": "User Account Control: Virtualize file and registry write failures to per-user locations",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
        "ValueName": "PromptOnSecureDesktop",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "d8f63848-f2a4-43e3-9588-82121871536d",
        "OriginalId": "a43ef40c-3543-4204-a431-0f01df930b63",
        "CceId": "CCE-36866-2",
        "Name": "User Account Control: Switch to the secure desktop when prompting for elevation",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
        "ValueName": "EnableLUA",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "c2c67b6f-5b67-4ad2-81a9-40ef68ed1f29",
        "OriginalId": "ef509260-bd3a-450b-807d-16b454851c6f",
        "CceId": "CCE-36869-6",
        "Name": "User Account Control: Run all administrators in Admin Approval Mode",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
        "ValueName": "ConsentPromptBehaviorUser",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "6ea3a26d-9b8d-4fcc-b96a-f8e0379b2f35",
        "OriginalId": "5a0c69d4-3f9a-4c0c-afe9-89a70342a2f7",
        "CceId": "CCE-36864-7",
        "Name": "User Account Control: Behavior of the elevation prompt for standard users",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Control\\Session Manager",
        "ValueName": "ProtectionMode",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "cd4a65f0-735a-491e-91f1-992eac63b2e3",
        "OriginalId": "92b9d876-9d87-460c-82ea-9e8bd94c21ad",
        "CceId": "CCE-37644-2",
        "Name": "System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links)",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
        "ValueName": "EnableInstallerDetection",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "aec71019-bad6-48e5-a371-c8b92fcf3f51",
        "OriginalId": "7ff3401a-70b6-40fa-bb33-73024f591b93",
        "CceId": "CCE-36533-8",
        "Name": "User Account Control: Detect application installations and prompt for elevation",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Services\\LanmanWorkstation\\Parameters",
        "ValueName": "EnableSecuritySignature",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "307d7a86-7830-48da-81b4-455f77a76294",
        "OriginalId": "817b2f4e-1f03-4bcc-927b-816ddd4777f9",
        "CceId": "CCE-36269-9",
        "Name": "Microsoft network client: Digitally sign communications (if server agrees)",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Critical",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Services\\LDAP",
        "ValueName": "LDAPClientIntegrity",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "ee5328da-98d4-4ea6-8832-7827d5623334",
        "OriginalId": "6e48c65a-e5dd-4d64-a6e9-dfd86742f91e",
        "CceId": "CCE-36858-9",
        "Name": "Network security: LDAP client signing requirements",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Services\\LanmanWorkstation\\Parameters",
        "ValueName": "RequireSecuritySignature",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "0d4ab9c2-cbb8-491a-848f-75692b5c4054",
        "OriginalId": "ed734c3b-b27f-4515-9154-9f6f414e6564",
        "CceId": "CCE-36325-9",
        "Name": "Microsoft network client: Digitally sign communications (always)",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Critical",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Services\\LanManServer\\Parameters",
        "ValueName": "requiresecuritysignature",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "bef8c442-25ca-4a30-8762-19e992c7a996",
        "OriginalId": "502cd61a-fec9-42f0-a096-1ac097bbdf73",
        "CceId": "CCE-37864-6",
        "Name": "Microsoft network server: Digitally sign communications (always)",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Critical",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Services\\Netlogon\\Parameters",
        "ValueName": "signsecurechannel",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "ee9368a1-f2f7-40f9-8358-1e15c43464c1",
        "OriginalId": "7ab7ae06-f9bd-4252-a282-8fd3a06a73df",
        "CceId": "CCE-37222-7",
        "Name": "Domain member: Digitally sign secure channel data (when possible)",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Services\\Netlogon\\Parameters",
        "ValueName": "requiresignorseal",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "b9022c31-695d-4a31-8cdf-0fc767e085fb",
        "OriginalId": "04b278da-3245-43ec-9d5a-a5a68805027b",
        "CceId": "CCE-36142-8",
        "Name": "Domain member: Digitally encrypt or sign secure channel data (always)",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Critical",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Services\\LanManServer\\Parameters",
        "ValueName": "enablesecuritysignature",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "8094f554-990c-4422-8086-a5eaf8fa7073",
        "OriginalId": "1c96e719-94c8-4333-9165-6efb6a9c6210",
        "CceId": "CCE-35988-5",
        "Name": "Microsoft network server: Digitally sign communications (if client agrees)",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Critical",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Services\\Netlogon\\Parameters",
        "ValueName": "sealsecurechannel",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "dba534fe-4e4b-4016-86b1-cbb538c4bae1",
        "OriginalId": "b106bcb1-2b74-4287-8587-6cd92d337be8",
        "CceId": "CCE-37130-2",
        "Name": "Domain member: Digitally encrypt secure channel data (when possible)",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "SYSTEM\\CurrentControlSet\\Services\\Eventlog\\Security",
        "ValueName": "WarningLevel",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "ad883480-4920-4984-8372-19c1814dc468",
        "OriginalId": "19a0c0e2-48ca-4a9f-9493-bd547b86d8ad",
        "CceId": "CCE-36880-3",
        "Name": "MSS: (WarningLevel) Percentage threshold for the security event log at which the system will generate a warning",
        "Type": "Registry",
        "ExpectedValue": "90",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Control\\Lsa",
        "ValueName": "crashonauditfail",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "dbab07cc-682a-40c1-9c18-7706c068f45d",
        "OriginalId": "25c67f65-0d37-41d5-9e75-72707c97a290",
        "CceId": "CCE-35907-5",
        "Name": "Audit: Shut down system immediately if unable to log security audits",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Control\\Lsa",
        "ValueName": "LimitBlankPasswordUse",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "385cc232-e49c-4ce1-bd8c-4c835968c46a",
        "OriginalId": "051cdac6-2234-4eb7-85eb-db391c469557",
        "CceId": "CCE-37615-2",
        "Name": "Accounts: Limit local account use of blank passwords to console logon only",
        "Type": "Registry",
        "ExpectedValue": "1",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "System\\CurrentControlSet\\Services\\Netlogon\\Parameters",
        "ValueName": "disablepasswordchange",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "5935e38e-c0cd-47de-a5e2-a86f93db2310",
        "OriginalId": "b44fadd3-f7c2-45dc-98dd-5e9ba179d89d",
        "CceId": "CCE-37508-9",
        "Name": "Domain member: Disable machine account password changes",
        "Type": "Registry",
        "ExpectedValue": "0",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "Hive": "LocalMachine",
        "RegValueType": "Int",
        "KeyPath": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon",
        "ValueName": "passwordexpirywarning",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "a7749991-3eba-4e69-9e31-6f6b6999d6c9",
        "OriginalId": "74870acb-ad3d-4bec-a067-1b1895ce2621",
        "CceId": "CCE-37622-8",
        "Name": "Interactive logon: Prompt user to change password before expiration",
        "Type": "Registry",
        "ExpectedValue": "14",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        }
        ],
        "BaselineAuditPolicyRule": [
        {
        "AuditPolicyId": "0cce9213-69ae-11d9-bed3-505054503030",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "107b8424-7ee8-4b6a-a859-b5256aa6596e",
        "OriginalId": "504f27d5-2540-48f2-9aa4-ee0eebc84728",
        "CceId": "CCE-37853-9",
        "Name": "Audit Policy: System: IPsec Driver",
        "Type": "AuditPolicy",
        "ExpectedValue": "Failure",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "AuditPolicyId": "0cce9211-69ae-11d9-bed3-505054503030",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "bda94d3b-0526-494c-9e33-c6bd0d9a0ac8",
        "OriginalId": "5bd3a1dc-6de8-4021-a1a7-f1cf51f51235",
        "CceId": "CCE-36144-4",
        "Name": "Audit Policy: System: Security System Extension",
        "Type": "AuditPolicy",
        "ExpectedValue": "Success and Failure",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": false
        },
        {
        "AuditPolicyId": "0cce9237-69ae-11d9-bed3-505054503030",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "d6bca841-8cbc-4e0b-a7cc-0d267033cf46",
        "OriginalId": "56d671e2-8ff8-47cd-adeb-82fb86067598",
        "CceId": "CCE-38034-5",
        "Name": "Audit Policy: Account Management: Security Group Management",
        "Type": "AuditPolicy",
        "ExpectedValue": "Success and Failure",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "AuditPolicyId": "0cce923a-69ae-11d9-bed3-505054503030",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "bfbcf6a4-5918-43d6-b227-3eb743c42fc6",
        "OriginalId": "2ea0de1a-c71d-46c8-8350-a7dd4d447895",
        "CceId": "CCE-37855-4",
        "Name": "Audit Policy: Account Management: Other Account Management Events",
        "Type": "AuditPolicy",
        "ExpectedValue": "Success and Failure",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "AuditPolicyId": "0cce9210-69ae-11d9-bed3-505054503030",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "9381b3b7-5bde-4ecd-af97-a944766690db",
        "OriginalId": "e54d7bef-4406-4689-813c-ba14b3fd3ef8",
        "CceId": "CCE-38114-5",
        "Name": "Audit Policy: System: Security State Change",
        "Type": "AuditPolicy",
        "ExpectedValue": "Success and Failure",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "AuditPolicyId": "0cce922b-69ae-11d9-bed3-505054503030",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "b566ed34-277a-420f-9070-1a004fceea77",
        "OriginalId": "6598ae0c-9227-4f87-b754-f68d2f5820fc",
        "CceId": "CCE-36059-4",
        "Name": "Audit Policy: Detailed Tracking: Process Creation",
        "Type": "AuditPolicy",
        "ExpectedValue": "Success",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "AuditPolicyId": "0cce9214-69ae-11d9-bed3-505054503030",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "632ec8bb-afbc-4b95-ae0c-4c47955e25fb",
        "OriginalId": "aad1ad34-9f4f-4c86-b29a-c6710169687c",
        "CceId": "CCE-38030-3",
        "Name": "Audit Policy: System: Other System Events",
        "Type": "AuditPolicy",
        "ExpectedValue": "Success and Failure",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "AuditPolicyId": "0cce9217-69ae-11d9-bed3-505054503030",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "ebad0dce-6521-48a5-b940-e83a03f237f6",
        "OriginalId": "a28ddc45-464d-4cee-a675-9a3dfe0c07c7",
        "CceId": "CCE-37133-6",
        "Name": "Audit Policy: Logon-Logoff: Account Lockout",
        "Type": "AuditPolicy",
        "ExpectedValue": "Success",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "AuditPolicyId": "0cce922f-69ae-11d9-bed3-505054503030",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "101eaf81-3dd3-4867-8871-f649131a06a9",
        "OriginalId": "821af41f-7ff7-4dae-a841-c098b7112b0c",
        "CceId": "CCE-38028-7",
        "Name": "Audit Policy: Policy Change: Audit Policy Change",
        "Type": "AuditPolicy",
        "ExpectedValue": "Success and Failure",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "AuditPolicyId": "0cce921b-69ae-11d9-bed3-505054503030",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "3872d203-c556-4001-b2f6-b6ee0bd926c4",
        "OriginalId": "f3179229-59a3-4c89-8eb2-45cdf42660b1",
        "CceId": "CCE-36266-5",
        "Name": "Audit Policy: Logon-Logoff: Special Logon",
        "Type": "AuditPolicy",
        "ExpectedValue": "Success",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "AuditPolicyId": "0cce9235-69ae-11d9-bed3-505054503030",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "d07a36dc-de05-4842-9a11-22d2b3411127",
        "OriginalId": "17bbd596-ee57-4506-b4eb-b8914b2d8b34",
        "CceId": "CCE-37856-2",
        "Name": "Audit Policy: Account Management: User Account Management",
        "Type": "AuditPolicy",
        "ExpectedValue": "Success and Failure",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "AuditPolicyId": "0cce923f-69ae-11d9-bed3-505054503030",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "a41cbeed-d66b-4020-8a10-9a78a135b523",
        "OriginalId": "ebd86e7c-c2be-461a-9db9-c4f9fd79e32f",
        "CceId": "CCE-37741-6",
        "Name": "Audit Policy: Account Logon: Credential Validation",
        "Type": "AuditPolicy",
        "ExpectedValue": "Success and Failure",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "AuditPolicyId": "0cce9215-69ae-11d9-bed3-505054503030",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "213b1b6e-523a-4a42-bc8f-1f4276ef59c7",
        "OriginalId": "abcedd04-373e-493b-8fc4-610ca4e2c11e",
        "CceId": "CCE-38036-0",
        "Name": "Audit Policy: Logon-Logoff: Logon",
        "Type": "AuditPolicy",
        "ExpectedValue": "Success and Failure",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "AuditPolicyId": "0cce9236-69ae-11d9-bed3-505054503030",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "8b61459e-2b27-4675-b5d1-00f8f1f1529d",
        "OriginalId": "a94d7f10-22ff-48e8-bd82-1dfc5ccb1cb4",
        "CceId": "CCE-38004-8",
        "Name": "Audit Policy: Account Management: Computer Account Management",
        "Type": "AuditPolicy",
        "ExpectedValue": "Success",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "AuditPolicyId": "0cce9228-69ae-11d9-bed3-505054503030",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "8d0d6832-fdb5-46f1-b225-cf224ff8d3c9",
        "OriginalId": "591401f2-3712-4434-ae22-e8633dcf2ad5",
        "CceId": "CCE-36267-3",
        "Name": "Audit Policy: Privilege Use: Sensitive Privilege Use",
        "Type": "AuditPolicy",
        "ExpectedValue": "Success and Failure",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "AuditPolicyId": "0cce9216-69ae-11d9-bed3-505054503030",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "41f6a2e9-03b1-4d32-a026-91ef6899024f",
        "OriginalId": "9f28bf93-31ae-4a09-b064-a391772fe13d",
        "CceId": "CCE-38237-4",
        "Name": "Audit Policy: Logon-Logoff: Logoff",
        "Type": "AuditPolicy",
        "ExpectedValue": "Success",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "AuditPolicyId": "0cce9230-69ae-11d9-bed3-505054503030",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "aa0ca1a0-d22f-4f98-9084-7de0dc6e05da",
        "OriginalId": "2768f99a-87a1-4be6-bf44-efcfd1412dea",
        "CceId": "CCE-38327-3",
        "Name": "Audit Policy: Policy Change: Authentication Policy Change",
        "Type": "AuditPolicy",
        "ExpectedValue": "Success",
        "Severity": "Warning",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "AuditPolicyId": "0cce9212-69ae-11d9-bed3-505054503030",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "2a94b2d5-fd25-45de-a576-8e5b7497262f",
        "OriginalId": "b8fc1e7a-57fd-48a0-827e-f466b21663ae",
        "CceId": "CCE-37132-8",
        "Name": "Audit Policy: System: System Integrity",
        "Type": "AuditPolicy",
        "ExpectedValue": "Success and Failure",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        }
        ],
        "BaselineSecurityPolicyRule": [
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeCreateGlobalPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "a01142fd-5529-4f95-b55b-73d04adb9919",
        "OriginalId": "c3a6cfaf-1504-4d55-ace8-1ebc971d9ebc",
        "CceId": "CCE-37453-8",
        "Name": "Create global objects",
        "Type": "SecurityPolicy",
        "ExpectedValue": "AUTHENTICATED USERS, SERVICE, LOCAL SERVICE, NETWORK SERVICE",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeNetworkLogonRight",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "33f6db2d-3816-47e5-af11-f3e014bdaad6",
        "OriginalId": "48cf8aee-1c72-4c3e-9f2a-c6dfe8990219",
        "CceId": "CCE-35818-4",
        "Name": "Access this computer from the network",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Administrators, Authenticated Users",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": false
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeRelabelPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "1dc534a7-f6c1-4977-bd74-037e6b5159bf",
        "OriginalId": "cb3e6c7f-6d9b-4577-95df-93791481f060",
        "CceId": "CCE-36054-5",
        "Name": "Modify an object label",
        "Type": "SecurityPolicy",
        "ExpectedValue": "No One",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeAuditPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "c0178641-dfd3-4937-b32a-a661f4b3b36a",
        "OriginalId": "3ebdc510-830f-4520-9bce-2fe8f4f88b3f",
        "CceId": "CCE-37639-2",
        "Name": "Generate security audits",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Local Service, Network Service",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeIncreaseBasePriorityPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "22e60f42-b881-41a9-a773-1dd57677d07c",
        "OriginalId": "eba90e79-8551-416f-9258-a48e1d9a60c7",
        "CceId": "CCE-38326-5",
        "Name": "Increase scheduling priority",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Administrators",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeRemoteShutdownPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "cc36c1ba-77d8-4317-9a52-c57862f9bee1",
        "OriginalId": "8840018d-e63a-4e69-96a8-c06af7e963a8",
        "CceId": "CCE-37877-8",
        "Name": "Force shutdown from a remote system",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Administrators",
        "Severity": "Critical",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeRemoteInteractiveLogonRight",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "31a81fcc-b81f-4c87-afe5-a6f422da365f",
        "OriginalId": "78c974e6-940e-4fec-8697-73d0ed54943c",
        "CceId": "CCE-37072-6",
        "Name": "Allow log on through Remote Desktop Services",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Administrators",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeSystemTimePrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "79ccc4e0-2306-4ac8-a492-7d36287c9adb",
        "OriginalId": "44aa9ea0-873d-441e-9103-39a98f1704aa",
        "CceId": "CCE-37452-0",
        "Name": "Change the system time",
        "Type": "SecurityPolicy",
        "ExpectedValue": "LOCAL SERVICE, Administrators",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeCreatePagefilePrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "b02be7bd-d30f-4d9e-8df4-7a5b01a1364d",
        "OriginalId": "52a9b265-75cb-45a0-ac23-3e5d4fa566c2",
        "CceId": "CCE-35821-8",
        "Name": "Create a pagefile",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Administrators",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeProfileSingleProcessPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "b239649c-499c-479a-b1a1-29ca9dc66fb1",
        "OriginalId": "f921fab5-cf36-4241-b474-276fd53263a5",
        "CceId": "CCE-37131-0",
        "Name": "Profile single process",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Administrators",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeDenyBatchLogonRight",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "406f0e13-8709-4ac1-87aa-779f2a3e554b",
        "OriginalId": "8797b752-5346-436e-8502-cd5031cc77d5",
        "CceId": "CCE-36923-1",
        "Name": "Deny log on as a batch job",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Guests",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeTcbPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "1eb18791-2d15-4e6a-9280-6cb868fc0162",
        "OriginalId": "b77b9700-3212-4d5f-9547-dbe8ffd32574",
        "CceId": "CCE-36876-1",
        "Name": "Act as part of the operating system",
        "Type": "SecurityPolicy",
        "ExpectedValue": "No One",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeTimeZonePrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "6fb65585-1b82-40dd-8449-32f91ac7ef21",
        "OriginalId": "9066c223-8261-4c0b-9cfc-6a396532dbbc",
        "CceId": "CCE-37700-2",
        "Name": "Change the time zone",
        "Type": "SecurityPolicy",
        "ExpectedValue": "LOCAL SERVICE, Administrators",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeLockMemoryPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "c7282bdc-e040-4e22-bb4a-f5977d8f59f8",
        "OriginalId": "38165ccc-d675-481c-8881-231a5c2032f9",
        "CceId": "CCE-36495-0",
        "Name": "Lock pages in memory",
        "Type": "SecurityPolicy",
        "ExpectedValue": "No One",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeTrustedCredManAccessPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "a723aa73-7a8e-46b6-8624-d086b27772fc",
        "OriginalId": "60859cb4-3ad7-4a2f-8564-fcfde3ee1768",
        "CceId": "CCE-37056-9",
        "Name": "Access Credential Manager as a trusted caller",
        "Type": "SecurityPolicy",
        "ExpectedValue": "No One",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeCreateTokenPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "ec508621-1384-40f9-8cee-defd90934808",
        "OriginalId": "96bc8bd8-d3d6-4f89-8f91-4ea964f2db67",
        "CceId": "CCE-36861-3",
        "Name": "Create a token object",
        "Type": "SecurityPolicy",
        "ExpectedValue": "No One",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeDebugPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "005bfd95-40be-4719-83e9-9769a70dcd9c",
        "OriginalId": "591bd8ac-a5b3-41cc-8978-2bce50123a00",
        "CceId": "CCE-37075-9",
        "Name": "Debug programs",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Administrators",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeDenyServiceLogonRight",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "6c2c0627-54b0-4dc0-8077-be7f3ea838e8",
        "OriginalId": "16e53e79-5879-477f-a7ea-2b4cd0fff5ba",
        "CceId": "CCE-36877-9",
        "Name": "Deny log on as a service",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Guests",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeDenyNetworkLogonRight",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "4c940ec2-5e0e-431b-906b-5c1b4a82c326",
        "OriginalId": "b9af2cf2-1528-469c-b7e8-3787c4513479",
        "CceId": "CCE-37954-5",
        "Name": "Deny access to this computer from the network",
        "Type": "SecurityPolicy",
        "ExpectedValue": "No One",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeBackupPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "32b97116-c800-4107-a1b7-8e15253508a8",
        "OriginalId": "1ce3bf70-68d8-419b-96ef-d293de427cff",
        "CceId": "CCE-35912-5",
        "Name": "Back up files and directories",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Administrators",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeShutdownPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "2c6609e1-4393-43b1-a77c-7a6dd15ccf94",
        "OriginalId": "204ff604-1cab-46c8-aa22-01e7d78925e4",
        "CceId": "CCE-38328-1",
        "Name": "Shut down the system",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Administrators",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeDenyInteractiveLogonRight",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "b179628e-7260-461e-9c1d-5638a78dac97",
        "OriginalId": "d2197a4c-19f4-4630-b15a-aaf85c813045",
        "CceId": "CCE-37146-8",
        "Name": "Deny log on locally",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Guests",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeAssignPrimaryTokenPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "fcfd01ef-29c0-470c-8669-131f6f3347f6",
        "OriginalId": "6870b1f9-8535-493c-9a30-889fd01900d7",
        "CceId": "CCE-37430-6",
        "Name": "Replace a process level token",
        "Type": "SecurityPolicy",
        "ExpectedValue": "LOCAL SERVICE, NETWORK SERVICE",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeDenyRemoteInteractiveLogonRight",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "49b31ab3-ba8d-44f7-92b1-850c105752d5",
        "OriginalId": "49862b02-e96e-4ebc-8cac-129f07b1298e",
        "CceId": "CCE-36867-0",
        "Name": "Deny log on through Remote Desktop Services",
        "Type": "SecurityPolicy",
        "ExpectedValue": "No One",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeSystemEnvironmentPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "49a2d248-907e-41dc-9f09-e91f60069c12",
        "OriginalId": "63db26be-30f4-4428-9b60-ea0b0daeae0d",
        "CceId": "CCE-38113-7",
        "Name": "Modify firmware environment values",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Administrators",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeInteractiveLogonRight",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "dd2d1504-9d49-4d16-8937-eb9e7d5f4a40",
        "OriginalId": "23a1c3b4-4d38-4153-854a-e315ad699d9b",
        "CceId": "CCE-37659-0",
        "Name": "Allow log on locally",
        "Type": "SecurityPolicy",
        "ExpectedValue": "AUTHENTICATED USERS",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeRestorePrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "048dd516-4793-44e1-8e5d-444a54113628",
        "OriginalId": "c63e0099-758c-4b99-aecd-eb63df8559d8",
        "CceId": "CCE-37613-7",
        "Name": "Restore files and directories",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Administrators",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeManageVolumePrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "dadaf9fd-114b-47b1-abc4-b95a8fc62426",
        "OriginalId": "5e0f8e3b-f0fe-40be-b155-c4fd56f6c9e1",
        "CceId": "CCE-36143-6",
        "Name": "Perform volume maintenance tasks",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Administrators",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeSecurityPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "0f5f6960-8122-47cb-a1f5-b1d174d4b8d7",
        "OriginalId": "6630b24b-754a-49a5-9750-188ae53c13b9",
        "CceId": "CCE-35906-7",
        "Name": "Manage auditing and security log",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Administrators",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeEnableDelegationPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "3edf66ca-eef2-4a11-9b5f-0e9f66d0c485",
        "OriginalId": "485ea1c9-091c-434b-b8e0-c9d8cbfde052",
        "CceId": "CCE-36860-5",
        "Name": "Enable computer and user accounts to be trusted for delegation",
        "Type": "SecurityPolicy",
        "ExpectedValue": "No One",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeImpersonatePrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "4907ba1a-3aa6-45d1-addf-bb3b93a3db43",
        "OriginalId": "87691f9f-e18e-42c3-ac3c-621c7b30bdda",
        "CceId": "CCE-37106-2",
        "Name": "Impersonate a client after authentication",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Administrators, SERVICE, Local Service, Network Service",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeLoadDriverPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "f1bd228c-0d50-4f76-9b3e-a18536d56a29",
        "OriginalId": "4e63307f-262d-4242-8210-c7753d029bef",
        "CceId": "CCE-36318-4",
        "Name": "Load and unload device drivers",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Administrators",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeTakeOwnershipPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "a0c45b19-b0e3-4a8a-801e-f0c0ee992d12",
        "OriginalId": "f540aa73-5550-4058-9209-e268908611d5",
        "CceId": "CCE-38325-7",
        "Name": "Take ownership of files or other objects",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Administrators",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeIncreaseQuotaPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "71683de8-8d1f-4e3e-b0bf-932b5d9a30db",
        "OriginalId": "4b696c3e-dd2c-4d5e-bb0a-d7190de2c322",
        "CceId": "CCE-37071-8",
        "Name": "Adjust memory quotas for a process",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Administrators, Local Service, Network Service",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeCreateSymbolicLinkPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "a7ff021c-f476-48af-82fc-9173919b6720",
        "OriginalId": "10afbff0-0f2c-41b7-8b66-68bda79b77bd",
        "CceId": "CCE-35823-4",
        "Name": "Create symbolic links",
        "Type": "SecurityPolicy",
        "ExpectedValue": "Administrators",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        },
        {
        "SectionName": "Privilege Rights",
        "SettingName": "SeCreatePermanentPrivilege",
        "BaselineId": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
        "Id": "15caeba9-6294-4223-8145-c57e523bbe3d",
        "OriginalId": "dd1e688f-295d-4ee6-8f2f-5cdb83c0b4e1",
        "CceId": "CCE-36532-0",
        "Name": "Create permanent shared objects",
        "Type": "SecurityPolicy",
        "ExpectedValue": "No One",
        "Severity": "Informational",
        "AnalyzeOperation": "NotEquals",
        "Enabled": true
        }
        ]
      },
    "Id": "6ba1ce80-e4e5-4b8a-bc88-257612e72185",
    "Name": "WS2012R2 Member Server Security Compliance"
    }
  ]
}},
"id": "/subscriptions/1/resourceGroups/1/providers/Microsoft.OperationalInsights/workspaces/mico-int/datasources/SecurityWindowsBaselineConfiguration",
"etag": "",
"name": "SecurityWindowsBaselineConfiguration",
"type": "Microsoft.OperationalInsights/workspaces/datasources"
}