Device checks¶
Lookout runs these 37 read-only checks on every Windows device. Each one maps to the CMMC and HIPAA requirements it helps prove. Thresholds marked default can be adjusted to match your policy.
| ID | Check | Severity | Standards |
|---|---|---|---|
ENC-001 |
BitLocker protects all fixed drives | High | CMMC, HIPAA |
ENC-002 |
TPM is present and ready | Medium | CMMC |
ENC-003 |
Secure Boot is enabled | Medium | CMMC |
AV-001 |
Antivirus real-time protection is active | High | CMMC, HIPAA |
AV-002 |
Antivirus signatures are current | High | CMMC, HIPAA |
AV-003 |
Defender tamper protection is on | Medium | CMMC |
AV-004 |
Attack surface reduction rules are configured | Medium | CMMC |
FW-001 |
Windows Firewall is on for all profiles | High | CMMC, HIPAA |
ACC-001 |
No standing local admin rights for user accounts | High | CMMC, HIPAA |
ACC-002 |
Guest account is disabled | Medium | CMMC, HIPAA |
ACC-003 |
Built-in Administrator account is disabled | Low | CMMC |
ACC-004 |
Account lockout threshold is set | High | CMMC, HIPAA |
ACC-005 |
Minimum password length is enforced | Medium | CMMC, HIPAA |
ACC-006 |
Password complexity is required | Medium | CMMC, HIPAA |
ACC-007 |
Password history prevents reuse | Low | CMMC, HIPAA |
ACC-008 |
Local admin password is managed (LAPS) | Medium | CMMC |
ACC-009 |
User Account Control is enabled | High | CMMC, HIPAA |
SES-001 |
Screen locks after inactivity | Medium | CMMC, HIPAA |
SES-002 |
Logon banner is displayed | Low | CMMC |
SES-003 |
Remote Desktop requires Network Level Authentication | High | CMMC, HIPAA |
HRD-001 |
SMBv1 is disabled | High | CMMC |
HRD-002 |
LLMNR is disabled | Medium | CMMC |
HRD-003 |
NetBIOS over TCP/IP is disabled | Low | CMMC |
HRD-004 |
AutoRun is disabled for all drives | Medium | CMMC |
HRD-005 |
Removable storage is restricted | Medium | CMMC |
HRD-006 |
FIPS-compliant algorithms are enforced | Low | CMMC |
HRD-007 |
LSA protection is enabled | Medium | CMMC |
HRD-008 |
Credential Guard is running | Medium | CMMC |
HRD-009 |
WDigest does not cache plaintext credentials | High | CMMC, HIPAA |
AUD-001 |
Key audit subcategories are enabled | High | CMMC, HIPAA |
AUD-002 |
Security event log is large enough | Medium | CMMC, HIPAA |
AUD-003 |
PowerShell script block logging is on | Medium | CMMC, HIPAA |
AUD-004 |
Process creation events include command line | Low | CMMC |
AUD-005 |
Time synchronization is running | Low | CMMC |
PAT-001 |
Updates installed recently | High | CMMC, HIPAA |
PAT-002 |
No reboot pending | Low | CMMC |
PAT-003 |
Operating system is supported | High | CMMC, HIPAA |
Encryption¶
ENC-001 · BitLocker protects all fixed drives¶
Fix: Enable BitLocker with TPM protector on the OS drive and all fixed data drives, and escrow the recovery key.
Take the helm: step-by-step
- For many devices, use Intune: Endpoint security → Disk encryption → create a BitLocker policy that encrypts OS and fixed drives and backs up recovery keys to Entra ID.
- On a single device, open an elevated PowerShell and run
Enable-BitLocker -MountPoint C: -EncryptionMethod XtsAes256 -TpmProtector. - Add a recovery password with
Add-BitLockerKeyProtector -MountPoint C: -RecoveryPasswordProtectorand back it up withBackupToAAD-BitLockerKeyProtector(Entra ID) orBackup-BitLockerKeyProtector(Active Directory) before restarting. - Repeat for each fixed data drive, then confirm with
Get-BitLockerVolume.
Maps to:
SC.L2-3.13.16Protect the confidentiality of CUI at rest164.312(a)(2)(iv)Encryption and decryption
ENC-002 · TPM is present and ready¶
Fix: Enable the TPM in firmware and initialize it.
Take the helm: step-by-step
- Restart into the firmware setup (often F2, F10, or Del during boot).
- Enable the TPM. It may be called Intel PTT or AMD fTPM. Save and exit.
- Back in Windows, run
Get-Tpmand confirm TpmPresent and TpmReady are True. If it isn't ready, runInitialize-Tpm. - If the device has no TPM, plan a replacement. Windows 11 requires TPM 2.0.
Maps to:
SC.L2-3.13.16Protect the confidentiality of CUI at restCM.L2-3.4.2Establish and enforce security configuration settings
ENC-003 · Secure Boot is enabled¶
Fix: Switch firmware to UEFI mode and enable Secure Boot.
Take the helm: step-by-step
- If BitLocker is on, suspend it for one restart first:
Suspend-BitLocker -MountPoint C: -RebootCount 1. - Check the disk style with
Get-Disk. If it's MBR, back up and convert it withmbr2gpt /convert /allowFullOS. - In the firmware setup, switch the boot mode to UEFI (turn off CSM or Legacy) and enable Secure Boot.
- Confirm in Windows with
Confirm-SecureBootUEFI.
Maps to:
CM.L2-3.4.2Establish and enforce security configuration settings
Malware Protection¶
AV-001 · Antivirus real-time protection is active¶
Fix: Enable Defender real-time protection or confirm a third-party AV is installed and running.
Take the helm: step-by-step
- Microsoft Defender: Windows Security → Virus & threat protection → Manage settings → turn on Real-time protection, or run
Set-MpPreference -DisableRealtimeMonitoring $false. - Check that no Group Policy or Intune setting turns Defender off (Administrative Templates → Windows Components → Microsoft Defender Antivirus).
- Third-party antivirus: open its console, confirm the device's agent is installed and protecting, and reinstall the agent if it shows offline.
Maps to:
SI.L2-3.14.2Provide protection from malicious codeSI.L2-3.14.5Perform periodic and real-time scans164.308(a)(5)(ii)(B)Protection from malicious software
AV-002 · Antivirus signatures are current¶
Fix: Confirm the device can reach update sources and run a signature update.
Default thresholds: Maximum signature age (days) = 3
Take the helm: step-by-step
- Update now with
Update-MpSignature(Defender) or the update action in your antivirus console. - Make sure the device can reach its update source and that no proxy or firewall blocks it.
- Confirm the signatures are current with
Get-MpComputerStatus | Select-Object AntivirusSignatureAge.
Maps to:
SI.L2-3.14.4Update malicious code protection mechanisms164.308(a)(5)(ii)(B)Protection from malicious software
AV-003 · Defender tamper protection is on¶
Fix: Turn on tamper protection through Intune, Defender for Endpoint, or Windows Security.
Take the helm: step-by-step
- For all devices, turn on tamper protection in the Microsoft Defender portal (Settings → Endpoints → Advanced features) or with an Intune Endpoint security → Antivirus policy.
- On a single unmanaged device: Windows Security → Virus & threat protection → Manage settings → Tamper Protection: On.
- Confirm with
Get-MpComputerStatus | Select-Object IsTamperProtected.
Maps to:
SI.L2-3.14.2Provide protection from malicious code
AV-004 · Attack surface reduction rules are configured¶
Fix: Deploy the standard ASR rule set in Block mode after an Audit period.
Default thresholds: Minimum ASR rules in Block mode = 5
Take the helm: step-by-step
- In Intune, create an Endpoint security → Attack surface reduction policy with the standard rules set to Audit.
- Review what would have been blocked in the Defender portal (Reports → Attack surface reduction rules) for one to two weeks.
- Switch the rules to Block, adding exclusions only where a business app needs one.
- On a single device:
Add-MpPreference -AttackSurfaceReductionRules_Ids <rule GUID> -AttackSurfaceReductionRules_Actions Enabled.
Maps to:
SI.L2-3.14.2Provide protection from malicious codeCM.L2-3.4.2Establish and enforce security configuration settings
Network¶
FW-001 · Windows Firewall is on for all profiles¶
Fix: Enable the firewall for Domain, Private, and Public profiles with inbound default set to Block.
Take the helm: step-by-step
- Turn on the firewall for every profile:
Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled True -DefaultInboundAction Block. - For many devices, use Intune (Endpoint security → Firewall) or Group Policy (Security Settings → Windows Defender Firewall with Advanced Security).
- Make sure no policy turns it back off:
Get-NetFirewallProfile -PolicyStore ActiveStore.
Maps to:
SC.L2-3.13.1Monitor, control, and protect communications at system boundariesSC.L2-3.13.6Deny network communications traffic by default164.312(e)(1)Transmission security
Accounts¶
ACC-001 · No standing local admin rights for user accounts¶
Fix: Remove user accounts from the local Administrators group. Use LAPS or just-in-time elevation for admin tasks.
Take the helm: step-by-step
- List current admins:
Get-LocalGroupMember -Group Administrators. - Before removing anyone, make sure another admin path works, such as LAPS or a domain admin group.
- Remove user accounts that don't need standing admin rights:
Remove-LocalGroupMember -Group Administrators -Member 'DOMAIN\user'. - Manage membership centrally (Intune: Endpoint security → Account protection → Local user group membership, or Group Policy Restricted Groups) so it doesn't drift back.
Maps to:
AC.L2-3.1.5Employ the principle of least privilegeAC.L2-3.1.6Use non-privileged accounts for nonsecurity functions164.312(a)(1)Access control
ACC-002 · Guest account is disabled¶
Fix: Disable the built-in Guest account.
Take the helm: step-by-step
- Disable the Guest account:
Get-LocalUser | Where-Object SID -like '*-501' | Disable-LocalUser. - For many devices, set Group Policy Security Options → 'Accounts: Guest account status' to Disabled.
Maps to:
AC.L2-3.1.1Limit system access to authorized users164.312(a)(1)Access control
ACC-003 · Built-in Administrator account is disabled¶
Fix: Disable the built-in Administrator (RID 500) account, or manage it with LAPS.
Take the helm: step-by-step
- Confirm another admin account works first.
- Disable the built-in Administrator:
Get-LocalUser | Where-Object SID -like '*-500' | Disable-LocalUser. - For many devices, set Group Policy Security Options → 'Accounts: Administrator account status' to Disabled. If LAPS manages this account, document that instead.
Maps to:
AC.L2-3.1.5Employ the principle of least privilege
ACC-004 · Account lockout threshold is set¶
Fix: Set the account lockout threshold between 1 and 10 invalid attempts with a lockout duration of 15+ minutes.
Default thresholds: Maximum lockout threshold = 10
Take the helm: step-by-step
- Group Policy: Computer Configuration → Windows Settings → Security Settings → Account Policies → Account Lockout Policy. Set the threshold to 5–10 attempts and the duration and reset counter to 15 minutes.
- On a single device:
net accounts /lockoutthreshold:10 /lockoutduration:15 /lockoutwindow:15. - Domain accounts follow the domain's policy (Default Domain Policy), so set it there as well.
Maps to:
AC.L2-3.1.8Limit unsuccessful logon attempts164.308(a)(5)(ii)(C)Log-in monitoring
ACC-005 · Minimum password length is enforced¶
Fix: Set the minimum password length to 14 characters or more.
Default thresholds: Minimum password length = 14
Take the helm: step-by-step
- Group Policy: Account Policies → Password Policy → Minimum password length = 14.
- On a single device:
net accounts /minpwlen:14. - On Entra-joined devices this covers local accounts only; cloud account passwords follow Entra ID policy.
Maps to:
IA.L2-3.5.7Enforce minimum password complexity164.308(a)(5)(ii)(D)Password management
ACC-006 · Password complexity is required¶
Fix: Enable 'Password must meet complexity requirements'.
Take the helm: step-by-step
- Group Policy: Account Policies → Password Policy → 'Password must meet complexity requirements' = Enabled.
- On a single device, set the same option in Local Security Policy (
secpol.msc).
Maps to:
IA.L2-3.5.7Enforce minimum password complexity164.308(a)(5)(ii)(D)Password management
ACC-007 · Password history prevents reuse¶
Fix: Set 'Enforce password history' to 24 or more.
Default thresholds: Passwords remembered = 24
Take the helm: step-by-step
- Group Policy: Account Policies → Password Policy → 'Enforce password history' = 24.
- On a single device:
net accounts /uniquepw:24.
Maps to:
IA.L2-3.5.8Prohibit password reuse for a specified number of generations164.308(a)(5)(ii)(D)Password management
ACC-008 · Local admin password is managed (LAPS)¶
Fix: Deploy Windows LAPS with backup to Entra ID or Active Directory.
Take the helm: step-by-step
- Entra-joined devices: Intune → Endpoint security → Account protection → create a Windows LAPS policy with Backup directory = Azure AD (Entra ID).
- Active Directory: run
Update-LapsADSchemaandSet-LapsADComputerSelfPermission -Identity '<OU>', then set Group Policy → Administrative Templates → System → LAPS → 'Configure password backup directory' = Active Directory. - Confirm a password was stored with
Get-LapsAADPasswordorGet-LapsADPassword.
Maps to:
AC.L2-3.1.5Employ the principle of least privilegeIA.L2-3.5.10Store and transmit only cryptographically-protected passwords
ACC-009 · User Account Control is enabled¶
Fix: Set EnableLUA to 1 and require consent or credentials for elevation.
Take the helm: step-by-step
- Group Policy Security Options: 'User Account Control: Run all administrators in Admin Approval Mode' = Enabled and 'Behavior of the elevation prompt for administrators' = 'Prompt for consent on the secure desktop'.
- On a single device:
Set-ItemProperty HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System -Name EnableLUA -Value 1, then restart.
Maps to:
AC.L2-3.1.7Prevent non-privileged users from executing privileged functions164.312(a)(1)Access control
Sessions¶
SES-001 · Screen locks after inactivity¶
Fix: Set the machine inactivity limit (InactivityTimeoutSecs) to 900 seconds or less.
Default thresholds: Maximum idle time (seconds) = 900
Take the helm: step-by-step
- Group Policy Security Options: 'Interactive logon: Machine inactivity limit' = 900 seconds or less.
- Intune: Settings catalog → Local Policies Security Options → 'Interactive Logon Machine Inactivity Limit'.
- On a single device:
Set-ItemProperty HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System -Name InactivityTimeoutSecs -Value 900 -Type DWord.
Maps to:
AC.L2-3.1.10Use session lock with pattern-hiding displays164.312(a)(2)(iii)Automatic logoff
SES-002 · Logon banner is displayed¶
Fix: Configure 'Interactive logon: Message title and text for users attempting to log on'.
Take the helm: step-by-step
- Write a short notice, for example: 'Authorized use only. Activity on this system is monitored.'
- Group Policy Security Options: set 'Interactive logon: Message title for users attempting to log on' and 'Message text for users attempting to log on'.
- Intune: Settings catalog → Local Policies Security Options → Interactive Logon Message Title and Message Text.
Maps to:
AC.L2-3.1.9Provide privacy and security notices
SES-003 · Remote Desktop requires Network Level Authentication¶
Fix: Disable RDP if not needed. If needed, require NLA and restrict access to a VPN or gateway.
Take the helm: step-by-step
- If Remote Desktop isn't needed, turn it off: Settings → System → Remote Desktop → Off.
- If it is needed, require NLA: Group Policy → Windows Components → Remote Desktop Services → Remote Desktop Session Host → Security → 'Require user authentication for remote connections by using Network Level Authentication' = Enabled.
- On a single device:
Set-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -Value 1. - Limit who can connect, and reach RDP only through a VPN or gateway.
Maps to:
AC.L2-3.1.12Monitor and control remote access sessions164.312(e)(1)Transmission security
Hardening¶
HRD-001 · SMBv1 is disabled¶
Fix: Disable the SMB1Protocol feature and set EnableSMB1Protocol to false.
Take the helm: step-by-step
- Check that no old printers, scanners, or NAS devices still need SMBv1.
- Remove it:
Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol -NoRestartandSet-SmbServerConfiguration -EnableSMB1Protocol $false -Force. - Restart the device.
Maps to:
CM.L2-3.4.6Employ the principle of least functionalityCM.L2-3.4.7Restrict nonessential programs, functions, ports, protocols, and services
HRD-002 · LLMNR is disabled¶
Fix: Set 'Turn off multicast name resolution' to Enabled.
Take the helm: step-by-step
- Group Policy: Administrative Templates → Network → DNS Client → 'Turn off multicast name resolution' = Enabled.
- On a single device:
New-Item 'HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient' -Force | Out-Null; Set-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient' -Name EnableMulticast -Value 0 -Type DWord.
Maps to:
CM.L2-3.4.7Restrict nonessential programs, functions, ports, protocols, and services
HRD-003 · NetBIOS over TCP/IP is disabled¶
Fix: Set NetbiosOptions to 2 on all interfaces, or disable through DHCP option.
Take the helm: step-by-step
- Make sure no legacy app relies on NetBIOS name resolution.
- Through DHCP (Windows Server): set scope option 001 'Microsoft Disable Netbios Option' to 0x2.
- On a single device:
Get-ChildItem HKLM:\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces | ForEach-Object { Set-ItemProperty $_.PSPath -Name NetbiosOptions -Value 2 }.
Maps to:
CM.L2-3.4.7Restrict nonessential programs, functions, ports, protocols, and services
HRD-004 · AutoRun is disabled for all drives¶
Fix: Set NoDriveTypeAutoRun to 255 and NoAutorun to 1.
Take the helm: step-by-step
- Group Policy: Administrative Templates → Windows Components → AutoPlay Policies → 'Turn off Autoplay' = Enabled for All drives, and 'Set the default behavior for AutoRun' = Do not execute any autorun commands.
- On a single device:
Set-ItemProperty HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer -Name NoDriveTypeAutoRun -Value 255 -Type DWord.
Maps to:
CM.L2-3.4.6Employ the principle of least functionalitySI.L2-3.14.2Provide protection from malicious code
HRD-005 · Removable storage is restricted¶
Fix: Block or make read-only removable storage through policy or EDR device control.
Take the helm: step-by-step
- If your EDR handles device control (for example SentinelOne or Defender for Endpoint), enforce it there and document it as the control.
- Otherwise, Group Policy or Intune Settings catalog: Administrative Templates → System → Removable Storage Access → 'All Removable Storage classes: Deny all access' (or deny write only).
- Allow exceptions for approved encrypted drives if needed.
Maps to:
MP.L2-3.8.7Control the use of removable media on system components
HRD-006 · FIPS-compliant algorithms are enforced¶
Fix: Enable 'System cryptography: Use FIPS compliant algorithms'. Test application impact first.
Take the helm: step-by-step
- Test first: some older apps and protocols break in FIPS mode.
- Group Policy Security Options: 'System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing' = Enabled.
- On a single device:
Set-ItemProperty HKLM:\SYSTEM\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy -Name Enabled -Value 1. - If you can't enable it, document that CUI is protected with FIPS-validated modules (BitLocker, TLS) as your approach to 3.13.11.
Maps to:
SC.L2-3.13.11Employ FIPS-validated cryptography to protect CUI
HRD-007 · LSA protection is enabled¶
Fix: Set RunAsPPL to 1 under HKLM\SYSTEM\CurrentControlSet\Control\Lsa.
Take the helm: step-by-step
- Check for unsigned LSA plug-ins (smart card or password filters) in the CodeIntegrity event log before enforcing.
- Intune: Settings catalog → Local Security Authority → 'Configure LSA to run as a protected process' = Enabled with UEFI lock.
- On a single device:
Set-ItemProperty HKLM:\SYSTEM\CurrentControlSet\Control\Lsa -Name RunAsPPL -Value 1 -Type DWord, then restart.
Maps to:
IA.L2-3.5.10Store and transmit only cryptographically-protected passwords
HRD-008 · Credential Guard is running¶
Fix: Enable Virtualization-based Security with Credential Guard.
Take the helm: step-by-step
- Make sure UEFI, Secure Boot, and CPU virtualization (VT-x or AMD-V) are on in the firmware.
- Intune: Endpoint security → Account protection → Credential Guard = Enable with UEFI lock. Group Policy: Administrative Templates → System → Device Guard → 'Turn On Virtualization Based Security' with Credential Guard enabled.
- Restart and confirm in
msinfo32that Credential Guard is listed under Virtualization-based security Services Running.
Maps to:
IA.L2-3.5.10Store and transmit only cryptographically-protected passwords
HRD-009 · WDigest does not cache plaintext credentials¶
Fix: Set UseLogonCredential to 0 under WDigest.
Take the helm: step-by-step
- Set UseLogonCredential to 0:
Set-ItemProperty HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest -Name UseLogonCredential -Value 0 -Type DWord. - For many devices, use the MS Security Guide Group Policy template setting 'WDigest Authentication' = Disabled.
Maps to:
IA.L2-3.5.10Store and transmit only cryptographically-protected passwords164.312(d)Person or entity authentication
Audit¶
AUD-001 · Key audit subcategories are enabled¶
Fix: Apply an advanced audit policy covering logon, lockout, credential validation, account and group management, process creation, and policy change.
Take the helm: step-by-step
- Group Policy: Security Settings → Advanced Audit Policy Configuration. Set Credential Validation, Logon, User Account Management, and Sensitive Privilege Use to Success and Failure; Account Lockout to Failure; Security Group Management, Process Creation, and Audit Policy Change to Success.
- Also set Security Options → 'Audit: Force audit policy subcategory settings to override audit policy category settings' = Enabled.
- On a single device, for example:
auditpol /set /subcategory:"Logon" /success:enable /failure:enable.
Maps to:
AU.L2-3.3.1Create and retain system audit logsAU.L2-3.3.2Ensure actions of individual users can be traced164.312(b)Audit controls164.308(a)(5)(ii)(C)Log-in monitoring
AUD-002 · Security event log is large enough¶
Fix: Set the Security log maximum size to 196,608 KB or more, and forward logs to a central store.
Default thresholds: Minimum Security log size (KB) = 196608
Take the helm: step-by-step
- Group Policy: Administrative Templates → Windows Components → Event Log Service → Security → 'Specify the maximum log file size (KB)' = 196608.
- On a single device:
wevtutil sl Security /ms:201326592. - Forward logs to a SIEM or Log Analytics so they're kept off the device as well.
Maps to:
AU.L2-3.3.1Create and retain system audit logs164.312(b)Audit controls
AUD-003 · PowerShell script block logging is on¶
Fix: Enable 'Turn on PowerShell Script Block Logging'.
Take the helm: step-by-step
- Group Policy: Administrative Templates → Windows Components → Windows PowerShell → 'Turn on PowerShell Script Block Logging' = Enabled.
- On a single device:
New-Item HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging -Force | Out-Null; Set-ItemProperty HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging -Name EnableScriptBlockLogging -Value 1.
Maps to:
AU.L2-3.3.1Create and retain system audit logsAU.L2-3.3.2Ensure actions of individual users can be traced164.312(b)Audit controls
AUD-004 · Process creation events include command line¶
Fix: Enable 'Include command line in process creation events'.
Take the helm: step-by-step
- Group Policy: Administrative Templates → System → Audit Process Creation → 'Include command line in process creation events' = Enabled.
- Make sure Process Creation auditing is on as well (see AUD-001).
Maps to:
AU.L2-3.3.2Ensure actions of individual users can be traced
AUD-005 · Time synchronization is running¶
Fix: Set the Windows Time service to start automatically and sync to the domain hierarchy or a trusted NTP source.
Take the helm: step-by-step
- Start the time service:
Set-Service W32Time -StartupType Automatic; Start-Service W32Time. - Domain-joined devices sync from the domain automatically. Others:
w32tm /config /manualpeerlist:time.windows.com /syncfromflags:manual /update, thenw32tm /resync. - Confirm with
w32tm /query /status.
Maps to:
AU.L2-3.3.7Synchronize system clocks with an authoritative source
Patching¶
PAT-001 · Updates installed recently¶
Fix: Investigate why updates are not installing and apply the latest cumulative update.
Default thresholds: Maximum days since last update = 35
Take the helm: step-by-step
- Open Settings → Windows Update → Update history and look for failed updates.
- Make sure an update policy (Intune update rings, WSUS, or your RMM) targets this device and isn't paused.
- If updates keep failing, free up disk space, restart, and run
DISM /Online /Cleanup-Image /RestoreHealthandsfc /scannow.
Maps to:
SI.L2-3.14.1Identify, report, and correct system flaws in a timely manner164.308(a)(1)(ii)(B)Risk management
PAT-002 · No reboot pending¶
Fix: Reboot the device to finish installing updates.
Take the helm: step-by-step
- Restart the device to finish installing updates.
- Use maintenance windows or Intune update ring deadlines so devices that stay on still restart.
Maps to:
SI.L2-3.14.1Identify, report, and correct system flaws in a timely manner
PAT-003 · Operating system is supported¶
Fix: Upgrade to a supported Windows release before end of servicing.
Default thresholds: Warn this many days before end of support = 60
Take the helm: step-by-step
- Check hardware compatibility (TPM 2.0, supported CPU) with the PC Health Check app.
- Upgrade to a supported Windows release with Windows Update, an Intune feature update policy, or the Installation Assistant.
- If the device can't be upgraded, enroll it in Extended Security Updates where available, or replace it.
Maps to:
SI.L2-3.14.1Identify, report, and correct system flaws in a timely manner164.308(a)(1)(ii)(B)Risk management