Skip to content

Device checks

Lookout runs these 37 read-only checks on every Windows device. Each one maps to the CMMC and HIPAA requirements it helps prove. Thresholds marked default can be adjusted to match your policy.

ID Check Severity Standards
ENC-001 BitLocker protects all fixed drives High CMMC, HIPAA
ENC-002 TPM is present and ready Medium CMMC
ENC-003 Secure Boot is enabled Medium CMMC
AV-001 Antivirus real-time protection is active High CMMC, HIPAA
AV-002 Antivirus signatures are current High CMMC, HIPAA
AV-003 Defender tamper protection is on Medium CMMC
AV-004 Attack surface reduction rules are configured Medium CMMC
FW-001 Windows Firewall is on for all profiles High CMMC, HIPAA
ACC-001 No standing local admin rights for user accounts High CMMC, HIPAA
ACC-002 Guest account is disabled Medium CMMC, HIPAA
ACC-003 Built-in Administrator account is disabled Low CMMC
ACC-004 Account lockout threshold is set High CMMC, HIPAA
ACC-005 Minimum password length is enforced Medium CMMC, HIPAA
ACC-006 Password complexity is required Medium CMMC, HIPAA
ACC-007 Password history prevents reuse Low CMMC, HIPAA
ACC-008 Local admin password is managed (LAPS) Medium CMMC
ACC-009 User Account Control is enabled High CMMC, HIPAA
SES-001 Screen locks after inactivity Medium CMMC, HIPAA
SES-002 Logon banner is displayed Low CMMC
SES-003 Remote Desktop requires Network Level Authentication High CMMC, HIPAA
HRD-001 SMBv1 is disabled High CMMC
HRD-002 LLMNR is disabled Medium CMMC
HRD-003 NetBIOS over TCP/IP is disabled Low CMMC
HRD-004 AutoRun is disabled for all drives Medium CMMC
HRD-005 Removable storage is restricted Medium CMMC
HRD-006 FIPS-compliant algorithms are enforced Low CMMC
HRD-007 LSA protection is enabled Medium CMMC
HRD-008 Credential Guard is running Medium CMMC
HRD-009 WDigest does not cache plaintext credentials High CMMC, HIPAA
AUD-001 Key audit subcategories are enabled High CMMC, HIPAA
AUD-002 Security event log is large enough Medium CMMC, HIPAA
AUD-003 PowerShell script block logging is on Medium CMMC, HIPAA
AUD-004 Process creation events include command line Low CMMC
AUD-005 Time synchronization is running Low CMMC
PAT-001 Updates installed recently High CMMC, HIPAA
PAT-002 No reboot pending Low CMMC
PAT-003 Operating system is supported High CMMC, HIPAA

Encryption

ENC-001 · BitLocker protects all fixed drives

High Encryption

Fix: Enable BitLocker with TPM protector on the OS drive and all fixed data drives, and escrow the recovery key.

Take the helm: step-by-step
  1. For many devices, use Intune: Endpoint security → Disk encryption → create a BitLocker policy that encrypts OS and fixed drives and backs up recovery keys to Entra ID.
  2. On a single device, open an elevated PowerShell and run Enable-BitLocker -MountPoint C: -EncryptionMethod XtsAes256 -TpmProtector.
  3. Add a recovery password with Add-BitLockerKeyProtector -MountPoint C: -RecoveryPasswordProtector and back it up with BackupToAAD-BitLockerKeyProtector (Entra ID) or Backup-BitLockerKeyProtector (Active Directory) before restarting.
  4. Repeat for each fixed data drive, then confirm with Get-BitLockerVolume.

Maps to:

ENC-002 · TPM is present and ready

Medium Encryption

Fix: Enable the TPM in firmware and initialize it.

Take the helm: step-by-step
  1. Restart into the firmware setup (often F2, F10, or Del during boot).
  2. Enable the TPM. It may be called Intel PTT or AMD fTPM. Save and exit.
  3. Back in Windows, run Get-Tpm and confirm TpmPresent and TpmReady are True. If it isn't ready, run Initialize-Tpm.
  4. If the device has no TPM, plan a replacement. Windows 11 requires TPM 2.0.

Maps to:

  • SC.L2-3.13.16 Protect the confidentiality of CUI at rest
  • CM.L2-3.4.2 Establish and enforce security configuration settings

ENC-003 · Secure Boot is enabled

Medium Encryption

Fix: Switch firmware to UEFI mode and enable Secure Boot.

Take the helm: step-by-step
  1. If BitLocker is on, suspend it for one restart first: Suspend-BitLocker -MountPoint C: -RebootCount 1.
  2. Check the disk style with Get-Disk. If it's MBR, back up and convert it with mbr2gpt /convert /allowFullOS.
  3. In the firmware setup, switch the boot mode to UEFI (turn off CSM or Legacy) and enable Secure Boot.
  4. Confirm in Windows with Confirm-SecureBootUEFI.

Maps to:

  • CM.L2-3.4.2 Establish and enforce security configuration settings

Malware Protection

AV-001 · Antivirus real-time protection is active

High Malware Protection

Fix: Enable Defender real-time protection or confirm a third-party AV is installed and running.

Take the helm: step-by-step
  1. Microsoft Defender: Windows Security → Virus & threat protection → Manage settings → turn on Real-time protection, or run Set-MpPreference -DisableRealtimeMonitoring $false.
  2. Check that no Group Policy or Intune setting turns Defender off (Administrative Templates → Windows Components → Microsoft Defender Antivirus).
  3. Third-party antivirus: open its console, confirm the device's agent is installed and protecting, and reinstall the agent if it shows offline.

Maps to:

AV-002 · Antivirus signatures are current

High Malware Protection

Fix: Confirm the device can reach update sources and run a signature update.

Default thresholds: Maximum signature age (days) = 3

Take the helm: step-by-step
  1. Update now with Update-MpSignature (Defender) or the update action in your antivirus console.
  2. Make sure the device can reach its update source and that no proxy or firewall blocks it.
  3. Confirm the signatures are current with Get-MpComputerStatus | Select-Object AntivirusSignatureAge.

Maps to:

AV-003 · Defender tamper protection is on

Medium Malware Protection

Fix: Turn on tamper protection through Intune, Defender for Endpoint, or Windows Security.

Take the helm: step-by-step
  1. For all devices, turn on tamper protection in the Microsoft Defender portal (Settings → Endpoints → Advanced features) or with an Intune Endpoint security → Antivirus policy.
  2. On a single unmanaged device: Windows Security → Virus & threat protection → Manage settings → Tamper Protection: On.
  3. Confirm with Get-MpComputerStatus | Select-Object IsTamperProtected.

Maps to:

AV-004 · Attack surface reduction rules are configured

Medium Malware Protection

Fix: Deploy the standard ASR rule set in Block mode after an Audit period.

Default thresholds: Minimum ASR rules in Block mode = 5

Take the helm: step-by-step
  1. In Intune, create an Endpoint security → Attack surface reduction policy with the standard rules set to Audit.
  2. Review what would have been blocked in the Defender portal (Reports → Attack surface reduction rules) for one to two weeks.
  3. Switch the rules to Block, adding exclusions only where a business app needs one.
  4. On a single device: Add-MpPreference -AttackSurfaceReductionRules_Ids <rule GUID> -AttackSurfaceReductionRules_Actions Enabled.

Maps to:

  • SI.L2-3.14.2 Provide protection from malicious code
  • CM.L2-3.4.2 Establish and enforce security configuration settings

Network

FW-001 · Windows Firewall is on for all profiles

High Network

Fix: Enable the firewall for Domain, Private, and Public profiles with inbound default set to Block.

Take the helm: step-by-step
  1. Turn on the firewall for every profile: Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled True -DefaultInboundAction Block.
  2. For many devices, use Intune (Endpoint security → Firewall) or Group Policy (Security Settings → Windows Defender Firewall with Advanced Security).
  3. Make sure no policy turns it back off: Get-NetFirewallProfile -PolicyStore ActiveStore.

Maps to:

Accounts

ACC-001 · No standing local admin rights for user accounts

High Accounts

Fix: Remove user accounts from the local Administrators group. Use LAPS or just-in-time elevation for admin tasks.

Take the helm: step-by-step
  1. List current admins: Get-LocalGroupMember -Group Administrators.
  2. Before removing anyone, make sure another admin path works, such as LAPS or a domain admin group.
  3. Remove user accounts that don't need standing admin rights: Remove-LocalGroupMember -Group Administrators -Member 'DOMAIN\user'.
  4. Manage membership centrally (Intune: Endpoint security → Account protection → Local user group membership, or Group Policy Restricted Groups) so it doesn't drift back.

Maps to:

ACC-002 · Guest account is disabled

Medium Accounts

Fix: Disable the built-in Guest account.

Take the helm: step-by-step
  1. Disable the Guest account: Get-LocalUser | Where-Object SID -like '*-501' | Disable-LocalUser.
  2. For many devices, set Group Policy Security Options → 'Accounts: Guest account status' to Disabled.

Maps to:

ACC-003 · Built-in Administrator account is disabled

Low Accounts

Fix: Disable the built-in Administrator (RID 500) account, or manage it with LAPS.

Take the helm: step-by-step
  1. Confirm another admin account works first.
  2. Disable the built-in Administrator: Get-LocalUser | Where-Object SID -like '*-500' | Disable-LocalUser.
  3. For many devices, set Group Policy Security Options → 'Accounts: Administrator account status' to Disabled. If LAPS manages this account, document that instead.

Maps to:

ACC-004 · Account lockout threshold is set

High Accounts

Fix: Set the account lockout threshold between 1 and 10 invalid attempts with a lockout duration of 15+ minutes.

Default thresholds: Maximum lockout threshold = 10

Take the helm: step-by-step
  1. Group Policy: Computer Configuration → Windows Settings → Security Settings → Account Policies → Account Lockout Policy. Set the threshold to 5–10 attempts and the duration and reset counter to 15 minutes.
  2. On a single device: net accounts /lockoutthreshold:10 /lockoutduration:15 /lockoutwindow:15.
  3. Domain accounts follow the domain's policy (Default Domain Policy), so set it there as well.

Maps to:

ACC-005 · Minimum password length is enforced

Medium Accounts

Fix: Set the minimum password length to 14 characters or more.

Default thresholds: Minimum password length = 14

Take the helm: step-by-step
  1. Group Policy: Account Policies → Password Policy → Minimum password length = 14.
  2. On a single device: net accounts /minpwlen:14.
  3. On Entra-joined devices this covers local accounts only; cloud account passwords follow Entra ID policy.

Maps to:

ACC-006 · Password complexity is required

Medium Accounts

Fix: Enable 'Password must meet complexity requirements'.

Take the helm: step-by-step
  1. Group Policy: Account Policies → Password Policy → 'Password must meet complexity requirements' = Enabled.
  2. On a single device, set the same option in Local Security Policy (secpol.msc).

Maps to:

ACC-007 · Password history prevents reuse

Low Accounts

Fix: Set 'Enforce password history' to 24 or more.

Default thresholds: Passwords remembered = 24

Take the helm: step-by-step
  1. Group Policy: Account Policies → Password Policy → 'Enforce password history' = 24.
  2. On a single device: net accounts /uniquepw:24.

Maps to:

ACC-008 · Local admin password is managed (LAPS)

Medium Accounts

Fix: Deploy Windows LAPS with backup to Entra ID or Active Directory.

Take the helm: step-by-step
  1. Entra-joined devices: Intune → Endpoint security → Account protection → create a Windows LAPS policy with Backup directory = Azure AD (Entra ID).
  2. Active Directory: run Update-LapsADSchema and Set-LapsADComputerSelfPermission -Identity '<OU>', then set Group Policy → Administrative Templates → System → LAPS → 'Configure password backup directory' = Active Directory.
  3. Confirm a password was stored with Get-LapsAADPassword or Get-LapsADPassword.

Maps to:

  • AC.L2-3.1.5 Employ the principle of least privilege
  • IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords

ACC-009 · User Account Control is enabled

High Accounts

Fix: Set EnableLUA to 1 and require consent or credentials for elevation.

Take the helm: step-by-step
  1. Group Policy Security Options: 'User Account Control: Run all administrators in Admin Approval Mode' = Enabled and 'Behavior of the elevation prompt for administrators' = 'Prompt for consent on the secure desktop'.
  2. On a single device: Set-ItemProperty HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System -Name EnableLUA -Value 1, then restart.

Maps to:

Sessions

SES-001 · Screen locks after inactivity

Medium Sessions

Fix: Set the machine inactivity limit (InactivityTimeoutSecs) to 900 seconds or less.

Default thresholds: Maximum idle time (seconds) = 900

Take the helm: step-by-step
  1. Group Policy Security Options: 'Interactive logon: Machine inactivity limit' = 900 seconds or less.
  2. Intune: Settings catalog → Local Policies Security Options → 'Interactive Logon Machine Inactivity Limit'.
  3. On a single device: Set-ItemProperty HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System -Name InactivityTimeoutSecs -Value 900 -Type DWord.

Maps to:

SES-002 · Logon banner is displayed

Low Sessions

Fix: Configure 'Interactive logon: Message title and text for users attempting to log on'.

Take the helm: step-by-step
  1. Write a short notice, for example: 'Authorized use only. Activity on this system is monitored.'
  2. Group Policy Security Options: set 'Interactive logon: Message title for users attempting to log on' and 'Message text for users attempting to log on'.
  3. Intune: Settings catalog → Local Policies Security Options → Interactive Logon Message Title and Message Text.

Maps to:

SES-003 · Remote Desktop requires Network Level Authentication

High Sessions

Fix: Disable RDP if not needed. If needed, require NLA and restrict access to a VPN or gateway.

Take the helm: step-by-step
  1. If Remote Desktop isn't needed, turn it off: Settings → System → Remote Desktop → Off.
  2. If it is needed, require NLA: Group Policy → Windows Components → Remote Desktop Services → Remote Desktop Session Host → Security → 'Require user authentication for remote connections by using Network Level Authentication' = Enabled.
  3. On a single device: Set-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -Value 1.
  4. Limit who can connect, and reach RDP only through a VPN or gateway.

Maps to:

Hardening

HRD-001 · SMBv1 is disabled

High Hardening

Fix: Disable the SMB1Protocol feature and set EnableSMB1Protocol to false.

Take the helm: step-by-step
  1. Check that no old printers, scanners, or NAS devices still need SMBv1.
  2. Remove it: Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol -NoRestart and Set-SmbServerConfiguration -EnableSMB1Protocol $false -Force.
  3. Restart the device.

Maps to:

  • CM.L2-3.4.6 Employ the principle of least functionality
  • CM.L2-3.4.7 Restrict nonessential programs, functions, ports, protocols, and services

HRD-002 · LLMNR is disabled

Medium Hardening

Fix: Set 'Turn off multicast name resolution' to Enabled.

Take the helm: step-by-step
  1. Group Policy: Administrative Templates → Network → DNS Client → 'Turn off multicast name resolution' = Enabled.
  2. On a single device: New-Item 'HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient' -Force | Out-Null; Set-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient' -Name EnableMulticast -Value 0 -Type DWord.

Maps to:

  • CM.L2-3.4.7 Restrict nonessential programs, functions, ports, protocols, and services

HRD-003 · NetBIOS over TCP/IP is disabled

Low Hardening

Fix: Set NetbiosOptions to 2 on all interfaces, or disable through DHCP option.

Take the helm: step-by-step
  1. Make sure no legacy app relies on NetBIOS name resolution.
  2. Through DHCP (Windows Server): set scope option 001 'Microsoft Disable Netbios Option' to 0x2.
  3. On a single device: Get-ChildItem HKLM:\SYSTEM\CurrentControlSet\Services\NetBT\Parameters\Interfaces | ForEach-Object { Set-ItemProperty $_.PSPath -Name NetbiosOptions -Value 2 }.

Maps to:

  • CM.L2-3.4.7 Restrict nonessential programs, functions, ports, protocols, and services

HRD-004 · AutoRun is disabled for all drives

Medium Hardening

Fix: Set NoDriveTypeAutoRun to 255 and NoAutorun to 1.

Take the helm: step-by-step
  1. Group Policy: Administrative Templates → Windows Components → AutoPlay Policies → 'Turn off Autoplay' = Enabled for All drives, and 'Set the default behavior for AutoRun' = Do not execute any autorun commands.
  2. On a single device: Set-ItemProperty HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer -Name NoDriveTypeAutoRun -Value 255 -Type DWord.

Maps to:

HRD-005 · Removable storage is restricted

Medium Hardening

Fix: Block or make read-only removable storage through policy or EDR device control.

Take the helm: step-by-step
  1. If your EDR handles device control (for example SentinelOne or Defender for Endpoint), enforce it there and document it as the control.
  2. Otherwise, Group Policy or Intune Settings catalog: Administrative Templates → System → Removable Storage Access → 'All Removable Storage classes: Deny all access' (or deny write only).
  3. Allow exceptions for approved encrypted drives if needed.

Maps to:

  • MP.L2-3.8.7 Control the use of removable media on system components

HRD-006 · FIPS-compliant algorithms are enforced

Low Hardening

Fix: Enable 'System cryptography: Use FIPS compliant algorithms'. Test application impact first.

Take the helm: step-by-step
  1. Test first: some older apps and protocols break in FIPS mode.
  2. Group Policy Security Options: 'System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing' = Enabled.
  3. On a single device: Set-ItemProperty HKLM:\SYSTEM\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy -Name Enabled -Value 1.
  4. If you can't enable it, document that CUI is protected with FIPS-validated modules (BitLocker, TLS) as your approach to 3.13.11.

Maps to:

  • SC.L2-3.13.11 Employ FIPS-validated cryptography to protect CUI

HRD-007 · LSA protection is enabled

Medium Hardening

Fix: Set RunAsPPL to 1 under HKLM\SYSTEM\CurrentControlSet\Control\Lsa.

Take the helm: step-by-step
  1. Check for unsigned LSA plug-ins (smart card or password filters) in the CodeIntegrity event log before enforcing.
  2. Intune: Settings catalog → Local Security Authority → 'Configure LSA to run as a protected process' = Enabled with UEFI lock.
  3. On a single device: Set-ItemProperty HKLM:\SYSTEM\CurrentControlSet\Control\Lsa -Name RunAsPPL -Value 1 -Type DWord, then restart.

Maps to:

  • IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords

HRD-008 · Credential Guard is running

Medium Hardening

Fix: Enable Virtualization-based Security with Credential Guard.

Take the helm: step-by-step
  1. Make sure UEFI, Secure Boot, and CPU virtualization (VT-x or AMD-V) are on in the firmware.
  2. Intune: Endpoint security → Account protection → Credential Guard = Enable with UEFI lock. Group Policy: Administrative Templates → System → Device Guard → 'Turn On Virtualization Based Security' with Credential Guard enabled.
  3. Restart and confirm in msinfo32 that Credential Guard is listed under Virtualization-based security Services Running.

Maps to:

  • IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords

HRD-009 · WDigest does not cache plaintext credentials

High Hardening

Fix: Set UseLogonCredential to 0 under WDigest.

Take the helm: step-by-step
  1. Set UseLogonCredential to 0: Set-ItemProperty HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest -Name UseLogonCredential -Value 0 -Type DWord.
  2. For many devices, use the MS Security Guide Group Policy template setting 'WDigest Authentication' = Disabled.

Maps to:

  • IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords
  • 164.312(d) Person or entity authentication

Audit

AUD-001 · Key audit subcategories are enabled

High Audit

Fix: Apply an advanced audit policy covering logon, lockout, credential validation, account and group management, process creation, and policy change.

Take the helm: step-by-step
  1. Group Policy: Security Settings → Advanced Audit Policy Configuration. Set Credential Validation, Logon, User Account Management, and Sensitive Privilege Use to Success and Failure; Account Lockout to Failure; Security Group Management, Process Creation, and Audit Policy Change to Success.
  2. Also set Security Options → 'Audit: Force audit policy subcategory settings to override audit policy category settings' = Enabled.
  3. On a single device, for example: auditpol /set /subcategory:"Logon" /success:enable /failure:enable.

Maps to:

AUD-002 · Security event log is large enough

Medium Audit

Fix: Set the Security log maximum size to 196,608 KB or more, and forward logs to a central store.

Default thresholds: Minimum Security log size (KB) = 196608

Take the helm: step-by-step
  1. Group Policy: Administrative Templates → Windows Components → Event Log Service → Security → 'Specify the maximum log file size (KB)' = 196608.
  2. On a single device: wevtutil sl Security /ms:201326592.
  3. Forward logs to a SIEM or Log Analytics so they're kept off the device as well.

Maps to:

AUD-003 · PowerShell script block logging is on

Medium Audit

Fix: Enable 'Turn on PowerShell Script Block Logging'.

Take the helm: step-by-step
  1. Group Policy: Administrative Templates → Windows Components → Windows PowerShell → 'Turn on PowerShell Script Block Logging' = Enabled.
  2. On a single device: New-Item HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging -Force | Out-Null; Set-ItemProperty HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging -Name EnableScriptBlockLogging -Value 1.

Maps to:

AUD-004 · Process creation events include command line

Low Audit

Fix: Enable 'Include command line in process creation events'.

Take the helm: step-by-step
  1. Group Policy: Administrative Templates → System → Audit Process Creation → 'Include command line in process creation events' = Enabled.
  2. Make sure Process Creation auditing is on as well (see AUD-001).

Maps to:

  • AU.L2-3.3.2 Ensure actions of individual users can be traced

AUD-005 · Time synchronization is running

Low Audit

Fix: Set the Windows Time service to start automatically and sync to the domain hierarchy or a trusted NTP source.

Take the helm: step-by-step
  1. Start the time service: Set-Service W32Time -StartupType Automatic; Start-Service W32Time.
  2. Domain-joined devices sync from the domain automatically. Others: w32tm /config /manualpeerlist:time.windows.com /syncfromflags:manual /update, then w32tm /resync.
  3. Confirm with w32tm /query /status.

Maps to:

  • AU.L2-3.3.7 Synchronize system clocks with an authoritative source

Patching

PAT-001 · Updates installed recently

High Patching

Fix: Investigate why updates are not installing and apply the latest cumulative update.

Default thresholds: Maximum days since last update = 35

Take the helm: step-by-step
  1. Open Settings → Windows Update → Update history and look for failed updates.
  2. Make sure an update policy (Intune update rings, WSUS, or your RMM) targets this device and isn't paused.
  3. If updates keep failing, free up disk space, restart, and run DISM /Online /Cleanup-Image /RestoreHealth and sfc /scannow.

Maps to:

PAT-002 · No reboot pending

Low Patching

Fix: Reboot the device to finish installing updates.

Take the helm: step-by-step
  1. Restart the device to finish installing updates.
  2. Use maintenance windows or Intune update ring deadlines so devices that stay on still restart.

Maps to:

  • SI.L2-3.14.1 Identify, report, and correct system flaws in a timely manner

PAT-003 · Operating system is supported

High Patching

Fix: Upgrade to a supported Windows release before end of servicing.

Default thresholds: Warn this many days before end of support = 60

Take the helm: step-by-step
  1. Check hardware compatibility (TPM 2.0, supported CPU) with the PC Health Check app.
  2. Upgrade to a supported Windows release with Windows Update, an Intune feature update policy, or the Installation Assistant.
  3. If the device can't be upgraded, enroll it in Extended Security Updates where available, or replace it.

Maps to: