Files
Chris Thompson c0272c587a Merge pull request #48 from DocumentationDave/MatrixCleanup
Align SCCM technique mappings and matrix; add CSV source of truth
2026-04-22 10:09:36 -04:00
..
2024-03-08 01:11:25 -05:00

Codename Description Admin Roles
CANARY1 Configure an appropriately-privileged NAA with interactive logon restricted SCCM, domain
DETECT1 Monitor site server domain computer accounts authenticating from another source Security
DETECT2 Monitor read access to the System Management Active Directory container Security
DETECT3 Monitor client push installation accounts authenticating from anywhere other than the primary site server Security
DETECT4 Monitor application deployment logs in the site's Audit Status Messages SCCM, security
DETECT5 Monitor group membership changes for SMS Admins SCCM, server, security
DETECT6 Monitor group membership changes for RBAC_Admins table SCCM, server, security
DETECT7 Monitor read access to the SMSTemp directory SCCM, server, security
DETECT8 Monitor connections to winreg named pipe SCCM, server, security
DETECT9 Monitor local object access for local SCCM logs and settings SCCM, server, security
PREVENT1 Patch site server with KB15599094 SCCM, server
PREVENT2 Disable Fallback to NTLM SCCM
PREVENT3 Harden or disable network access accounts SCCM, domain, security
PREVENT4 Configure Enhanced HTTP SCCM
PREVENT5 Disable automatic side-wide client push installation SCCM
PREVENT6 Configure a strong PXE boot password SCCM
PREVENT7 Disable command support in PXE boot configuration SCCM
PREVENT8 Require PKI certificates for client authentation SCCM, network, security, server, domain
PREVENT9 Enforce MFA for SMS Provider calls SCCM
PREVENT10 Enforce the principle of least privilege for accounts SCCM, domain, server, security
PREVENT11 Disable and uninstall WebClient on site servers SCCM, server
PREVENT12 Require SMB signing on site systems Domain, server, SCCM
PREVENT13 Require LDAP channel binding and signing Domain, server
PREVENT14 Require EPA on AD CS and site databases Domain, security, SCCM, server, database
PREVENT15 Disable and change passwords of legacy NAAs and collection variables/task sequence secrets in Active Directory Domain, SCCM
PREVENT16 Remove SeMachineAccountPrivilege and set MachineAccountQuota to 0 for non-admin accounts Domain
PREVENT17 Remove Extended Rights assignment from accounts that do not require it Domain, desktop
PREVENT18 Use strong passwords for DBA accounts Database, security, domain
PREVENT19 Remove unnecessary links to site databases SCCM, database
PREVENT20 Block unnecessary connections to site systems Network, server
PREVENT21 Restrict PXE boot to authorized VLANs SCCM, network
PREVENT22 Do not manage assets in two or more segmented forests, domains, networks, or security tiers SCCM, network, security, domain
PREVENT23 Ensure the SCCM client cache directory (ccmcache) is not writable or renameable by non-administrative users SCCM, desktop, security