Help Windows Security Assesment, Item not found- Windows Server 2019

Anonymous
2023-11-29T10:45:44+00:00

Need help to fix this issue on windows server 2019, item/options not found

i have installed all admx on this link: https://learn.microsoft.com/en-US/troubleshoot/windows-client/group-policy/create-and-manage-central-store

but item/options still not found, please help me.

18.6.4.1 Ensure 'Configure NetBIOS settings' is set to 'Enabled Disable NetBIOS name resolution on public networks' - Enabled Disable NetBIOS name resolution on public networks

18.7.3 Ensure 'Configure RPC connection settings: Protocol to use for outgoing RPC connections' is set to 'Enabled: RPC over TCP'

18.7.4 Ensure 'Configure RPC connection settings Use authentication for outgoing RPC connections' is set to 'Enabled Default'

18.7.5 Ensure 'Configure RPC listener settings Protocols to allow for incoming RPC connections' is set to 'Enabled RPC over TCP'

18.7.7 Ensure 'Configure RPC over TCP port' is set to 'Enabled 0'

18.7.9 Ensure 'Manage processing of Queue-specific files' is set to 'Enabled Limit Queue-specific files to Color profiles'

18.10.12.1 Ensure 'Turn off cloud consumer account state content' is set to 'Enabled' - Enabled

18.10.15.1 Ensure 'Allow Diagnostic Data' is set to 'Enabled Diagnostic data off (not recommended)' or 'Enabled Send required diagnostic data' - Enabled Send required diagnostic data

18.10.15.3 Ensure 'Disable OneSettings Downloads' is set to 'Enabled' - Enabled

18.10.15.5 Ensure 'Enable OneSettings Auditing' is set to 'Enabled' - Enabled

18.10.15.6 Ensure 'Limit Diagnostic Log Collection' is set to 'Enabled' - Enabled

18.10.15.7 Ensure 'Limit Dump Collection' is set to 'Enabled' - Enabled

18.10.17.1 Ensure 'Enable App Installer' is set to 'Disabled'

18.10.17.2 Ensure 'Enable App Installer Experimental Features' is set to 'Disabled'

18.10.17.3 Ensure 'Enable App Installer Hash Override' is set to 'Disabled'

18.10.17.4 Ensure 'Enable App Installer ms-appinstaller protocol' is set to 'Disabled'

19.7.7.5 Ensure 'Turn off Spotlight collection on Desktop' is set to 'Enabled' - Enabled

Windows for business | Windows Server | Directory services | Deploy group policy objects

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} votes

7 answers

Sort by: Most helpful
  1. Anonymous
    2023-11-30T01:21:26+00:00

    Hello siska3089,

    Thank you for posting in Microsoft Community forum.

    Where did you see error message "but item/options still not found"?

    Is the windows server 2019 one domain controller?

    If so, you can copy PolicyDefinitions folder from C:\Windows\PolicyDefinitions on this server to \domain.com\SYSVOL\domain.com\policies folder.

    I hope the information above is helpful.

    If you have any question or concern, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    0 comments No comments
  2. Anonymous
    2023-11-30T02:46:08+00:00

    for example:

    18.7.4 Ensure 'Configure RPC connection settings Use authentication for outgoing RPC connections' is set to 'Enabled Default'

    Instruction from auditor > To establish the recommended configuration via GP, set the following UI path to Enabled: Default: Computer Configuration\Policies\Administrative Templates\Printers\Configure RPC connection settings: Use authentication for outgoing RPC connections Note: This Group Policy path is provided by the Group Policy template Printing.admx/adml that is included with the Microsoft Windows 11 Release 22H2 Administrative Templates (and newer).

    I have followed the instructions and installed the administrative template from the Microsoft website. but the item Configure RPC connection settings: Use authentication for outgoing RPC connections still not found in the group policy object. any have solution why some item still not found ?

    my server not using domain controller or join domain https://learn.microsoft.com/en-US/troubleshoot/windows-client/group-policy/create-and-manage-central-store

    0 comments No comments
  3. Anonymous
    2023-11-30T08:55:30+00:00

    Hello siska3089,

    Thank you for your reply.

    You can check on this server:

    If the Printing.admx is in C:\Windows\PolicyDefinitions.

    Image

    And check if the Printing.adml is in C:\Windows\PolicyDefinitions\en-US.

    Best Regards,
    Daisy Zhou

    0 comments No comments
  4. Anonymous
    2023-11-30T09:21:16+00:00

    Hello Daisy,

    file Printing.admx and Printing.adml found in my server


    But inside GP setting item not found for:

    Configure RPC connection settings: Protocol to use for outgoing RPC connections

    Configure RPC connection settings Use authentication for outgoing RPC connections

    Configure RPC listener settings Protocols to allow for incoming RPC connections

    Configure RPC over TCP port

    Manage processing of Queue-specific files

    only 17 setting items audit requirement on above still not showing in GP,'

    Can you check on your server whether this setting's found or not?

    fyi: my windows server 2019 is latest update

    0 comments No comments
  5. Anonymous
    2023-12-04T07:26:02+00:00

    Hello siska3089,

    Good day!

    Please find one machine with Microsoft Windows 11 Release 22H2 or newer version.

    And copy Printing.admx and Printing.adml on machine with Microsoft Windows 11 Release 22H2 or newer version to your current server , replace Printing.admx within C:\Windows\PolicyDefinitions using Printing.admx on Windows 11 Release 22H2 and replace Printing.adml within C:\Windows\PolicyDefinitions\en-US using on Printing.adml Windows 11 Release 22H2.

    Best Regards,
    Daisy Zhou

    0 comments No comments