Check: WN12-CC-000012
      
      
        
  Microsoft Windows Server 2012/2012 R2 Domain Controller STIG:
  WN12-CC-000012
  
    (in versions v3 r7 through v2 r7)
  
      
      
    
  Title
The configuration of wireless devices using Windows Connect Now must be disabled. (Cat II impact)
Discussion
Windows Connect Now allows the discovery and configuration of devices over wireless. Wireless devices must be managed. If a rogue device is connected to a system, there is potential for sensitive information to be compromised.
Check Content
If the following registry values do not exist or are not configured as specified, this is a finding: Registry Hive: HKEY_LOCAL_MACHINE Registry Path: \Software\Policies\Microsoft\Windows\WCN\Registrars\ Value Name: DisableFlashConfigRegistrar Value Name: DisableInBand802DOT11Registrar Value Name: DisableUPnPRegistrar Value Name: DisableWPDRegistrar Value Name: EnableRegistrars Type: REG_DWORD Value: 0
Fix Text
Configure the policy value for Computer Configuration -> Administrative Templates -> Network -> Windows Connect Now -> "Configuration of wireless settings using Windows Connect Now" to "Disabled".
Additional Identifiers
Rule ID: SV-226146r794417_rule
Vulnerability ID: V-226146
Group Title: SRG-OS-000095-GPOS-00049
Expert Comments
      
        
        
      
      
        
  CCIs
      
      
        
        
      
    
  | Number | Definition | 
|---|---|
| CCI-000381 | Configure the system to provide only organization-defined mission essential capabilities. | 
      
        
        
      
      
        
  Controls
      
      
        
        
      
    
  | Number | Title | 
|---|---|
| CM-7 | Least Functionality |