Skip to main content
CodenameDescriptionAdmin Roles
CANARY‑1Configure an appropriately-privileged NAA with interactive logon restrictedSCCM, domain
DETECT‑1Monitor site server domain computer accounts authenticating from another sourceSecurity
DETECT‑2Monitor read access to the System Management Active Directory containerSecurity
DETECT‑3Monitor client push installation accounts authenticating from anywhere other than the primary site serverSecurity
DETECT‑4Monitor application deployment logs in the site’s Audit Status MessagesSCCM, security
DETECT‑5Monitor group membership changes for SMS AdminsSCCM, server, security
DETECT‑6Monitor group membership changes for RBAC_Admins tableSCCM, server, security
DETECT‑7Monitor read access to the SMSTemp directorySCCM, server, security
DETECT‑8Monitor connections to winreg named pipeSCCM, server, security
DETECT‑9Monitor local object access for local SCCM logs and settingsSCCM, server, security
PREVENT‑1Patch site server with KB15599094SCCM, server
PREVENT‑2Disable Fallback to NTLMSCCM
PREVENT‑3Harden or disable network access accountsSCCM, domain, security
PREVENT‑4Configure Enhanced HTTPSCCM
PREVENT‑5Disable automatic side-wide client push installationSCCM
PREVENT‑6Configure a strong PXE boot passwordSCCM
PREVENT‑7Disable command support in PXE boot configurationSCCM
PREVENT‑8Require PKI certificates for client authentationSCCM, network, security, server, domain
PREVENT‑9Enforce MFA for SMS Provider callsSCCM
PREVENT‑10Enforce the principle of least privilege for accountsSCCM, domain, server, security
PREVENT‑11Disable and uninstall WebClient on site serversSCCM, server
PREVENT‑12Require SMB signing on site systemsDomain, server, SCCM
PREVENT‑13Require LDAP channel binding and signingDomain, server
PREVENT‑14Require EPA on AD CS and site databasesDomain, security, SCCM, server, database
PREVENT‑15Disable and change passwords of legacy NAAs and collection variables/task sequence secrets in Active DirectoryDomain, SCCM
PREVENT‑16Remove SeMachineAccountPrivilege and set MachineAccountQuota to 0 for non-admin accountsDomain
PREVENT‑17Remove Extended Rights assignment from accounts that do not require itDomain, desktop
PREVENT‑18Use strong passwords for DBA accountsDatabase, security, domain
PREVENT‑19Remove unnecessary links to site databasesSCCM, database
PREVENT‑20Block unnecessary connections to site systemsNetwork, server
PREVENT‑21Restrict PXE boot to authorized VLANsSCCM, network
PREVENT‑22Do not manage assets in two or more segmented forests, domains, networks, or security tiersSCCM, network, security, domain