SV-226078r569184_rule
V-226078
SRG-OS-000134-GPOS-00068
WN12-AD-000009-DC
CAT II
10
Remove additional roles or applications such as web, database, and email from the domain controller.
Review the roles and services the domain controller is running.
Run "services.msc" to display the Services console.
Determine if any running services are application components.
Examples of services indicating the presence of applications are:
-DHCP Server for DHCP server
-IIS Admin Service for IIS web server
-Microsoft Exchange System Attendant for Exchange
-MSSQLServer for SQL Server.
If any application-related components have the "Started" status, this is a finding.
Installed roles can be displayed by viewing Server Roles in the Add (or Remove) Roles and Features wizard. (Cancel before any changes are made.)
Determine if any additional server roles are installed. A basic domain controller set up will include the following:
-Active Directory Domain Services
-DNS Server
-File and Storage Services
If any roles not requiring installation on a domain controller are installed, this is a finding.
Supplemental Notes:
A Domain Name System (DNS) server integrated with the directory server (e.g., AD-integrated DNS) is an acceptable application. However, the DNS server must comply with the DNS STIG security requirements.
Some directory servers utilize specialized web servers for administrative functions and databases for data management. These web and database servers are permitted as long as they are dedicated to directory server support and only administrative users have access to them.
V-226078
False
WN12-AD-000009-DC
Review the roles and services the domain controller is running.
Run "services.msc" to display the Services console.
Determine if any running services are application components.
Examples of services indicating the presence of applications are:
-DHCP Server for DHCP server
-IIS Admin Service for IIS web server
-Microsoft Exchange System Attendant for Exchange
-MSSQLServer for SQL Server.
If any application-related components have the "Started" status, this is a finding.
Installed roles can be displayed by viewing Server Roles in the Add (or Remove) Roles and Features wizard. (Cancel before any changes are made.)
Determine if any additional server roles are installed. A basic domain controller set up will include the following:
-Active Directory Domain Services
-DNS Server
-File and Storage Services
If any roles not requiring installation on a domain controller are installed, this is a finding.
Supplemental Notes:
A Domain Name System (DNS) server integrated with the directory server (e.g., AD-integrated DNS) is an acceptable application. However, the DNS server must comply with the DNS STIG security requirements.
Some directory servers utilize specialized web servers for administrative functions and databases for data management. These web and database servers are permitted as long as they are dedicated to directory server support and only administrative users have access to them.
M
4217