SV-230220r569300_rule
V-230220
SRG-OS-000041
WN10-CC-000327
CAT II
10
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows PowerShell >> "Turn on PowerShell Transcription" to "Enabled".
Specify the Transcript output directory to point to a Central Log Server or another secure location to prevent user access.
If the following registry value does not exist or is not configured as specified, this is a finding.
Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \SOFTWARE\Policies\Microsoft\Windows\PowerShell\Transcription\
Value Name: EnableTranscripting
Value Type: REG_DWORD
Value: 1
V-230220
False
WN10-CC-000327
If the following registry value does not exist or is not configured as specified, this is a finding.
Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \SOFTWARE\Policies\Microsoft\Windows\PowerShell\Transcription\
Value Name: EnableTranscripting
Value Type: REG_DWORD
Value: 1
M
4072