DISA: Windows Server 2022


Product: BMC TrueSight Server Automation
Applicable Version: 20.x and later
Feature/Hotfix: Importing DISA Compliance Content Templates (Version V2R3) for Windows Server 2022

Overview

This document outlines the steps to import the updated DISA Compliance Templates (V2R3) for Windows Server 2022. These templates are compatible with BMC TrueSight Server Automation version 20.x and later.

The updated DISA Windows Server 2022 V2R3 template introduces a script-based approach that is more streamlined, modular, and maintainable for managing compliance checks. Each rule is now supported by dedicated audit and remediation scripts, organized within a structured directory to ensure clarity and ease of maintenance.

The template includes Local Configuration Objects for each rule, which are responsible for triggering the corresponding audit scripts. Remediation scripts are specifically designed for each rule to ensure accurate and efficient compliance enforcement.

This approach delivers a consistent, script-driven framework that aligns with DISA Windows 2022 compliance requirements while enabling easier updates and reliable execution.

Updated Template

  • DISA – Windows Server 2022

Before you begin

Before importing the template, review and adjust the following local and global properties to align with your organization’s standards:

Property nameRule IDDefault valueNotes
ADMIN_ACCOUNT_NAMEV-254239AdministratorIf renamed, specify the new administrator account name.
APPLICATION_USER_LISTV-254243"user1,user2"Manually managed application/service accounts
DOWNLOADMODEV-2543570

Acceptable Values and Descriptions:

Hex valueDecimal valueDescription
0x000000000No peering (HTTP Only)
0x000000011Peers on same NAT only (LAN)
0x000000022Local Network / Private group peering (Group)
0x0000006399Simple download mode, no peering (Simple)

Note: Use the following values based on your network configuration:

  • 0 for HTTP only
  • 1 for LAN
  • 2 for Group
  • 99 for Simple
FOREST_NAMEV-254400"dc=disaost,dc=mil"Fully qualified LDAP name of the domain being reviewed.
APPROVED_ISSUERSV-254413"test1,test2"List of authorized CAs. This property is related to PKI. For example, DoD PKI, ECA
ALLOWED_DOMAIN_SUFFIXV-254414"test"

Domain suffix used in User Principal Name (UPN)

For example:

  • Name - User Principal Name
  • User1 - 1234567890@mil
SEDENYINTERACTIVELOGONRIGHTV-254438"user1"Set to BladeLogicRSCD (MS) or BladeLogicRSCDDC (DC). Use comma-separated usernames if needed.
  • The audit script auto-detects Domain Controller vs Member Server; there is no need to manually set the DOMAIN property.
  • Make sure the following files are copied to all target servers:

    • .admx: C:\Windows\PolicyDefinitions
    • .adml: C:\Windows\PolicyDefinitions\en-US
    Rule IDADMX FileADML File
    V-254276SecGuide.admxSecGuide.adml
    V-254277SecGuide.admxSecGuide.adml
    V-254334SecGuide.admxSecGuide.adml
    V-254335MSS-Legacy.admxMSS-Legacy.adml
    V-254336MSS-Legacy.admxMSS-Legacy.adml
    V-254337MSS-Legacy.admxMSS-Legacy.adml
    V-254338MSS-Legacy.admxMSS-Legacy.adml
    V-254429SecGuide.admxSecGuide.adml

    Download these files from Microsoft Download Center, if not apresent already.

Step 1: Download and install the files

  1. Download the DISA - Windows Server 2022 package from the EPD location by following these steps:
    1. Log in to the BMC EPD Website.
    2. In View by category, navigate to Additional Products and select Server Automation.
    3. Navigate to:
      • TrueSight Server Automation > TrueSight Server Automation 24.4.0.0, or
      • Navigate to True Sight Server Automation Compliance Module > True Sight Server Automation Compliance Module 24.4.0.0.
    4. Download the TSSA 24.4.00 DISA updates for Windows 2022.
      This file includes:
      • DISA-Windows Server 2022.zip
      • U_MS_Windows_Server_2022_V2R3_STIG.zip
      • RELEASE_NOTES_FOR_HOTFIX_OF_DISA_WINDOWS_2022_V2R3.docx
      • ExtendedObjects.zip
    5. Verify the MD5 Checksums in the downloaded content:
      FilenameMD5 checksum
      DISA - Windows Server 2022.zip554dcb686cf544a2c9d43f366a58a119
      ExtendedObjects.zip13a3343323f3048acf0654c42f9bdee4
  2. Update the extended objects
    1. Extract ExtendedObjects.zip.
    2. Backup existing objects from <Appserver_Install_Path>/share/sensors/disa/win2022.
    3. Replace only the updated objects on all app servers.
  3. Move the DISA - Windows Server 2022 package to your RCP client server.

Step 2: Import the compliance content

  1. Log in to the  Console.
  2. Right-click Component Templates and select Import.
    1748341897920-439.png
     
  3. Select the Import (Version-neutral) option and click OK.
    1748342015969-479.png
  4. Select the DISA - Windows Server 2022.zip package from the temporary location and click Next.The DISA template for DISA - Windows Server 2022 is available in the DISA - Windows Server 2022.zip package. To import the templates, select the DISA - Windows Server 2022.zip and click Next.
    1748342123291-448.png

  5. Make sure that you select the Update objects according to the imported package and Preserve template group path options, and click Next.
    1748342730371-812.png
  6. Click Finish.
    1748342864675-932.png
  7. Click OK.
    1748343270003-208.png

The templates will appear under: DISA Compliance Content > DISA STIG Revised.

 

Important

The hotfix contains a DISA template for DISA—Windows Server 2022, with implementation for 275 rules that can be installed on TrueSight Server Automation 20.x onwards. This template is created based on the recommended settings defined by Microsoft Windows Server 2022 Security Technical Implementation Guide V2R3, published on January 30, 2025.

The template contains 275 rules.

​​​

Rules within the template

The following are the details of the 275 rules provided in the zip package. It contains the following types of rules:

  • Rules that check for compliance (audit) and provide remediation: 205
  • Rules that check for compliance(audit) but do not provide remediation: 28
  • Rules that do not check for compliance and do not provide remediation: 42

The following are the details of the rules that are divided into parts:

  • Rules not divided into parts: 272
  • Rules divided into two parts (1 Rule) so (1* 3) = 3

The current rule count, according to the DISA Windows 2022 template, after running the compliance job, is 275 (272+3).

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*