CIS Benchmark Compliance for Microsoft Platforms with Greenbone

Microsoft technologies are a core component of enterprise IT infrastructures around the world. In many organizations, they underpin business-critical databases, identity systems, essential server workloads, and applications used for everyday productivity. Greenbone has introduced four additional compliance scans based on CIS Benchmarks for Microsoft environments.

CIS Benchmarks provide prescriptive guidance for configuring systems securely. They complement other essential cybersecurity practices, such as vulnerability management, endpoint protection, and activity monitoring.

This article reviews the main security areas addressed by each benchmark. It also outlines how Greenbone compliance policies support the detection of configuration gaps in Microsoft Office, SQL Server, and Windows Server environments. With the broad coverage provided by the OPENVAS ENTERPRISE FEED, OPENVAS SCAN delivers the compliance insight required to uncover insecure settings, prioritize corrective actions, and enhance the resilience of Microsoft-based IT infrastructures.

The newly added compliance policies for Microsoft environments further expand Greenbone’s already broad portfolio of compliance scans:

  • CIS Microsoft Office Enterprise Benchmark v1.2.0
  • CIS Microsoft SQL Server 2022 Benchmark v1.2.1
  • CIS Microsoft Windows Server 2025 Benchmark v2.0.0
  • CIS Microsoft Windows Server 2022 Benchmark v5.0.0

The Importance of IT Compliance in 2026

In 2026, organizations operating in the European Union are subject to several overlapping requirements related to cybersecurity, operational resilience, privacy, and corporate governance.

The NIS2 Directive requires critical infrastructure operators to implement appropriate technical, operational, and organizational measures to maintain cybersecurity. DORA establishes additional requirements for organizations in the financial sector, particularly regarding ICT risk management and digital operational resilience. The GDPR imposes security obligations on organizations that process or store personal data. Beginning on September 11, 2026, the Cyber Resilience Act (CRA) requires organizations to report actively exploited vulnerabilities and serious incidents affecting products, alongside additional obligations.

Following established IT security standards, including CIS Benchmarks, helps organizations create strong and auditable security baselines. It also supports the production of audit evidence, reduces configuration drift, and demonstrates that governance and risk management responsibilities are applied consistently.

Understanding CIS Microsoft SQL Server 2022 Benchmark v1.2.1

CIS Microsoft SQL Server 2022 Benchmark v1.2.1 provides prescriptive guidance for securely configuring SQL Server 2022 on Microsoft Windows. The benchmark is designed for database and system administrators, security specialists, auditors, and deployment teams involved in planning, assessing, or securing SQL Server environments.

The benchmark covers installation and patching, attack surface reduction, authentication and access control, password policies, auditing and logging settings, application development practices, and encryption. For CIS Microsoft SQL Server 2022 Benchmark v1.2.1, Greenbone’s compliance scan includes the practical Level 1 profile for both the SQL Server Database Engine and AWS RDS.

Understanding CIS Microsoft Windows Server 2025 Benchmark v2.0.0

CIS Microsoft Windows Server 2025 Benchmark v2.0.0 defines and evaluates security settings designed to harden Windows Server 2025 systems.

The benchmark applies to systems joined to an Active Directory domain or configured as Entra Hybrid-joined. These environments are managed through policies distributed using Active Directory Group Policy Manager. It is not intended for standalone or workgroup-based systems, nor for environments that are cloud-managed or cloud-hosted.

Its scope covers Active Directory domain-joined and Entra Hybrid-joined systems where policy settings are centrally enforced through Active Directory Group Policy Manager. Greenbone’s compliance scan for CIS Microsoft Windows Server 2025 Benchmark v2.0.0 covers both Level 1 and Level 2 profiles for Domain Controllers as well as Member Servers.

Understanding CIS Microsoft Windows Server 2022 Benchmark v5.0.0

CIS Microsoft Windows Server 2022 Benchmark v5.0.0 addresses the security settings necessary to harden Windows Server 2022 deployments.

The benchmark applies to Active Directory domain-joined and Entra Hybrid-joined systems whose policy settings are centrally controlled through Active Directory Group Policy Manager. The policy does not target standalone systems, workgroup environments, cloud-managed systems, or cloud-hosted systems.

The benchmark covers major security areas such as account and local security policies, system services, Windows Defender Firewall, advanced auditing settings, authentication, remote access, and administrative templates.

For CIS Microsoft Windows Server 2022 Benchmark v5.0.0, Greenbone provides compliance scanning for both Level 1 and Level 2 profiles across Domain Controllers and Member Servers.

Explore Greenbone’s Range of Compliance Scans

OPENVAS SCAN compliance policies are created from carefully selected sets of vulnerability tests that assess systems against defined security requirements. These policies are suitable for organizations that must comply with BSI technical standards. They are equally applicable to organizations that need deeper insight into the security and resilience of their IT networks and applications. OPENVAS SCAN provides the compliance insight necessary to identify configuration weaknesses and strengthen the overall security posture.

The OPENVAS ENTERPRISE FEED provides access to a range of compliance scans, including:

  • BSI TR-03116-4: BSI Minimum Standards for the Use of TLS
  • BSI TR-02102-4: BSI Minimum Standards for the Use of SSH
  • CIS Benchmark v1.10 for Kubernetes 1.28 Controller Node
  • CIS Benchmark v1.10 for Kubernetes 1.28 Worker Nodes
  • Compliance profiles for Huawei EulerOS, openEuler, and Huawei Cloud EulerOS
  • CIS Benchmark v3.0.0 (L1) for Microsoft Windows 11 Enterprise
  • CIS Benchmarks v3.0.0 (L1 – Windows) for Google Chrome
  • BSI and CIS Benchmarks for Microsoft Office
  • Policy check for SSH: Post Quantum Cryptography (PQC)
  • Policy check for SSL/TLS: Post Quantum Cryptography (PQC)

Summary

Microsoft platforms support a substantial share of business-critical workloads. At the same time, the extensive range of configuration options can introduce security weaknesses when hardening controls are implemented inconsistently. Greenbone’s expanding portfolio of compliance scans helps organizations detect deviations from recommended security baselines, improve governance and audit readiness, and reduce risks associated with insecure or inconsistent configurations.

OPENVAS SCAN provides the visibility organizations need to strengthen Microsoft environments as regulatory expectations and operational security requirements continue to evolve. Organizations can evaluate the security and resilience of their IT networks and applications through a free two-week trial of the OPENVAS ENTERPRISE FEED with OPENVAS SCAN.

Request a free trial



    Subscribe to news