• Request consultation
  • Newsletter
  • Deutsch Deutsch German de
  • English English English en
  • Italiano Italiano Italian it
  • Nederlands Nederlands Dutch nl
Greenbone
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for Your Sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap & Lifecycle
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • Cybersec Europe 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
  • Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for your sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap and Lifecycle
    • Request IT Security
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • Cybersec Europe 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
    • Newsletter
  • Our Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • German
  • English
  • Italian
  • Dutch
Greenbone AG

CIS Benchmarks for Microsoft Environments: Greenbone’s Got You Covered!

Blog

Microsoft technologies are foundational to enterprise IT globally, providing the backbone for operation-critical databases, identity services, core server workloads, and daily productivity applications at many organizations. Greenbone is happy to announce new compliance scans aligned with four CIS Benchmarks for Microsoft environments. CIS Benchmarks provide prescriptive guidance for establishing secure configurations and complement essential security practices such as vulnerability management, endpoint protection, and activity monitoring.

Fortified server module illustration for Greenbone's new Microsoft CIS Benchmark compliance scans

In this article, we briefly review the security focus of each benchmark and explain how Greenbone’s compliance policies help organizations identify configuration gaps across Microsoft Office, SQL Server, and Windows Server systems. OPENVAS SCAN, backed by the industry-leading coverage of the OPENVAS ENTERPRISE FEED, provides the compliance visibility needed to detect insecure settings, prioritize remediation, and strengthen the resilience of Microsoft IT environments.

The new compliance policies for Microsoft IT environments add to Greenbone’s already impressive line of scans:

  • CIS Microsoft Office Enterprise Benchmark v1.2.0
  • CIS Microsoft SQL Server 2022 Benchmark v1.2.1
  • CIS Microsoft Windows Server 2025 Benchmark v2.0.0
  • CIS Microsoft Windows Server 2022 Benchmark v5.0.0

The Importance of IT Compliance in 2026

In 2026, organizations operating in the EU face overlapping cyber security, resilience, privacy, and corporate governance obligations. The Network and Information Systems Directive 2 (NIS2) requires critical infrastructure entities to implement technical, operational, and organizational safeguards. The Digital Operational Resilience Act (DORA) imposes additional ICT risk management and resilience requirements on the financial sector. The GDPR imposes security requirements on organizations that process or store personal data, and the Cyber Resilience Act (CRA) introduces mandatory reporting of actively exploited vulnerabilities and severe product security incidents from September 11, 2026, among other obligations.

Following recognized IT security standards such as CIS Benchmarks helps organizations establish defensible security baselines, produce audit evidence, reduce configuration drift, and demonstrate that governance and risk management duties are implemented consistently.

Talk to Our Sales Team

Whether your organization must meet regulatory requirements or simply wants deeper insight into securing Microsoft IT environments, OPENVAS SCAN provides the compliance visibility needed to identify configuration gaps, reduce risk, and strengthen security. Contact Greenbone’s sales team to discuss how compliance scanning can best support your organization’s regulatory and security governance requirements.

Understanding CIS Microsoft SQL Server 2022 Benchmark v1.2.1

The CIS Microsoft SQL Server 2022 Benchmark v1.2.1 provides prescriptive guidance for the secure configuration of SQL Server 2022 on Microsoft Windows. It is intended for database and system administrators, security specialists, auditors, and deployment personnel responsible for developing, assessing, or securing SQL Server environments.

The benchmark covers installation and patching, attack surface reduction, authentication and authorization, password policies, auditing and logging, application development, and encryption. Greenbone’s compliance scan for CIS Microsoft SQL Server 2022 Benchmark v1.2.1 covers the practical Level 1 profile for the SQL Server Database Engine and AWS RDS, and the Level 2 Database Engine profile with additional defense-in-depth controls.

Understanding CIS Microsoft Windows Server 2025 Benchmark v2.0.0

The CIS Microsoft Windows Server 2025 Benchmark v2.0.0 audits security controls for establishing a hardened configuration of Windows Server 2025. It is designed for Active Directory domain-joined and Entra Hybrid-joined systems that receive policies through Active Directory Group Policy Manager. The policy is not designed for standalone, workgroup, cloud-managed, or cloud-hosted systems.

The benchmark addresses areas such as account and local security policies, system services, Windows Defender Firewall, advanced audit configuration, authentication, remote access, and administrative template settings. Greenbone’s compliance scan for CIS Microsoft Windows Server 2025 Benchmark v2.0.0 covers Level 1 and Level 2 profiles for both Domain Controllers and Member Servers, along with optional Next Generation Windows Security profiles for advanced controls.

Understanding CIS Microsoft Windows Server 2022 Benchmark v5.0.0

The CIS Microsoft Windows Server 2022 Benchmark v5.0.0 audits security controls for establishing a hardened configuration of Windows Server 2022. The Windows Server 2022 benchmark is intended for Active Directory domain-joined and Entra Hybrid-joined systems that receive policies through Active Directory Group Policy Manager. The policy is not designed for standalone, workgroup, cloud-managed, or cloud-hosted systems.

The benchmark addresses areas such as account and local security policies, system services, Windows Defender Firewall, advanced auditing, authentication, remote access, and administrative template settings. Greenbone’s compliance scan for CIS Microsoft Windows Server 2022 Benchmark v5.0.0 covers Level 1 and Level 2 profiles for Domain Controllers and Member Servers, along with optional Next Generation Windows Security profiles containing advanced controls.

Get to Know Greenbone’s Full Suite of Compliance Scans

OPENVAS SCAN’s compliance policies consist of specially selected groups of vulnerability tests used to assess compliance. Whether your organization is required to meet BSI technical standards or simply wants deeper insight into building resilient IT networks and applications, OPENVAS SCAN provides compliance visibility to identify gaps and strengthen security.

Some of the compliance scans in Greenbone’s OPENVAS ENTERPRISE FEED:

  • BSI TR-03116-4: BSI Minimum Standards for the Use of TLS
  • BSI TR-02102-4: BSI Minimum Standards for the Use of SSH
  • CIS Benchmark v1.10 for Kubernetes 1.28 Controller Node
  • CIS Benchmark v1.10 for Kubernetes 1.28 Worker Nodes
  • Compliance profiles for Huawei EulerOS, openEuler, and Huawei Cloud EulerOS
  • CIS Benchmark v3.0.0 (L1) for Microsoft Windows 11 Enterprise
  • CIS Benchmarks v3.0.0 (L1 – Windows) for Google Chrome
  • BSI and CIS Benchmarks for Microsoft Office
  • Policy check for SSH: Post Quantum Cryptography (PQC)
  • Policy check for SSL/TLS: Post Quantum Cryptography (PQC)

Talk to Our Sales Team

Whether your organization must meet regulatory requirements or simply wants deeper insight into securing Microsoft IT environments, OPENVAS SCAN provides the compliance visibility needed to identify configuration gaps, reduce risk, and strengthen security. Contact Greenbone’s sales team to discuss how compliance scanning can best fit your organization’s regulatory and security governance requirements.

Summary

Microsoft platforms support critical business operations, but their extensive configuration options can introduce security gaps when systems are not consistently hardened. CIS Benchmarks are the IT industry standard for practical guidance on establishing secure configurations. Greenbone’s growing list of compliance scans helps organizations identify deviations from these recommended baselines, strengthen governance and audit readiness, and reduce configuration-related risk.

OPENVAS SCAN provides the visibility needed to maintain more resilient Microsoft environments as regulatory and operational security expectations continue to increase. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way for your organization to gain the deepest insight into building resilient IT networks and applications.

 

Contact Test Now Buy Here Back to Overview
31. July 2026/by Greenbone AG
Share this entry
  • Share on LinkedIn
  • Share by Mail
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Greenbone AG https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Greenbone AG2026-07-31 14:03:422026-07-31 14:03:42CIS Benchmarks for Microsoft Environments: Greenbone’s Got You Covered!

Search

Search Search

Archive

  • 2026
  • 2025

Newsletter

Subscribe Now

OPENVAS BASIC

Our entry-level enterprise product

Test 14 Days Free of Charge

Products & Solutions

  • OPENVAS PRODUCTS
  • OPENVAS SECURITY INTELLIGENCE
  • OPENVAS SCAN
  • OPENVAS BASIC
  • OPENVAS FREE
  • OPENVAS AI
ISO9001-EN

Service & Support

  • Professional Services
  • Documents
  • Technical Support
  • FAQ
  • Warranty
  • Cyber Resilience Act
ISO27001-EN

About us

  • About Greenbone
  • Partners
  • MSSP
  • License information
  • Privacy Statement
  • Terms & Conditions
ISO14001-EN

Contact with us

  • Contact
  • Newsletter
  • Media Contact
  • Careers
  • Security Response
  • Imprint
  • Grounding Page

Community

  • Community Portal
  • Community Forum
© Copyright - Greenbone AG 2020-2026
  • Link to LinkedIn
Link to: Patch Priority: An Emerging Tide of Linux Vulnerabilities Put Users in Hot Water Link to: Patch Priority: An Emerging Tide of Linux Vulnerabilities Put Users in Hot Water Patch Priority: An Emerging Tide of Linux Vulnerabilities Put Users in Hot ...
Scroll to top Scroll to top Scroll to top
Contact
Request IT Security Contact Us Subscribe to Newsletter Follow on LinkedIn