CIS Benchmarks for Microsoft Environments: Greenbone’s Got You Covered!
Microsoft technologies are foundational to enterprise IT globally, providing the backbone for operation-critical databases, identity services, core server workloads, and daily productivity applications at many organizations. Greenbone is happy to announce new compliance scans aligned with four CIS Benchmarks for Microsoft environments. CIS Benchmarks provide prescriptive guidance for establishing secure configurations and complement essential security practices such as vulnerability management, endpoint protection, and activity monitoring.

In this article, we briefly review the security focus of each benchmark and explain how Greenbone’s compliance policies help organizations identify configuration gaps across Microsoft Office, SQL Server, and Windows Server systems. OPENVAS SCAN, backed by the industry-leading coverage of the OPENVAS ENTERPRISE FEED, provides the compliance visibility needed to detect insecure settings, prioritize remediation, and strengthen the resilience of Microsoft IT environments.
The new compliance policies for Microsoft IT environments add to Greenbone’s already impressive line of scans:
- CIS Microsoft Office Enterprise Benchmark v1.2.0
- CIS Microsoft SQL Server 2022 Benchmark v1.2.1
- CIS Microsoft Windows Server 2025 Benchmark v2.0.0
- CIS Microsoft Windows Server 2022 Benchmark v5.0.0
The Importance of IT Compliance in 2026
In 2026, organizations operating in the EU face overlapping cyber security, resilience, privacy, and corporate governance obligations. The Network and Information Systems Directive 2 (NIS2) requires critical infrastructure entities to implement technical, operational, and organizational safeguards. The Digital Operational Resilience Act (DORA) imposes additional ICT risk management and resilience requirements on the financial sector. The GDPR imposes security requirements on organizations that process or store personal data, and the Cyber Resilience Act (CRA) introduces mandatory reporting of actively exploited vulnerabilities and severe product security incidents from September 11, 2026, among other obligations.
Following recognized IT security standards such as CIS Benchmarks helps organizations establish defensible security baselines, produce audit evidence, reduce configuration drift, and demonstrate that governance and risk management duties are implemented consistently.
Talk to Our Sales Team
Whether your organization must meet regulatory requirements or simply wants deeper insight into securing Microsoft IT environments, OPENVAS SCAN provides the compliance visibility needed to identify configuration gaps, reduce risk, and strengthen security. Contact Greenbone’s sales team to discuss how compliance scanning can best support your organization’s regulatory and security governance requirements.
Understanding CIS Microsoft SQL Server 2022 Benchmark v1.2.1
The CIS Microsoft SQL Server 2022 Benchmark v1.2.1 provides prescriptive guidance for the secure configuration of SQL Server 2022 on Microsoft Windows. It is intended for database and system administrators, security specialists, auditors, and deployment personnel responsible for developing, assessing, or securing SQL Server environments.
The benchmark covers installation and patching, attack surface reduction, authentication and authorization, password policies, auditing and logging, application development, and encryption. Greenbone’s compliance scan for CIS Microsoft SQL Server 2022 Benchmark v1.2.1 covers the practical Level 1 profile for the SQL Server Database Engine and AWS RDS, and the Level 2 Database Engine profile with additional defense-in-depth controls.
Understanding CIS Microsoft Windows Server 2025 Benchmark v2.0.0
The CIS Microsoft Windows Server 2025 Benchmark v2.0.0 audits security controls for establishing a hardened configuration of Windows Server 2025. It is designed for Active Directory domain-joined and Entra Hybrid-joined systems that receive policies through Active Directory Group Policy Manager. The policy is not designed for standalone, workgroup, cloud-managed, or cloud-hosted systems.
The benchmark addresses areas such as account and local security policies, system services, Windows Defender Firewall, advanced audit configuration, authentication, remote access, and administrative template settings. Greenbone’s compliance scan for CIS Microsoft Windows Server 2025 Benchmark v2.0.0 covers Level 1 and Level 2 profiles for both Domain Controllers and Member Servers, along with optional Next Generation Windows Security profiles for advanced controls.
Understanding CIS Microsoft Windows Server 2022 Benchmark v5.0.0
The CIS Microsoft Windows Server 2022 Benchmark v5.0.0 audits security controls for establishing a hardened configuration of Windows Server 2022. The Windows Server 2022 benchmark is intended for Active Directory domain-joined and Entra Hybrid-joined systems that receive policies through Active Directory Group Policy Manager. The policy is not designed for standalone, workgroup, cloud-managed, or cloud-hosted systems.
The benchmark addresses areas such as account and local security policies, system services, Windows Defender Firewall, advanced auditing, authentication, remote access, and administrative template settings. Greenbone’s compliance scan for CIS Microsoft Windows Server 2022 Benchmark v5.0.0 covers Level 1 and Level 2 profiles for Domain Controllers and Member Servers, along with optional Next Generation Windows Security profiles containing advanced controls.
Get to Know Greenbone’s Full Suite of Compliance Scans
OPENVAS SCAN’s compliance policies consist of specially selected groups of vulnerability tests used to assess compliance. Whether your organization is required to meet BSI technical standards or simply wants deeper insight into building resilient IT networks and applications, OPENVAS SCAN provides compliance visibility to identify gaps and strengthen security.
Some of the compliance scans in Greenbone’s OPENVAS ENTERPRISE FEED:
- BSI TR-03116-4: BSI Minimum Standards for the Use of TLS
- BSI TR-02102-4: BSI Minimum Standards for the Use of SSH
- CIS Benchmark v1.10 for Kubernetes 1.28 Controller Node
- CIS Benchmark v1.10 for Kubernetes 1.28 Worker Nodes
- Compliance profiles for Huawei EulerOS, openEuler, and Huawei Cloud EulerOS
- CIS Benchmark v3.0.0 (L1) for Microsoft Windows 11 Enterprise
- CIS Benchmarks v3.0.0 (L1 – Windows) for Google Chrome
- BSI and CIS Benchmarks for Microsoft Office
- Policy check for SSH: Post Quantum Cryptography (PQC)
- Policy check for SSL/TLS: Post Quantum Cryptography (PQC)
Talk to Our Sales Team
Whether your organization must meet regulatory requirements or simply wants deeper insight into securing Microsoft IT environments, OPENVAS SCAN provides the compliance visibility needed to identify configuration gaps, reduce risk, and strengthen security. Contact Greenbone’s sales team to discuss how compliance scanning can best fit your organization’s regulatory and security governance requirements.
Summary
Microsoft platforms support critical business operations, but their extensive configuration options can introduce security gaps when systems are not consistently hardened. CIS Benchmarks are the IT industry standard for practical guidance on establishing secure configurations. Greenbone’s growing list of compliance scans helps organizations identify deviations from these recommended baselines, strengthen governance and audit readiness, and reduce configuration-related risk.
OPENVAS SCAN provides the visibility needed to maintain more resilient Microsoft environments as regulatory and operational security expectations continue to increase. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way for your organization to gain the deepest insight into building resilient IT networks and applications.



