{ "data": [ { "6": "1.1.1. Cau hinh tham so 'Enforce password history'" }, { "7": "1.1.2. Cau hinh tham so 'Maximum password age'" }, { "8": "1.1.3. Cau hinh tham so 'Minimum password age'" }, { "9": "1.1.4. Cau hinh tham so 'Minimum password length'" }, { "10": "1.1.5. Cau hinh chinh sach 'Password must meet complexity requirements'" }, { "11": "1.1.6. Cau hinh tham so 'Store passwords using reversible encryption'" }, { "13": "1.2.1. Cau hinh tham so 'Account lockout duration'" }, { "14": "1.2.2. Cau hinh tham so 'Account lockout threshold'" }, { "15": "1.2.3. Cau hinh tham so 'Reset account lockout counter after'" }, { "18": "2.1.1. Cau hinh chinh sach 'Access Credential Manager as a trusted caller'" }, { "19": "2.1.2. Cau hinh chinh sach 'Access this computer from the network' [Chỉ DC]" }, { "19": "2.1.2. Cau hinh chinh sach 'Access this computer from the network' [Chỉ MS]" }, { "21": "2.1.3. Cau hinh chinh sach 'Act as part of the operating system'" }, { "22": "2.1.4. Cau hinh chinh sach 'Add workstations to domain' [Chỉ DC]" }, { "23": "2.1.5. Cau hinh chinh sach 'Adjust memory quotas for a process'" }, { "24": "2.1.6. Cau hinh chinh sach 'Allow log on locally'" }, { "25": "2.1.7. Cau hinh chinh sach 'Allow log on through Remote Desktop Services' [Chỉ DC]" }, { "25": "2.1.7. Cau hinh chinh sach 'Allow log on through Remote Desktop Services' [Chỉ MS]" }, { "27": "2.1.8. Cau hinh chinh sach 'Back up files and directories'" }, { "28": "2.1.9. Cau hinh chinh sach 'Change the system time'" }, { "29": "2.1.10. Cau hinh chinh sach 'Change the time zone'" }, { "30": "2.1.11. Cau hinh chinh sach 'Create a pagefile'" }, { "31": "2.1.12. Cau hinh chinh sach 'Create a token object'" }, { "32": "2.1.13. Cau hinh chinh sach 'Create global objects'" }, { "33": "2.1.14. Cau hinh chinh sach 'Create permanent shared objects'" }, { "34": "2.1.15. Cau hinh chinh sach 'Create symbolic links' [Chỉ DC]" }, { "34": "2.1.15. Cau hinh chinh sach 'Create symbolic links' [Chỉ MS]" }, { "36": "2.1.16. Cau hinh chinh sach 'Debug programs'" }, { "37": "2.1.17. Cau hinh chinh sach 'Deny access to this computer from the network' [Chỉ DC]" }, { "37": "2.1.17. Cau hinh chinh sach 'Deny access to this computer from the network' [Chỉ MS]" }, { "39": "2.1.18. Cau hinh chinh sach 'Deny log on as a batch job'" }, { "40": "2.1.19. Cau hinh chinh sach 'Deny log on as a service'" }, { "41": "2.1.20. Cau hinh chinh sach 'Deny log on locally'" }, { "42": "2.1.21. Cau hinh chinh sach 'Deny log on through Remote Desktop Services' [Chỉ DC]" }, { "42": "2.1.21. Cau hinh chinh sach 'Deny log on through Remote Desktop Services' [Chỉ MS]" }, { "44": "2.1.22. Cau hinh chinh sach 'Enable computer and user accounts to be trusted for delegation' [Chỉ DC]" }, { "44": "2.1.22. Cau hinh chinh sach 'Enable computer and user accounts to be trusted for delegation' [Chỉ MS]" }, { "46": "2.1.23. Cau hinh chinh sach 'Force shutdown from a remote system'" }, { "47": "2.1.24. Cau hinh chinh sach 'Generate security audits'" }, { "48": "2.1.25. Cau hinh chinh sach 'Impersonate a client after authentication' [Chỉ DC]" }, { "48": "2.1.25. Cau hinh chinh sach 'Impersonate a client after authentication' [Chỉ MS]" }, { "50": "2.1.26. Cau hinh chinh sach 'Increase scheduling priority'" }, { "51": "2.1.27. Cau hinh chinh sach 'Load and unload device drivers'" }, { "52": "2.1.28. Cau hinh chinh sach 'Lock pages in memory'" }, { "53": "2.1.29. Cau hinh chinh sach 'Manage auditing and security log' [Chỉ DC]" }, { "53": "2.1.29. Cau hinh chinh sach 'Manage auditing and security log' [Chỉ MS]" }, { "55": "2.1.30. Cau hinh chinh sach 'Modify an object label'" }, { "56": "2.1.31. Cau hinh chinh sach 'Modify firmware environment values'" }, { "57": "2.1.32. Cau hinh chinh sach 'Perform volume maintenance tasks'" }, { "58": "2.1.33. Cau hinh chinh sach 'Profile single process'" }, { "59": "2.1.34. Cau hinh chinh sach 'Profile system performance'" }, { "60": "2.1.35. Cau hinh chinh sach 'Replace a process level token'" }, { "61": "2.1.36. Cau hinh chinh sach 'Restore files and directories'" }, { "62": "2.1.37. Cau hinh chinh sach 'Shut down the system'" }, { "63": "2.1.38. Cau hinh chinh sach 'Synchronize directory service data' [Chỉ DC]" }, { "64": "2.1.39. Cau hinh chinh sach 'Take ownership of files or other objects'" }, { "66": "2.2.1.1. Cau hinh trang thai tai khoan 'Administrator account status'" }, { "67": "2.2.1.2. Cau hinh chinh sach tai khoan 'Block Microsoft accounts'" }, { "68": "2.2.1.3. Cau hinh trang thai tai khoan 'Guest account status'" }, { "69": "2.2.1.4. Cau hinh chinh sach tai khoan 'Limit local account use of blank passwords to console logon only'" }, { "70": "2.2.1.5. Cau hinh thay doi ten mac dinh tai khoan quan tri 'Rename administrator account'" }, { "71": "2.2.1.6. Cau hinh thay doi ten mac dinh tai khoan Guests 'Rename guest account'" }, { "73": "2.2.2.1. Cau hinh chinh sach 'Audit: Force audit policy subcategory settings'" }, { "74": "2.2.2.2. Cau hinh chinh sach 'Audit: Shut down system immediately if unable to log security audits'" }, { "76": "2.2.3.1. Cau hinh chinh sach 'Devices: Allowed to format and eject removable media'" }, { "77": "2.2.3.2. Cau hinh chinh sach 'Devices: Prevent users from installing printer drivers'" }, { "79": "2.2.4.1. Cau hinh chinh sach 'Domain controller: Allow server operators to schedule tasks'" }, { "80": "2.2.4.2. Cau hinh chinh sach 'Domain controller: Refuse machine account password changes'" }, { "82": "2.2.5.1. Cau hinh chinh sach 'Domain member: Digitally encrypt or sign secure channel data (always)'" }, { "83": "2.2.5.2. Cau hinh chinh sach 'Domain member: Digitally encrypt secure channel data (when possible)'" }, { "84": "2.2.5.3. Cau hinh chinh sach 'Domain member: Digitally sign secure channel data (when possible)'" }, { "85": "2.2.5.4. Cau hinh chinh sach 'Domain member: Disable machine account password changes'" }, { "86": "2.2.5.5. Cau hinh chinh sach 'Domain member: Maximum machine account password age'" }, { "87": "2.2.5.6. Cau hinh chinh sach 'Domain member: Require strong (Windows 2000 or later) session key'" }, { "89": "2.2.6.1. Thiet lap 'Interactive logon: Do not display last user name'" }, { "90": "2.2.6.2. Thiet lap 'CTRL+ALT+DEL'" }, { "91": "2.2.6.3. Thiet lap 'Interactive logon: Machine inactivity limit'" }, { "92": "2.2.6.4. Cau hinh 'Interactive logon: Message text for users attempting to log on'" }, { "93": "2.2.6.5. Thiet lap 'Interactive logon: Message title for users attempting to log on'" }, { "94": "2.2.6.6. Thiet lap 'Interactive logon: Prompt user to change password before expiration'" }, { "95": "2.2.6.7. Thiet lap 'Interactive logon: Require Domain Controller Authentication to unlock workstation' [Chỉ MS]" }, { "96": "2.2.6.8. Thiet lap 'Interactive logon: Smart card removal behavior'" }, { "98": "2.2.7.1. Thiet lap 'Microsoft network client: Digitally sign communications (if server agrees)'" }, { "98": "7.1. Kiem tra trang thai phan mem" }, { "99": "2.2.7.2. Thiet lap 'Microsoft network client: Send unencrypted password to third-party SMB servers'" }, { "99": "7.2. Kiem tra tinh nang tu dong cap nhat cua phan mem" }, { "100": "2.2.7.3. Thiet lap 'Microsoft network client: Digitally sign communications (always)'" }, { "100": "7.3. Thuc hien lich quet dinh ky may chu" }, { "102": "2.2.8.1. Thiet lap 'Microsoft network server: Amount of idle time required before suspending session'" }, { "103": "2.2.8.2. Thiet lap 'Microsoft network server: Disconnect clients when logon hours expire'" }, { "104": "2.2.8.3. Thiet lap 'Microsoft network server: Digitally sign communications (always)'" }, { "105": "2.2.8.4. Thiet lap 'Microsoft network server: Digitally sign communications (if client agrees)'" }, { "106": "2.2.8.5. Thiet lap 'Microsoft network server: Server SPN target name validation level' [Chỉ MS]" }, { "108": "2.2.9.1. Thiet lap 'Network access: Allow anonymous SID/Name translation'" }, { "109": "2.2.9.2. Thiet lap 'Network access: Do not allow anonymous enumeration of SAM accounts' [Chỉ MS]" }, { "110": "2.2.9.3. Thiet lap 'Network access: Do not allow anonymous enumeration of SAM accounts and shares' [Chỉ MS]" }, { "111": "2.2.9.4. Thiet lap 'Network access: Let Everyone permissions apply to anonymous users'" }, { "112": "2.2.9.5. Cau hinh 'Network access: Named Pipes that can be accessed anonymously' [Chỉ DC]" }, { "112": "2.2.9.5. Cau hinh 'Network access: Named Pipes that can be accessed anonymously' [Chỉ MS]" }, { "114": "2.2.9.6. Cau hinh 'Network access: Remotely accessible registry paths'" }, { "115": "2.2.9.7. Cau hinh 'Network access: Remotely accessible registry paths and sub-paths'" }, { "116": "2.2.9.8. Cau hinh 'Network access: Restrict anonymous access to Named Pipes and Shares'" }, { "117": "2.2.9.9. Cau hinh 'Network access: Shares that can be accessed anonymously'" }, { "118": "2.2.9.10. Cau hinh 'Network access: Sharing and security model for local accounts'" }, { "120": "2.2.10.1. Thiet lap 'Network security: Allow LocalSystem NULL session fallback'" }, { "121": "2.2.10.2. Thiet lap 'Network Security: Allow PKU2U authentication requests to this computer to use online identities'" }, { "122": "2.2.10.3. Thiet lap 'Network security: Configure encryption types allowed for Kerberos'" }, { "123": "2.2.10.4. Thiet lap 'Network security: Do not store LAN Manager hash value on next password change'" }, { "124": "2.2.10.5. Thiet lap 'Network security: Force logoff when logon hours expire'" }, { "125": "2.2.10.6. Thiet lap 'Network security: Allow Local System to use computer identity for NTLM'" }, { "126": "2.2.10.7. Thiet lap 'Network security: LAN Manager authentication level'" }, { "127": "2.2.10.8. Thiet lap 'Network security: LDAP client signing requirements'" }, { "128": "2.2.10.9. Thiet lap 'Network security: Minimum session security for NTLM SSP based (including secure RPC) clients'" }, { "129": "2.2.10.10. Thiet lap 'Network security: Minimum session security for NTLM SSP based (including secure RPC) servers'" }, { "131": "2.2.11.1. Thiet lap 'Shutdown: Allow system to be shut down without having to log on'" }, { "133": "2.2.12.1. Cau hinh chinh sach 'System objects: Require case insensitivity for non-Windows subsystems'" }, { "134": "2.2.12.2. Cau hinh chinh sach 'System objects: Strengthen default permissions of internal system objects'" }, { "136": "2.2.13.1. Thiet lap 'User Account Control: Admin Approval Mode for the Built-in Administrator account'" }, { "137": "2.2.13.2. Thiet lap 'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode'" }, { "138": "2.2.13.3. Thiet lap 'User Account Control: Detect application installations and prompt for elevation'" }, { "139": "2.2.13.4. Thiet lap 'User Account Control: Only elevate UIAccess applications that are installed in secure locations'" }, { "140": "2.2.13.5. Thiet lap 'User Account Control: Run all administrators in Admin Approval Mode'" }, { "141": "2.2.13.6. Thiet lap 'User Account Control: Switch to the secure desktop when prompting for elevation'" }, { "142": "2.2.13.7. Thiet lap 'User Account Control: Virtualize file and registry write failures to per-user locations'" }, { "143": "2.2.13.8. Thiet lap 'User Account Control: Behavior of the elevation prompt for standard users'" }, { "146": "3.1.1. Thiet lap trang thai 'Windows Firewall: Domain : Firewall state'" }, { "147": "3.1.2. Thiet lap trang thai 'Windows Firewall: Domain : Inbound connections'" }, { "148": "3.1.3. Thiet lap trang thai 'Windows Firewall: Domain : Outbound connections'" }, { "149": "3.1.4. Cau hinh vi tri luu tru nhat ky 'Windows Firewall: Domain: Logging: Name'" }, { "150": "3.1.5. Cau hinh kich thuoc gioi han 'Windows Firewall: Domain: Logging: Size limit (KB)'" }, { "151": "3.1.6. Thiet lap chinh sach 'Windows Firewall: Domain: Logging: Log dropped packets'" }, { "152": "3.1.7. Thiet lap chinh sach 'Windows Firewall: Domain: Logging: Log successful connections'" }, { "153": "3.1.8. Thiet lap chinh sach 'Windows Firewall: Domain: Settings: Display a notification'" }, { "155": "3.2.1. Thiet lap trang thai 'Windows Firewall: Private : Firewall state'" }, { "156": "3.2.2. Thiet lap trang thai 'Windows Firewall: Private : Inbound connections'" }, { "157": "3.2.3. Thiet lap trang thai 'Windows Firewall: Private : Outbound connections'" }, { "158": "3.2.4. Cau hinh vi tri luu tru nhat ky 'Windows Firewall: Private: Logging: Name'" }, { "159": "3.2.5. Cau hinh kich thuoc gioi han 'Windows Firewall: Private: Logging: Size limit (KB)'" }, { "160": "3.2.6. Thiet lap chinh sach 'Windows Firewall: Private: Logging: Log dropped packets'" }, { "161": "3.2.7. Thiet lap chinh sach 'Windows Firewall: Private: Logging: Log successful connections'" }, { "162": "3.2.8. Thiet lap trang thai 'Windows Firewall: Private: Settings: Display a notification'" }, { "164": "3.3.1. Thiet lap trang thai 'Windows Firewall: Public : Firewall state'" }, { "165": "3.3.2. Thiet lap trang thai 'Windows Firewall: Public : Inbound connections'" }, { "166": "3.3.3. Thiet lap trang thai 'Windows Firewall: Public : Outbound connections'" }, { "167": "3.3.4. Cau hinh vi tri luu tru nhat ky 'Windows Firewall: Public: Logging: Name'" }, { "168": "3.3.5. Cau hinh kich thuoc gioi han 'Windows Firewall: Public: Logging: Size limit (KB)'" }, { "169": "3.3.6. Thiet lap chinh sach 'Windows Firewall: Public: Logging: Log dropped packets'" }, { "170": "3.3.7. Thiet lap chinh sach 'Windows Firewall: Public: Logging: Log successful connections'" }, { "171": "3.3.8. Thiet lap trang thai 'Windows Firewall: Public: Settings: Display a notification'" }, { "172": "3.3.9. Thiet lap trang thai 'Windows Firewall: Public: Settings: Apply local connection security rules'" }, { "175": "4.1.1. Cau hinh chinh sach 'Audit Credential Validation'" }, { "176": "4.1.2. Cau hinh chinh sach 'Audit Kerberos Authentication Service' [Chỉ DC]" }, { "177": "4.1.3. Cau hinh chinh sach 'Audit Kerberos Service Ticket Operations' [Chỉ DC]" }, { "179": "4.2.1. Cau hinh chinh sach 'Audit Application Group Management'" }, { "180": "4.2.2. Cau hinh chinh sach 'Audit Computer Account Management' [Chỉ DC]" }, { "181": "4.2.3. Cau hinh chinh sach 'Audit Distribution Group Management' [Chỉ DC]" }, { "182": "4.2.4. Cau hinh chinh sach 'Audit Other Account Management Events' [Chỉ DC]" }, { "183": "4.2.5. Cau hinh chinh sach 'Audit Security Group Management'" }, { "184": "4.2.6. Cau hinh chinh sach 'Audit User Account Management'" }, { "186": "4.3.1. Cau hinh chinh sach 'Audit Process Creation'" }, { "187": "4.3.2. Cau hinh chinh sach 'Audit PNP Activity'" }, { "189": "4.4.1. Cau hinh chinh sach 'Audit Directory Service Access' [Chỉ DC]" }, { "190": "4.4.2. Cau hinh chinh sach 'Audit Directory Service Changes' [Chỉ DC]" }, { "192": "4.5.1. Cau hinh chinh sach 'Audit Account Lockout'" }, { "193": "4.5.2. Cau hinh chinh sach 'Audit Logoff'" }, { "194": "4.5.3. Cau hinh chinh sach 'Audit Logon'" }, { "195": "4.5.4. Cau hinh chinh sach 'Audit Other Logon/Logoff Events'" }, { "196": "4.5.5. Cau hinh chinh sach 'Audit Special Logon'" }, { "197": "4.5.6. Cau hinh chinh sach 'Audit Group Membership'" }, { "199": "4.6.1. Cau hinh chinh sach 'Audit Detailed File Share'" }, { "200": "4.6.2. Cau hinh chinh sach 'Audit File Share'" }, { "201": "4.6.3. Cau hinh chinh sach 'Audit Other Object Access Events'" }, { "202": "4.6.4. Cau hinh chinh sach 'Audit Removable Storage'" }, { "204": "4.7.1. Cau hinh chinh sach 'Audit Audit Policy Change'" }, { "205": "4.7.2. Cau hinh chinh sach 'Audit Authentication Policy Change'" }, { "206": "4.7.3. Cau hinh chinh sach 'Audit Authorization Policy Change'" }, { "207": "4.7.4. Cau hinh chinh sach 'Audit MPSSVC Rule-Level Policy Change'" }, { "208": "4.7.5. Cau hinh chinh sach 'Audit Other Policy Change Events'" }, { "210": "4.8.1. Cau hinh chinh sach 'Audit Sensitive Privilege Use'" }, { "212": "4.9.1. Cau hinh chinh sach 'Audit IPsec Driver'" }, { "213": "4.9.2. Cau hinh chinh sach 'Audit Other System Events'" }, { "214": "4.9.3. Cau hinh chinh sach 'Audit Security State Change'" }, { "215": "4.9.4. Cau hinh chinh sach 'Audit Security System Extension'" }, { "216": "4.9.5. Cau hinh chinh sach 'Audit System Integrity'" }, { "219": "5.1.1. Cau hinh chinh sach 'Turn off app notifications on the lock screen'" }, { "220": "5.1.2. Cau hinh chinh sach 'Turn off picture password sign-in'" }, { "221": "5.1.3. Cau hinh chinh sach 'Turn on convenience PIN sign-in'" }, { "222": "5.1.4. Cau hinh chinh sach 'Block user from showing account details on sign-in'" }, { "223": "5.1.5. Cau hinh chinh sach 'Do not display network selection UI'" }, { "224": "5.1.6. Cau hinh chinh sach 'Do not enumerate connected users on domain joined computers'" }, { "225": "5.1.7. Cau hinh chinh sach 'Enumerate local users on domain-joined computers'" }, { "227": "5.2.1. Cau hinh chinh sach 'Require a password when a computer wakes (on battery)'" }, { "228": "5.2.2. Cau hinh chinh sach 'Require a password when a computer wakes (plugged in)'" }, { "230": "5.3.1. Cau hinh chinh sach 'Disallow Autoplay for non-volume devices'" }, { "231": "5.3.2. Cau hinh chinh sach 'Set the default behavior for AutoRun'" }, { "232": "5.3.3. Cau hinh chinh sach 'Turn off Autoplay'" }, { "235": "5.4.1.1. Thiet lap chinh sach 'Application : Control Event Log behavior when the log file reaches its maximum size'" }, { "236": "5.4.1.2. Thiet lap chinh sach 'Application : Specify the maximum log file size (KB)'" }, { "238": "5.4.2.1. Thiet lap chinh sach 'Security : Control Event Log behavior when the log file reaches its maximum size'" }, { "239": "5.4.2.2. Thiet lap chinh sach 'Security : Specify the maximum log file size (KB)'" }, { "241": "5.4.3.1. Thiet lap chinh sach 'Setup : Control Event Log behavior when the log file reaches its maximum size'" }, { "242": "5.4.3.2. Thiet lap chinh sach 'Setup : Specify the maximum log file size (KB)'" }, { "244": "5.4.4.1. Thiet lap chinh sach 'System : Control Event Log behavior when the log file reaches its maximum size'" }, { "245": "5.4.4.2. Thiet lap chinh sach 'System : Specify the maximum log file size (KB)'" } ] }