69.13 (L1) Ensure 'OpenSSH SSH Server (sshd)' is set to 'Disabled' or 'Not Installed'

Information

SSH protocol based service to provide secure encrypted communications between two untrusted hosts over an insecure network.

The recommended state for this setting is: Disabled or Not Installed

Note: This service is not installed by default. It is supplied with Windows, but it is installed by enabling an optional Windows feature (

OpenSSH Server

).

Hosting an SSH server from a workstation is an increased security risk, as the attack surface of that workstation is then greatly increased.

Note: This security concern applies to

any

SSH server application installed on a workstation, not just the one supplied with Windows.

Solution

Remediation of this service is currently not possible through Settings Catalog or a custom profile OMA-URI. Instead, it can be scripted and deployed through the Intune Scripts or Remediations blade or by other means.

To establish the recommended configuration via PowerShell, run the following cmdlet:

Set-Service -Name sshd -StartupType Disabled

Impact:

The workstation will not be permitted to be a SSH host server.

See Also

https://workbench.cisecurity.org/benchmarks/16853

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 1d86bb290096741329382c4ec5e55c383cebce26366c88e0d93d5bc9bddc75ea