Enable svchost.exe mitigation options

Information

This policy setting enables process mitigation options on svchost.exe processes.
If you enable this policy setting, built-in system services hosted in svchost.exe processes will have stricter security policies enabled on them.
This includes a policy requiring all binaries loaded in these processes to be signed by microsoft, as well as a policy disallowing dynamically-generated code.
If you disable or do not configure this policy setting, these stricter security settings will not be applied.

Solution

Policy Path: System\Service Control Manager Settings\Security Settings
Policy Setting Name: Enable svchost.exe mitigation options

See Also

https://blogs.technet.microsoft.com/secguide/2019/05/23/security-baseline-final-for-windows-10-v1903-and-windows-server-v1903/

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6

Plugin: Windows

Control ID: 7503ba8657de8c28c73c3cced105027e3b7c69997d90814d832f6af6f52b8b99