Skip to content

fix: make all Windows baselines enforceable - #119

Merged
Amir Bredy (ABMFST) merged 3 commits into
mainfrom
fix/windows-baseline-enforcement-v03103
Aug 10, 2026
Merged

fix: make all Windows baselines enforceable#119
Amir Bredy (ABMFST) merged 3 commits into
mainfrom
fix/windows-baseline-enforcement-v03103

Conversation

@ABMFST

Copy link
Copy Markdown
Contributor

Summary

  • convert Windows Server 2016/2019 account-policy and value-less controls to safe Test wrappers
  • accept effective unset firewall defaults on Windows Server 2022 domain profiles
  • treat role-managed Windows Server 2025 NTP client state as informational
  • prepare the Windows/Linux v0.3.103 prerelease

Validation

  • native Azure matrix across Server 2016, 2019, 2022, and 2025
  • domain controller, domain member, and workgroup role per generation (12 baselines total)
  • every Audit report matched its exact resource count with zero unread entries
  • every ApplyAndAutoCorrect report finished Compliant with zero noncompliant resources
  • UseMachineId regression probe changed from 0 to 1 on every target
  • all 24 Machine Configuration packages embedded Microsoft.OSConfig 1.4.3

Local constraints

  • npm was not run locally per corporate IT policy; hosted PR checks are the authoritative build/test/lint gate

Amir Bredy added 3 commits August 9, 2026 20:19
Use safe Test wrappers for legacy account-policy and value-less controls, accept effective firewall defaults, and treat role-managed NTP state as informational. The full 12-baseline Azure Machine Configuration matrix passes Audit and ApplyAndAutoCorrect with OSConfig 1.4.3.

Co-authored-by: Copilot <[email protected]>

Copilot-Session: 48993ee6-f068-4c4a-b317-2cd940fab804
Publish the fully validated Windows baseline enforcement repairs and align Full-edition package metadata and public documentation for the new Windows/Linux prerelease.

Co-authored-by: Copilot <[email protected]>

Copilot-Session: 48993ee6-f068-4c4a-b317-2cd940fab804
Keep the deterministic WS2022 repair generator aligned with the validated domain firewall expressions so hosted tests do not regenerate strict assertions for unset DefaultInboundAction values.

Co-authored-by: Copilot <[email protected]>

Copilot-Session: 48993ee6-f068-4c4a-b317-2cd940fab804
@ABMFST
Amir Bredy (ABMFST) merged commit ce52036 into main Aug 10, 2026
11 checks passed
@ABMFST
Amir Bredy (ABMFST) deleted the fix/windows-baseline-enforcement-v03103 branch August 10, 2026 03:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant