Rule version WN25-SH-000080 · STIG v1 · 2026-09-01
Service configuration files enable or disable features of their respective services, which if configured incorrectly can lead to insecure and vulnerable configurations. Therefore, service configuration files must be owned by the correct group to prevent unauthorized changes.
If OpenSSH is not installed on the system, this requirement is not applicable.
Verify the permissions of the "$env:ProgramData/ssh/sshd_config" file with the following command:
C:\ > icacls $env:ProgramData/ssh/sshd_config
C:\ProgramData\ssh\sshd_config NT AUTHORITY\SYSTEM:(F) BUILTIN\Administrators:(F) NT AUTHORITY\Authenticated Users:(RX)
Successfully processed 1 files; Failed processing 0 files
If the "$env:ProgramData/ssh/sshd_config" file does not have the default permission as in the example output, this is a finding.
Maintain the permissions of the "$env:ProgramData/ssh/sshd_config" file as follows:
NT AUTHORITY\SYSTEM:(F) BUILTIN\Administrators:(F) NT AUTHORITY\Authenticated Users:(RX)