18.9.108.1.2 Ensure 'Do not display 'Install Updates and Shut Down' option in Shut Down Windows dialog box' is set to 'Disabled'

Information

This policy setting allows you to manage whether the 'Install Updates and Shut Down' option is displayed in the Shut Down Windows dialog box.

The recommended state for this setting is: Disabled.

Rationale:

Installing security updates is very important for maintaining the ongoing security of a computer. This setting should not be Enabled, to therefore keep the 'Install Updates and Shut Down' option available (when applicable), which helps to encourage the installation of pending updates when a user shuts down their computer.

Impact:

None - this is the default behavior.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

Computer Configuration\Policies\Administrative Templates\Windows Components\Windows Update\Legacy Policies\Do not display 'Install Updates and Shut Down' option in Shut Down Windows dialog box

Note: This Group Policy path is provided by the Group Policy template WindowsUpdate.admx/adml that is included with all versions of the Microsoft Windows Administrative Templates.

Default Value:

Disabled. (The 'Install Updates and Shut Down' option will be available in the Shut Down Windows dialog box if updates are available when the user selects the Shut Down option in the Start menu.)

See Also

https://workbench.cisecurity.org/files/4022

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4

Plugin: Windows

Control ID: 84589f35b9dce8ac0349166ea7b355bbc217bf4edc057f1aa9023049ad1023b4