3.7 Ensure 'Refresh interval' is set to '1'

Information

This policy setting specifies how often in hours, that policy settings are refreshed.

Rationale:

Organizational requirements change, and new vulnerabilities may be discovered, so it is likely that ActiveSync policy settings will change. For these reasons, it is important to configure a refresh interval to ensure that the latest policy settings are applied to the devices in your organization.

Impact:

Clients will attempt to acquire the latest policy at a shorter interval impacting server and client bandwidth.

Note: This is a mobile device management setting. Use caution when applying these settings as they could have adverse effects depending on the environment, and internal policies around bring your own device (BYOD). These policies could affect a user's BYOD.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-MobileDeviceMailboxPolicy 'Profile' -DevicePolicyRefreshInterval '1:00:00'

Default Value:

24 hours

See Also

https://workbench.cisecurity.org/benchmarks/12442

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-19

Plugin: Windows

Control ID: 5a4071af2d7dad84879bde53f8076a82a4b6dc8c125cbb23bb9da46dcadf03ed