3.10.25.5 (L1) Ensure 'Turn off app notifications on the lock screen' is set to 'Enabled'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This policy setting allows you to prevent app notifications from appearing on the lock screen.

The recommended state for this setting is: Enabled

Warning: If the

Self Service Password Reset (SSPR)

feature is used in Microsoft Entra ID, an exception to this recommendation is needed as it's known to interfere with SSPR.

App notifications might display sensitive business or personal data.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled

Administrative Templates\System\Logon\Turn off app notifications on the lock screen

Impact:

No app notifications are displayed on the lock screen.

See Also

https://workbench.cisecurity.org/benchmarks/16853