3.11.28.10.1 (L2) Ensure 'Configure Watson events' is set to 'Disabled'

Information

This policy setting allows you to configure whether or not Watson events are sent.

The recommended state for this setting is: Disabled

Watson events are the reports that get sent to Microsoft when a program or service crashes or fails, including the possibility of automatic submission. Preventing this information from being sent can help reduce privacy concerns.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Disabled

Administrative Templates\Windows Components\Microsoft Defender Antivirus\Reporting\Configure Watson events

Impact:

Watson events will not be sent to Microsoft automatically when a program or service crashes or fails.

See Also

https://workbench.cisecurity.org/benchmarks/16853

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION

References: 800-53|CA-7, CSCv7|13.3

Plugin: Windows

Control ID: b4ad251100fafe0f2df825679d230d8a14ad5aae482508971fd5f08c99135076