30.3 (L2) Ensure 'Allow Windows Spotlight (User)' is set to 'Block'

Information

This policy setting determines whether the all Windows Spotlight features are turned on/off (together).

The recommended state for this setting is: Block

Note:

Per Microsoft TechNet

, this policy setting only applies to Windows 10 Enterprise and Windows 10 Education editions.

Note #2: Setting this recommendation to Block also disables the Recommendation Allow Tailored Experiences With Diagnostic Data which was is included in the on-prem Workstation Benchmarks. It was not included in the Intune version since this setting is automatically disabled.

Disabling this setting will help ensure your data is not shared with any third party. The Windows Spotlight feature collects data and uses that data to display suggested apps as well as images from the internet.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Block :

Experience\Allow Windows Spotlight (User)

Impact:

Windows Spotlight on lock screen, Windows tips, Microsoft consumer features and other related features will be turned off.

See Also

https://workbench.cisecurity.org/benchmarks/16853

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 4a0dc4a383e65190816467b3081f4c1f8e879bf79b213665f12a3d85c54403c3