15.1 (L1) Ensure 'Config refresh' is set to 'Enabled'

Information

This policy setting determines whether or not MDM policies are refreshed on the system.

The recommended state for this setting is: Enabled

Policy CSP settings should be set to refresh at regular intervals to ensure constant compliance and to reduce policy drift. This helps to ensure systems stay in compliance.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled

Config Refresh\Config refresh

Impact:

Microsoft's tech community blog confirms that performance testing was done before the feature's release, showing minimal impact on CPU, RAM, and battery even when the refresh cadence is set to 30 minutes.

See Also

https://workbench.cisecurity.org/benchmarks/21719

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

References: 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.4

Plugin: Windows

Control ID: 03e33648bd96a8f69c2dcf37f01fbbc944451f9c880bdb11fcfba1ad0bdaa618