4.11.10.2 (L1) Ensure 'Enable App Installer Hash Override' is set to 'Disabled'

Information

This policy setting controls whether or not users can override the SHA256 security validation in the Windows Package Manager settings.

The recommended state for this setting is: Disabled

Users should not have the ability to override SHA256 security validation.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Disabled :

Administrative Templates\Windows Components\Desktop App Installer\Enable App Installer Hash Override

Impact:

Users will not have the ability to override the SHA256 security validation.

See Also

https://workbench.cisecurity.org/benchmarks/21719

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 34eeeb8e6a35d7db2cc9131d2c4177c1124c55b045aa1ca2b7217342c37149ab