4.11.10.3 (L1) Ensure 'Enable App Installer ms-appinstaller protocol' is set to 'Disabled'

Information

This policy setting controls whether users can install packages from a website that is using the ms-appinstaller protocol. The ms-appinstaller protocol allows users to install an application by clicking a link on a website.

The recommended state for this setting is: Disabled

Users should not have the ability to install an application by clicking a link on a website. If an unknown or malicious link is clicked, malicious software could be installed on the system.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Disabled :

Administrative Templates\Windows Components\Desktop App Installer\Enable App Installer ms-appinstaller protocol

Impact:

Users will not have the ability to use the ms-appinstaller protocol to install applications by clicking a link on a website.

See Also

https://workbench.cisecurity.org/benchmarks/21719

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: f2c047dc599abf0c0dda39fc6320c33d73b6a3545a87cc1e520cf53d1d8cbac8