55.3 (L2) Ensure 'Allow Shared User App Data' is set to 'Block'

Information

Manages a Windows app's ability to share data between users who have installed the app. Data is shared through the SharedLocal folder. This folder is available through the Windows.Storage API.

The recommended state for this setting is: Block

Users of a system could accidentally share sensitive data with other users on the same system.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Block

Microsoft App Store\Allow Shared User App Data

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/21719

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CSCv7|14.6

Plugin: Windows

Control ID: 5f569414aa59c81b0d84e55576611b1ecaadd619e4fafc39e7f53a85da85e200