22.31 (L2) Ensure 'Remote Encryption Protection Aggressiveness' is set to 'Medium' or higher

Information

This policy setting configures how aggressively Remote Encryption Prevention Protection blocks malicious IP addresses.

The recommended state for this setting is: Medium: Use cloud aggregation and block when confidence level is above 99% or higher. Configuring this setting to High: Use cloud intel and context, and block when confidence level is above 90% also conforms to the benchmark.

Note: As of the publication of this Benchmark, the setting configuration state in Intune is the sentence above after

The recommended state for this setting is:

and not

Medium

or higher as the title states. This was done to keep title length to a minimum.

This feature can help reduce the likelihood of users visiting malicious websites.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Medium: Use cloud aggregation and block when confidence level is above 99% or High: Use cloud intel and context, and block when confidence level is above 90%

Defender\Remote Encryption Protection Aggressiveness

Impact:

Legitimate websites could be blocked by Remote Encryption Prevention Protection. When set to Medium, blocks will occur when the confidence level is above 99%. When set to High, blocks will occur when confidence level is above 90%.

See Also

https://workbench.cisecurity.org/benchmarks/21719

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: 8a8d783194c27bc0a3001868450df129183c8b4389c28a5aa667ca2d89c998df