61.1 (L2) Ensure 'Disallow Cloud Notification' is set to 'Allow'

Information

This policy setting blocks applications from using the network to send notifications to update tiles, tile badges, toast, or raw notifications. This policy setting turns off the connection between Windows and the Windows Push Notification Service (WNS). This policy setting also stops applications from being able to poll application services to update tiles.

The recommended state for this setting is: Allow

Windows Push Notification Services (WNS) is a mechanism to receive third-party notifications and updates from the cloud/Internet. In a high security environment, external systems, especially those hosted outside the organization, should be prevented from having an impact on the secure workstations.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Allow

Notifications\Disallow Cloud Notification

Impact:

Applications and system features will not be able receive notifications from the network from WNS or via notification polling APIs.

See Also

https://workbench.cisecurity.org/benchmarks/21719

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv7|9.2

Plugin: Windows

Control ID: ba7999f9571f557fe321ff38fe48eb768f1b3da28c50f5d09ef32e769163c77f