81.4 (L2) Ensure 'Downloaded Maps Manager (MapsBroker)' is set to 'Disabled'

Information

Windows service for application access to downloaded maps. This service is started on-demand by application accessing downloaded maps.

Mapping technologies can unwillingly reveal your location to attackers and other software that picks up the information. In addition, automatic downloads of data from third-party sources should be minimized when not needed. Therefore, this service should not be needed in high security environments.

Solution

Remediation of this service is currently not possible through Settings Catalog or a custom profile OMA-URI. Instead, it can be scripted and deployed through the Intune Scripts or Remediations blade or by other means.

To establish the recommended configuration via PowerShell, run the following cmdlet:

Set-Service -Name MapsBroker -StartupType Disabled

Impact:

Applications will be prevented from accessing maps data.

See Also

https://workbench.cisecurity.org/benchmarks/21719

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 1f83cfbc02b92e3ed463fef038dcebc1de01e0f73211889461d9d261a4c3f3ea