18.9.19.5 (L1) Ensure 'Configure security policy processing: Process even if the Group Policy objects have not changed' is set to 'Enabled: TRUE'

Information

The 'Process even if the Group Policy objects have not changed' option updates and reapplies security policies even if the security policies have not changed.

This setting affects all policy settings within the built-in security template of Group Policy (e.g. Windows Settings\Security Settings).

The recommended state for this setting is: Enabled: TRUE (checked).

Setting this option to true (checked) will ensure unauthorized local changes are reverted to match the domain-based Group Policy settings.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled then set the Process even if the Group Policy objects have not changed option to TRUE (checked):

Computer Configuration\Policies\Administrative Templates\System\Group Policy\Configure security policy processing

Note: This Group Policy path is provided by the Group Policy template GroupPolicy.admx/adml that is included with the Microsoft Windows 8.0 & Server 2012 (non-R2) Administrative Templates (or newer).

Impact:

Built-in security template settings will be reapplied even if they have not been changed, which may cause Group Policy refreshes to take longer.

See Also

https://workbench.cisecurity.org/benchmarks/16514

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

References: 800-53|CM-1, 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.4

Plugin: Windows

Control ID: d799ad4d64b706f7ba6d5e760b5722ea2f9e91fdf75b2f9285ee8b9afeb5b34b