18.10.12.1 Ensure 'Turn off cloud consumer account state content' is set to 'Enabled' - Enabled

Information

This policy setting determines whether cloud consumer account state content is allowed in all Windows experiences.

The recommended state for this setting is: Enabled.

Rationale:

The use of consumer accounts in an enterprise managed environment is not good security practice as it could lead to possible data leakage.

Impact:

Users will not be able to use Microsoft consumer accounts on the system, and associated Windows experiences will instead present default fallback content.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:

Computer Configuration\Policies\Administrative Templates\Windows Components\Cloud Content\Turn off cloud consumer account state content

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template CloudContent.admx/adml that is included with the Microsoft Windows 11 Release 21H2 Administrative Templates (or newer).

Default Value:

Disabled. (Windows experiences are able to use cloud consumer accounts.)

See Also

https://workbench.cisecurity.org/benchmarks/13204

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2(1)

Plugin: Windows

Control ID: a3b89df2537c9d973b356b547f89c27cdad5579b8c9caf78f6bedfe5dfb5c992