18.10.3.1 (L2) Ensure 'Turn off API Sampling' is set to 'Enabled'

Information

This policy setting determines if API data sampling is sent to Microsoft. API sampling monitors the sampled collection of APIs used during system runtime to help diagnose compatibility problems in Windows.

The recommended state for this setting is: Enabled

Due to privacy concerns, data should never be sent to any third-party since this data could contain sensitive information.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\App and Device Inventory\Turn off API Sampling

Note: This Group Policy path is provided by the Group Policy template AppDeviceInventory.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).

Impact:

API data sampling will not be sent to Microsoft.

See Also

https://workbench.cisecurity.org/benchmarks/21318

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Windows

Control ID: a0811a75876f019d2a97da276c87e8115f8cf4e82d182690651ce34399cd01df