18.10.3.2 (L2) Ensure 'Turn off Application Footprint' is set to 'Enabled'

Information

This policy setting determines if Application Footprint data is sent to Microsoft. Application Footprint monitors a sampled collection of registry and file activity to help diagnose compatibility problems.

The recommended state for this setting is: Enabled

Due to privacy concerns, data should never be sent to any third-party since this data could contain sensitive information.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\App and Device Inventory\Turn off Application Footprint

Note: This Group Policy path is provided by the Group Policy template AppDeviceInventory.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).

Impact:

Data from Application Footprint sampling will not be sent to Microsoft.

See Also

https://workbench.cisecurity.org/benchmarks/22007

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Windows

Control ID: 9d71c500849e703ee24fa673f3f3aa6ee7a09126cc5fa9a0f83b48e43ad1ec7e