1.123 WN19-CC-000300

Information

Windows Server 2019 Windows Defender SmartScreen must be enabled.

GROUP ID:V-205692
RULE ID:SV-205692r958478

Windows Defender SmartScreen helps protect systems from programs downloaded from the internet that may be malicious. Enabling SmartScreen can block potentially malicious programs or warn users.

Solution

Configure the policy value for

Computer Configuration >> Administrative Templates >> Windows Components >> File Explorer >> 'Configure Windows Defender SmartScreen' to 'Enabled' with either option 'Warn' or 'Warn and prevent bypass' selected.

Windows 2019 includes duplicate policies for this setting. It can also be configured under

Computer Configuration >> Administrative Templates >> Windows Components >> Windows Defender SmartScreen >> Explorer.

See Also

https://workbench.cisecurity.org/benchmarks/22176