Information
This policy setting enables a remote user to log on to this computer and run programs, and supports various TCP/IP Telnet clients, including UNIX-based and Windows-based computers.
The STIG recommended state for this setting is: Not Installed
Note: This service is not installed by default. It is supplied with Windows, but is installed by enabling an optional Windows feature (_Telnet Client).
Hosting a Telnet server (especially a non-secure Telnet) from a workstation is an increased security risk, as the attack surface of that workstation is then greatly increased.
Note: This security concern applies to any Telnet application installed on a workstation, not just the one supplied with Windows.
Solution
To establish the recommended configuration, navigate to the the following and Uninstall the Telnet Client feature:
To Uninstall the Telnet Client feature:
 - Start
Server Manager
 - Select the server with the role
 - Scroll down to
ROLES AND FEATURES
in the right pane
 - Select
Remove Roles and Features
from the drop-down
TASKS
list
 - Select the appropriate server on the
Server Selection
page and click
Next
 - Deselect
Telnet Client
on the
Features
page
 - Click
Next
and
Remove
as prompted (if installed).
Impact:
Remote user Telnet access will not be available.