18.10.16.5 Ensure 'Limit Diagnostic Log Collection' is set to 'Enabled'

Information

This policy setting controls whether additional diagnostic logs are collected when more information is needed to troubleshoot a problem on the device.

The recommended state for this setting is: Enabled.

Note: Diagnostic logs are only sent when the device has been configured to send optional diagnostic data. Diagnostic data is limited when recommendation Allow Diagnostic Data is set to Enabled: Diagnostic data off (not recommended) or Enabled: Send required diagnostic data to send only basic information.

In high-security environments, data must never be shared with third-parties without explicit consent, as it may contain sensitive information.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\Data Collection and Preview Builds\Limit Diagnostic Log Collection

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template DataCollection.admx/adml that is included with the Microsoft Windows 11 Release 21H2 Administrative Templates (or newer).

Impact:

Diagnostic logs and information such as crash dumps will not be collected for transmission to Microsoft.

See Also

https://workbench.cisecurity.org/benchmarks/25733

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: Windows

Control ID: 73b5b9c838c171b9718531b961a48dba6dede0c1dffe75283df86b129b047bfa