18.10.29.2 (L1) Ensure 'Do not apply the Mark of the Web tag to files copied from insecure sources' is set to 'Disabled'

Information

This policy setting determines whether files that are sourced from insecure locations are tagged with Mark of the Web (MOTW).

The recommended state for this setting is: Disabled

MOTW is an important security feature that ensures files from insecure locations are treated with extra caution and are tagged with MOTW. If files are left untagged, users and computers could be exposed to security risks.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\File Explorer\Do not apply the Mark of the Web tag to files copied from insecure sources

Note: This Group Policy path is provided by the Group Policy template Explorer.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/21344

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: df69823abf1327702d1aca916f75a39017a4b8cf47d059b6dc2bcf8be87b780c