18.10.42.12.1 Ensure 'Configure Watson events' is set to 'Disabled'

Information

This policy setting determines whether or not Watson events are sent to Microsoft. Watson events are the reports that get sent to Microsoft when a program or service crashes or fails, including the possibility of automatic submission.

The recommended state for this setting is: Disabled.

In high-security environments, data must never be shared with third-parties without explicit consent, as it may contain sensitive information.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Reporting\Configure Watson events

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template WindowsDefender.admx/adml that is included with the Microsoft Windows 8.1 & Server 2012 R2 Administrative Templates (or newer).

Impact:

Watson events will not be sent to Microsoft automatically when a program or service crashes or fails.

See Also

https://workbench.cisecurity.org/benchmarks/25708

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION

References: 800-53|CA-7, CSCv7|13.3

Plugin: Windows

Control ID: 4ebabb30000878176b128b1ad645836e8e9385669350e9d56e984fa071aa3542