18.5.21.1 Ensure 'Minimize the number of simultaneous connections to the Internet or a Windows Domain' is set to 'Enabled'

Information

This policy setting prevents computers from connecting to both a domain based network and a non-domain based network at the same time.

The recommended state for this setting is: 'Enabled'.

Rationale:
Blocking simultaneous connections can help prevent a user unknowingly allowing network traffic to flow between the Internet and the enterprise managed network.

Solution

To establish the recommended configuration via GP, set the following UI path to 'Enabled':


Computer Configuration\Policies\Administrative Templates\Network\Windows Connection Manager\Minimize the number of simultaneous connections to the Internet or a Windows Domain


Note: This Group Policy path may not exist by default. It is provided by the Group Policy template 'WCM.admx/adml' that is included with the Microsoft Windows 8.0 & Server 2012 (non-R2) Administrative Templates (or newer).

Impact:
None - this is the default behavior.

See Also

https://workbench.cisecurity.org/files/1949

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5(2), CCE|CCE-38338-0, CSCv6|12

Plugin: Windows

Control ID: 60ac76f89ddefe10bb24ea549d0ffcc2a7ac2255f8ed83db9b254e61c4c942c3