4.1.4 Ensure 'Configure the required domain names for remote access clients' is set to 'Enabled' with a domain defined

Information

Chrome allows the user to configure a list of required host domain that is imposed on remote access hosts. When enabled, hosts can only be shared using accounts that are registered to the specified domains.
Rationale:
Remote assistance connections shall be restricted.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled and enter a domain (e.g. nodomain.local):
Computer Configuration\Administrative Templates\Google\Google Chrome\Configure remote access options\Configure the required domain names for remote access clients
Impact:
If this setting is enabled, clients from the specified domains only can connect to the host.
Default Value:
Disabled.

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17, CSCv7|9

Plugin: Windows

Control ID: e08df21744600fe7cced1202578403c9c223ad6cfdfebe18f2d9d02d003dc8ef