18.9.33.1 (L1) Ensure 'Prevent the computer from joining a homegroup' is set to 'Enabled'

Information

By default, users can add their computer to a HomeGroup on a home network.

The recommended state for this setting is: Enabled.

Rationale:

While resources on a domain-joined computer cannot be shared with a HomeGroup, information from the domain-joined computer can be leaked to other computers in the HomeGroup.

Solution

To establish the recommended configuration via GP, set the following Group Policy setting to Enabled:

Computer Configuration\Policies\Administrative Templates\Windows Components\HomeGroup\Prevent the computer from joining a homegroup


Impact:

A user on this computer will not be able to add this computer to a HomeGroup. This setting does not affect other network sharing features. Mobile users who access printers and other shared devices on their home networks will not be able to leverage the ease of use provided by HomeGroup functionality.

Default Value:

Disabled. (A user can add their computer to a HomeGroup. However, data on a domain-joined computer is not shared with the HomeGroup.)

See Also

https://workbench.cisecurity.org/files/1721