18.8.31.1 Ensure 'Allow Clipboard synchronization across devices' is set to 'Disabled'

Information

This setting determines whether Clipboard contents can be synchronized across devices.

The recommended state for this setting is: Disabled.

Rationale:

In high security environments, clipboard data should stay local to the system and not synced across devices, as it may contain very sensitive information that must be contained locally.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

Computer Configuration\Policies\Administrative Templates\System\OS Policies\Allow Clipboard synchronization across devices

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template OSPolicy.admx/adml that is included with the Microsoft Windows 10 Release 1809 & Server 2019 Administrative Templates (or newer).

Impact:

Clipboard contents will not be shareable to other devices.

Default Value:

Enabled. (Clipboard contents are allowed to be synchronized across devices logged in under the same Microsoft account or Azure AD account.)

See Also

https://workbench.cisecurity.org/files/2651