5.2 Ensure 'Computer Browser (Browser)' is set to 'Disabled' or 'Not Installed'

Information

Maintains an updated list of computers on the network and supplies this list to computers designated as browsers.

The recommended state for this setting is: 'Disabled' or 'Not Installed'.

Note: In Windows 8.1 and Windows 10, this service is bundled with the _SMB 1.0/CIFS File Sharing Support_ optional feature.

As a result, removing that feature (highly recommended unless backward compatibility is needed to XP/2003 and older Windows OSes - see [Stop using SMB1 | Storage at Microsoft](https://blogs.technet.microsoft.com/filecab/2016/09/16/stop-using-smb1/)) will also remediate this recommendation.

The feature is not installed by default starting with Windows 10 R1709.

Rationale:
This is a legacy service - its sole purpose is to maintain a list of computers and their network shares in the environment (i.e.

'Network Neighborhood').

If enabled, it generates a lot of unnecessary traffic, including 'elections' to see who gets to be the 'master browser'.

This noisy traffic could also aid malicious attackers in discovering online machines, because the service also allows anyone to 'browse' for shared resources without any authentication.

This service used to be running by default in older Windows versions (e.g.

Windows XP), but today it only remains for backward compatibility for very old software that requires it.

Solution

To establish the recommended configuration via GP, set the following UI path to: 'Disabled'.


Computer Configuration\Policies\Windows Settings\Security Settings\System Services\Computer Browser


Impact:
The list of computers and their shares on the network will not be updated or maintained.

See Also

https://workbench.cisecurity.org/files/1929

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Windows

Control ID: 6ef417902e9559a8c32f5508abca31b0aa630f61fce38909426df9db588ec27b