18.5.4.2 Ensure 'Turn off multicast name resolution' is set to 'Enabled'

Information

This policy setting determines whether to require domain users to elevate when setting a network's location.

The recommended state for this setting is: 'Enabled'.

Rationale:
Allowing regular users to set a network location increases the risk and attack surface.

Solution

To establish the recommended configuration via GP, set the following UI path to 'Enabled':


Computer Configuration\Policies\Administrative Templates\Network\Network Connections\Require domain users to elevate when setting a network's location


Note: This Group Policy path may not exist by default.

It is provided by the Group Policy template 'NetworkConnections.admx/adml' that is included with the Microsoft Windows 7 & Server 2008 R2 Administrative Templates (or newer).

Impact:
Domain users must elevate when setting a network's location.

See Also

https://workbench.cisecurity.org/files/1929

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Windows

Control ID: 457f86cafaad23804033af201c369b4711ae882939231e1561d9e2aefdcc8d52