18.9.35.1 Ensure 'Prevent the computer from joining a homegroup' is set to 'Enabled'

Information

By default, users can add their computer to a HomeGroup on a home network.

The recommended state for this setting is: 'Enabled'.

Rationale:
While resources on a domain-joined computer cannot be shared with a HomeGroup, information from the domain-joined computer can be leaked to other computers in the HomeGroup.

Solution

To establish the recommended configuration via GP, set the following UI path to 'Enabled':


Computer Configuration\Policies\Administrative Templates\Windows Components\HomeGroup\Prevent the computer from joining a homegroup


Note: This Group Policy path may not exist by default.

It is provided by the Group Policy template 'Sharing.admx/adml' that is included with the Microsoft Windows 7 & Server 2008 R2 Administrative Templates (or newer).

Impact:
A user on this computer will not be able to add this computer to a HomeGroup.

This setting does not affect other network sharing features.

Mobile users who access printers and other shared devices on their home networks will not be able to leverage the ease of use provided by HomeGroup functionality.

See Also

https://workbench.cisecurity.org/files/1929

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|3.1, CSCv6|14.1

Plugin: Windows

Control ID: 19925ad5619b12b1c17bbe90e40a4dc8856ee0230c17787d47a4d2c199f338b3