18.9.69.1 Ensure 'Turn off Automatic Download and Install of updates' is set to 'Disabled'

Information

This setting enables or disables the automatic download and installation of Microsoft Store app updates.

The recommended state for this setting is: Disabled.

Rationale:

Keeping your system properly patched can help protect against 0 day vulnerabilities.

Impact:

None - this is the default behavior.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

Computer Configuration\Policies\Administrative Templates\Windows Components\Store\Turn off Automatic Download and Install of updates

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template WinStoreUI.admx/adml that is included with the Microsoft Windows 8.1 & Server 2012 R2 Administrative Templates, or by the Group Policy template WindowsStore.admx/adml that is included with the Microsoft Windows 10 Release 1511 Administrative Templates (or newer).

Default Value:

Disabled. (Microsoft Store automatically downloads and installs updates for Microsoft Store apps.)

See Also

https://workbench.cisecurity.org/benchmarks/14249

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|CM-6, 800-53|SI-2c., CCE|CCE-35807-7, CSCv7|3.4, CSCv7|3.5, CSCv7|5.1

Plugin: Windows

Control ID: 765225aaf1aa99f0d47b361e3c8c0dd37001d8c1600224c54514608d13c645f2