1.2.2.3.1 Configure 'Registry policy processing' - NoGPOListChanges

Information

This policy setting determines when registry policies are updated. It affects all policies in the Administrative Templates folder, and any other policies that store values in the registry. If this policy setting is enabled, the following options are available: . Do not apply during periodic background processing. . Process even if the Group Policy objects have not changed. Some settings that are configured through the Administrative Templates are made in areas of the registry that are accessible to users. User changes to these settings will be overwritten if this policy setting is enabled. You can enable this setting and then select the Process even if the Group Policy objects have not changed option to ensure that the policies will be reprocessed even if none have been changed. This way, any unauthorized changes that might have been configured locally are forced to match the domainbased Group Policy settings again.

Solution

Configure the following Group Policy setting in a manner that is consistent with the security and operational requirements of your organization-

Computer Configuration\Administrative Templates\System\Group Policy\Registry policy processing

Impact- Group Policies will be reapplied every time they are refreshed, which could have a slight impact on performance.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-3(3), CCE|CCE-8043-2

Plugin: Windows

Control ID: e57acfb50946644a83c53619f0eca8af1d3844e2c373378191935b09d9f4361c