1.2.2.1.1 Configure 'Offer Remote Assistance'

Information

This policy setting determines whether a support person or an IT expert administrator can offer remote assistance to computers in your environment if a user does not explicitly request assistance first through a channel, such as e-mail, or Instant Messenger. Note The expert cannot connect to the computer unannounced or control it without permission from the user. When the expert tries to connect, the user can still choose to deny the connection or give the expert view-only privileges. The user must explicitly click the Yes button to allow the expert to remotely control the workstation after the Offer Remote Assistance setting is configured to Enabled. If this policy setting is enabled the following options are available: . Allow helpers to only view the computer . Allow helpers to remotely control the computer When you configure this policy setting, you can also specify a list of users or user groups known as helpers who may offer remote assistance. To configure the list of helpers 1. In the Offer Remote Assistance setting configuration window, click Show. A new window will open in which you can enter helper names. 2. Add each user or group to the Helper list in one of the following formats: . <Domain Name>\<User Name> . <Domain Name>\<Group Name> If this policy setting is disabled or not configured, users and or groups will not be able to offer unsolicited remote assistance to computer users in your environment. A user might be tricked and accept an unsolicited Remote Assistance offer from a malicious user.

Solution

Configure the following Group Policy setting in a manner that is consistent with the security and operational requirements of your organization-

Computer Configuration\Administrative Templates\System\Remote Assistance\Offer Remote Assistance

Impact- Help desk and support personnel will not be able to proactively offer assistance, although they can still respond to user assistance requests.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(4), CCE|CCE-3617-8

Plugin: Windows

Control ID: d64022243cede29d75f49d86882c646aea69e52b02ece91d5512cba5ca213422