1.1.1.2.1.65 Set 'MSS: (AutoReboot) Allow Windows to automatically restart after a system crash'

Information

1.1.1.2.1.65 Set 'MSS: (AutoReboot) Allow Windows to automatically restart after a system crash (recommended except for highly secure environments)' to 'Enabled'

This entry appears as MSS: (AutoReboot) Allow Windows to automatically restart after a system crash (recommended except for highly secure environments) in the SCE. This entry, when enabled, permits a server to automatically reboot after a fatal crash. It is enabled by default, which is undesirable on highly secure servers. You can add this registry value to the template file in the HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\CrashControl\ subkey. There is some concern that a computer could get stuck in an endless loop of failures and reboots. However, the alternative to this entry may not be much more appealing the computer will simply stop running.

Solution

To implement the recommended configuration state, set the following Group Policy setting to 1.

Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\MSS- (AutoReboot) Allow Windows to automatically restart after a system crash (recommended except for highly secure environments)

Impact- The computer will no longer reboot automatically after a failure.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-24, CCE|CCE-7611-7

Plugin: Windows

Control ID: 8efb41ddfe3023d4eb8a34921dab4e2a5e352c7f97a4067e469e1e95292f3368