18.9.108.1.1 (L1) Ensure 'Do not adjust default option to 'Install Updates and Shut Down' in Shut Down Windows dialog box' is set to 'Disabled'

Information

This policy setting allows you to manage whether the 'Install Updates and Shut Down' option is allowed to be the default choice in the Shut Down Windows dialog box.

The recommended state for this setting is: Disabled

Installing security updates is very important for maintaining the ongoing security of a computer. This setting should

not

be Enabled, to therefore keep the 'Install Updates and Shut Down' option as the default choice (when applicable), which helps to encourage the installation of pending updates when a user shuts down their computer.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Administrative Templates\Windows Components\Windows Update\Legacy Policies\Do not adjust default option to 'Install Updates and Shut Down' in Shut Down Windows dialog box

Note: This Group Policy path is provided by the Group Policy template WindowsUpdate.admx/adml that is included with all versions of the Microsoft Windows Administrative Templates.

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/14289

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4

Plugin: Windows

Control ID: bd19cfc1468bcfb447f694441fe18ede8626a5718cea4299891535082e645627