18.9.108.1.2 (L1) Ensure 'Do not display 'Install Updates and Shut Down' option in Shut Down Windows dialog box' is set to 'Disabled'

Information

This policy setting allows you to manage whether the 'Install Updates and Shut Down' option is displayed in the Shut Down Windows dialog box.

The recommended state for this setting is: Disabled

Installing security updates is very important for maintaining the ongoing security of a computer. This setting should

not

be Enabled, to therefore keep the 'Install Updates and Shut Down' option available (when applicable), which helps to encourage the installation of pending updates when a user shuts down their computer.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

Computer Configuration\Policies\Administrative Templates\Windows Components\Windows Update\Legacy Policies\Do not display 'Install Updates and Shut Down' option in Shut Down Windows dialog box

Note: This Group Policy path is provided by the Group Policy template WindowsUpdate.admx/adml that is included with all versions of the Microsoft Windows Administrative Templates.

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/14289

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4

Plugin: Windows

Control ID: 329f095da1ed408102052495cc945e81209901e6f3e82415a46b181931b8c831