78.1 (L1) Ensure 'Disallow Exploit Protection Override' is set to '(Enable)'

Information

This policy setting prevent users from making changes to the Exploit protection settings area in the Windows Security settings.

The recommended state for this setting is: (Enable)

Only authorized IT staff should be able to make changes to the exploit protection settings in order to ensure the organizations specific configuration is not modified.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to (Enable)

Windows Defender Security Center\Disallow Exploit Protection Override

Impact:

Local users cannot make changes in the Exploit protection settings area.

See Also

https://workbench.cisecurity.org/benchmarks/16852

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: 38c5e5aad78ee22160cbe47e716706f622aab39e27129b251f56e47a3b80cf62