3.11.18.4 (L1) Ensure 'Turn off shell protocol protected mode' is set to 'Disabled'

Information

This policy setting allows you to configure the amount of functionality that the shell protocol can have. When using the full functionality of this protocol, applications can open folders and launch files. The protected mode reduces the functionality of this protocol allowing applications to only open a limited set of folders. Applications are not able to open files with this protocol when it is in the protected mode. It is recommended to leave this protocol in the protected mode to increase the security of Windows.

The recommended state for this setting is: Disabled

Limiting the opening of files and folders to a limited set reduces the attack surface of the system.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Disabled

Administrative Templates\Windows Components\File Explorer\Turn off shell protocol protected mode

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/16852

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|8.3

Plugin: Windows

Control ID: e46305df946b32ee55e9d5fde97c60e6c774b536dd0719a4b032a2b6a267652e