3.11.6.1 (L1) Ensure 'Disallow Autoplay for non-volume devices' is set to 'Enabled'

Information

This policy setting disallows AutoPlay for MTP devices like cameras or phones.

The recommended state for this setting is: Enabled

An attacker could use this feature to launch a program to damage a client computer or data on the computer.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled

Administrative Templates\Windows Components\AutoPlay Policies\Disallow Autoplay for non-volume devices

Impact:

AutoPlay will not be allowed for MTP devices like cameras or phones.

See Also

https://workbench.cisecurity.org/benchmarks/16853

Item Details

Category: MEDIA PROTECTION

References: 800-53|MP-7, CSCv7|8.5

Plugin: Windows

Control ID: 21dc0ed432613c1f0a41b93d0e5cc339d50ce64b14decc1ee94e38b21f53935b