67.1 (L1) Ensure 'Allow Telemetry' is set to 'Basic'

Information

This policy setting determines the amount of diagnostic and usage data reported to Microsoft:

The recommended state for this setting is: Basic or Security

Note: If your organization relies on Windows Update, the minimum recommended setting is Required diagnostic data Because no Windows Update information is collected when diagnostic data is off, important information about update failures is not sent. Microsoft uses this information to fix the causes of those failures and improve the quality of updates.

Note #2: The

Configure diagnostic data opt-in settings user interface

group policy can be used to prevent end users from changing their data collection settings.

Note #3: Enhanced diagnostic data setting is not available on Windows 11 and Windows Server 2022 and has been replaced with policies that can control the amount of optional diagnostic data that is sent. For more information on these settings visit

Manage diagnostic data using Group Policy and MDM

Sending any data to a third-party vendor is a security concern and should only be done on an as needed basis.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Basic or Security :

System\Allow Telemetry

Impact:

Note that setting values of 0 or 1 will degrade certain experiences on the device.

See Also

https://workbench.cisecurity.org/benchmarks/16853

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: Windows

Control ID: bf619fb208931d2af92316a9d1b8860b363ad54308a7272b006837f18ba9d303