80.2 (L1) Ensure 'Allow Windows Ink Workspace' is set to 'Enabled: but the user can't access it above the lock screen' OR 'Disabled'

Information

This policy setting determines whether Windows Ink items are allowed above the lock screen.

The recommended state for this setting is: Ink workspace is enabled (feature is turned on), but the user can't access it above the lock screen OR Access to ink workspace is disabled. The feature is turned off

Allowing any apps to be accessed while system is locked is not recommended. If this feature is permitted, it should only be accessible once a user authenticates with the proper credentials.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Ink workspace is enabled (feature is turned on), but the user can't access it above the lock screen OR Access to ink workspace is disabled. The feature is turned off

Windows Ink Workspace\Allow Windows Ink Workspace

Impact:

Windows Ink Workspace will not be permitted above the lock screen.

See Also

https://workbench.cisecurity.org/benchmarks/16853

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: Windows

Control ID: 20bc1f027f99a8661fd8307e489c64c86697892a40031a7eec5bfa4be290132c