3.10.25.5 (L1) Ensure 'Turn off app notifications on the lock screen' is set to 'Enabled'

Information

This policy setting allows you to prevent app notifications from appearing on the lock screen.

The recommended state for this setting is: Enabled

Warning: If the

Self Service Password Reset (SSPR)

feature is used in Microsoft Entra ID, an exception to this recommendation is needed as it's known to interfere with SSPR.

App notifications might display sensitive business or personal data.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled

Administrative Templates\System\Logon\Turn off app notifications on the lock screen

Impact:

No app notifications are displayed on the lock screen.

See Also

https://workbench.cisecurity.org/benchmarks/16853

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|16.11

Plugin: Windows

Control ID: 2526493e59fa3fa75bd65d33152d08789346fd05a6b51db81c501c1923fb15f3