86.1.8 (L2) Ensure 'Turn off notifications network usage' is set to 'Enabled'

Information

This policy setting blocks applications from using the network to send notifications to update tiles, tile badges, toast, or raw notifications. This policy setting turns off the connection between Windows and the Windows Push Notification Service (WNS). This policy setting also stops applications from being able to poll application services to update tiles.

The recommended state for this setting is: Enabled

Windows Push Notification Services (WNS) is a mechanism to receive third-party notifications and updates from the cloud/Internet. In a high security environment, external systems, especially those hosted outside the organization, should be prevented from having an impact on the secure workstations.

Solution

To establish the recommended configuration, set the following Custom Configuration Policy to 1 :

Name: <Enter name>
Description: <Enter Description>
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/Notifications/DisallowCloudNotification
Data type: Integer
Value: 1

Impact:

Applications and system features will not be able receive notifications from the network from WNS or via notification polling APIs.

See Also

https://workbench.cisecurity.org/benchmarks/16853

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: Windows

Control ID: 59f3fe06352dd30eb4d07f7f171a498efe33616825b0b863f006c573e0450ce4