18.9.7.1.3 (L1) Ensure 'Display a custom message when installation is prevented by a policy setting' is set to 'Enabled: <Text>'

Information

This policy setting allows a custom message to be displayed to users via a notification when device installation is attempted and a policy setting prevents the installation.

The recommended state for this setting is: Enabled

Displaying a warning message can help to reinforce corporate policy by notifying employees that plug and play/removable media devices (unless approved) are not allowed on the system.

Sample Text: Only approved plug and play/removable media devices are allow on this system. For more information please contact the Help Desk.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\System\Device Installation\Device Installation Restrictions\Display a custom message when installation is prevented by a policy setting

Note: This Group Policy path is provided by the Group Policy template DeviceInstallation.admx/adml that is included with the Microsoft Windows 10 Release 1903 Administrative Templates (or newer).

Impact:

Users will have to acknowledge a dialog box with the configured text before they can proceed.

See Also

https://workbench.cisecurity.org/benchmarks/17610

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-6(10), 800-53|MP-7

Plugin: Windows

Control ID: d59fbf7bb93161fcecd36cd8f3c42581b57308ef4214387990bc2c658a4931ce