18.9.7.1.4 (L1) Ensure 'Display a custom message title when device installation is prevented by a policy setting' is set to 'Enabled: <Text>'

Information

This policy setting allows a custom message title to be displayed to users via a notification when device installation is attempted and a policy setting prevents the installation.

The recommended state for this setting is: Enabled

Displaying a warning message can help to reinforce corporate policy by notifying employees that plug and play/removable media devices (unless approved) are not allowed on the system.

Sample Text: WARNING: Unapproved Device.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\System\Device Installation\Device Installation Restrictions\Display a custom message title when device installation is prevented by a policy setting

Note: This Group Policy path is provided by the Group Policy template DeviceInstallation.admx/adml that is included with the Microsoft Windows 10 Release 1903 Administrative Templates (or newer).

Impact:

Users will have to acknowledge a dialog box with the configured text before they can proceed.

See Also

https://workbench.cisecurity.org/benchmarks/17610

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-6(10), 800-53|MP-7

Plugin: Windows

Control ID: d82f80f467d695cc0ec590c678bf138cc33629e4f6c14112698cff7e48c70214