18.9.19.4 (L1) Ensure 'Configure security policy processing: Do not apply during periodic background processing' is set to 'Enabled: FALSE'

Information

The 'Do not apply during periodic background processing' option prevents the system from updating affected security policies in the background while the computer is in use. When background updates are disabled, updates to security policies will not take effect until the next user logon or system restart.

This setting affects all policy settings that use the built-in security template of Group Policy (e.g. Windows Settings\Security Settings).

The recommended state for this setting is: Enabled: FALSE (unchecked).

Setting this option to false (unchecked) will ensure that domain security policy changes are applied more quickly, as compared to waiting until the next user logon or system restart.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled then set the Do not apply during periodic background processing option to FALSE (unchecked):

Computer Configuration\Policies\Administrative Templates\System\Group Policy\Configure security policy processing

Note: This Group Policy path is provided by the Group Policy template GroupPolicy.admx/adml that is included with the Microsoft Windows 8.0 & Server 2012 (non-R2) Administrative Templates (or newer).

Impact:

Built-in security template settings will be reapplied by Group Policy even when the system is in use, which may have a slight impact on performance.

See Also

https://workbench.cisecurity.org/benchmarks/16514