18.10.90.1 (L1) Ensure 'Allow clipboard sharing with Windows Sandbox' is set to 'Disabled'

Information

This policy setting enables or disables clipboard sharing with the Windows Sandbox.

The recommended state for this setting is: Disabled

Note: The Windows Sandbox feature was first introduced in Windows 10 R1903, and allows a temporary 'clean install' virtual instance of Windows to be run inside the host, for the ostensible purpose of testing applications without making changes to the host.

Disabling copy and paste decreases the attack surface exposed by the Windows Sandbox and possible exposure of untrusted applications to the internal network.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\Windows Sandbox\Allow clipboard sharing with Windows Sandbox

Note: This Group Policy path is provided by the Group Policy template WindowsSandbox.admx/adml that is included with the Microsoft Windows 11 Release 21H2 Administrative Templates (or newer).

Impact:

The copy and paste function to/from the Windows Sandbox will be disabled. Therefore, files will not be able to be moved to/from the Windows Sandbox via the clipboard.

See Also

https://workbench.cisecurity.org/benchmarks/16514

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: Windows

Control ID: 172c6239f9400a389dae62af9193433bdfadd245d29fe6a05ba9161c3425c214