18.10.92.4.4 (L1) Ensure 'Enable optional updates' is set to 'Disabled'

Information

This policy setting controls whether devices are able to receive optional updates (including Controlled Feature Rollout (CFRs)). These optional updates can include non-security updates, feature enhancements, and other improvements.

The recommended state for this setting is: Disabled

Often, new features or enhancements that are enabled by default (before IT administrators are ready to manage them) can negatively impact the user experience or introduce bugs and security risks.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\Windows Update\Manage updates offered from Windows Update\Enable optional updates

This Group Policy path may not exist by default. It is provided by the Group Policy template WindowsUpdate.admx/adml that is included with the Microsoft Windows 11 Release 23H2 Administrative Templates (or newer).

Impact:

New features will not be available on the system until the feature update that includes these features and enhancements is installed.

See Also

https://workbench.cisecurity.org/benchmarks/16515

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4

Plugin: Windows

Control ID: 9e116e3f8cd79a42955d0d382850c18529ede072fddfe43ba4917fea8cda1dc1