18.9.51.1.1 (L1) Ensure 'Enable Windows NTP Client' is set to 'Enabled'

Information

This policy setting specifies whether the Windows NTP Client is enabled. Enabling the Windows NTP Client allows synchronization from a systems computer clock to NTP server(s).

The recommended state for this setting is: Enabled

Note: If a third-party time provider is used in the environment, an exception to this recommendation will be needed.

A reliable and accurate account of time is important for a number of services and security requirements, including but not limited to distributed applications, authentication services, multi-user databases and logging services. The use of an NTP client (with secure operation) establishes functional accuracy and is a focal point when reviewing security relevant events.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\System\Windows Time Service\Time Providers\Enable Windows NTP Client

Note: This Group Policy path is provided by the Group Policy template W32Time.admx/adml that is included with all versions of the Microsoft Windows Administrative Templates.

Impact:

System time will be synced to the configured NTP server(s).

See Also

https://workbench.cisecurity.org/benchmarks/16515

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-7, 800-53|AU-8, CSCv7|6.1

Plugin: Windows

Control ID: 296774978e84a1aaf953fe4491d6d40fd05674bcb3a263a55a5cbfa625b05026