19.7.38.1 (L1) Ensure 'Turn off Windows Copilot' is set to 'Enabled'

Information

This policy setting configures the use of Windows Copilot. Windows Copilot is an artificial intelligence (AI) assistant that's integrated in Microsoft Windows workstation OSes, beginning with Windows 11 Release 23H2.

The recommended state for this setting is: Enabled

While AI can be an exciting new technology, it also carries its own risks, including the possibility of users accidentally uploading or typing personal or organization-sensitive data into it, with no real way to 'undo' or get that data back.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

User Configuration\Policies\Administrative Templates\Windows Components\Windows Copilot\Turn off Windows Copilot

This Group Policy path may not exist by default. It is provided by the Group Policy template WindowsCopilot.admx/adml that is included with the Microsoft Windows 11 Release 23H2 Administrative Templates (or newer).

Impact:

Users will not be able to use Windows Copilot and its icon will not appear on the taskbar.

See Also

https://workbench.cisecurity.org/benchmarks/17603

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: Windows

Control ID: 44335a9d8eb32f734b291492f15baf823a07a99d176161d9b40a81d997e3968b