18.10.92.2.3 (L1) Ensure 'Enable features introduced via servicing that are off by default' is set to 'Disabled'

Information

This policy settings configures whether or not features and enhancements that are introduced through monthly cumulative updates (servicing), are enabled on the system.

The recommended state for this setting is: Disabled

Often, new features or enhancements that are enabled by default (before IT administrators are ready to manage them) can negatively impact the user experience or introduce bugs and security risks.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\\Windows Components\Windows Update\Manage end user experience\Enable features introduced via servicing that are off by default

This Group Policy path may not exist by default. It is provided by the Group Policy template WindowsUpdate.admx/adml that is included with the Microsoft Windows 11 Release 22H2 Administrative Templates v3.0 (or newer).

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/17603

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Windows

Control ID: 612145bb9859e644a9c594257b2231088ff03e140e0eef26da5a6456e3d0500e