18.10.56.2.2 (L2) Ensure 'Disable Cloud Clipboard integration for server-to-client data transfer' is set to 'Enabled'

Information

This policy setting controls whether data transferred from the remote session to the client using clipboard redirection is added to the client-side cloud clipboard.

The recommended state for this setting is: Enabled

In high security environments, clipboard data should stay local to the system and not synced to the cloud as it may contain sensitive information that should be contained locally.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\Remote Desktop Services\Remote Desktop Connection Client\Disable Cloud Clipboard integration for server-to-client data transfer

Note: This Group Policy path is provided by the Group Policy template TerminalServer.admx/adml that is included with the Microsoft Windows 11 Release 22H2 Administrative Templates v1.0 (or newer).

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/17603

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 24543f59206834246c140767e4d384d970909c41d735febeaf6b00993dd618b4