18.9.31.1 (L2) Ensure 'Allow Clipboard synchronization across devices' is set to 'Disabled'

Information

This setting determines whether Clipboard contents can be synchronized across devices.

The recommended state for this setting is: Disabled

In high security environments, clipboard data should stay local to the system and not synced across devices, as it may contain very sensitive information that must be contained locally.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\System\OS Policies\Allow Clipboard synchronization across devices

Note: This Group Policy path is provided by the Group Policy template OSPolicy.admx/adml that is included with the Microsoft Windows 10 Release 1809 & Server 2019 Administrative Templates (or newer).

Impact:

Clipboard contents will not be shareable to other devices.

See Also

https://workbench.cisecurity.org/benchmarks/17603

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: Windows

Control ID: 680aad896b41b3db53456d89d88c5974b3087164bc7bc48c226cc9f84a80718e