18.10.17.2 (L1) Ensure 'Enable App Installer Experimental Features' is set to 'Disabled'

Information

This policy setting controls whether users can enable experimental features in the Windows Package Manager.

The recommended state for this setting is Disabled

Windows Package Manager is a command line tool can be used to discover, install, upgrade, remove and configure applications, and it can be used as a distribution channel for software packages containing tools and applications. Users should not have access to experimental features.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\Desktop App Installer\Enable App Installer Experimental Features

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template DesktopAppInstaller.admx/adml that is included with the Microsoft Windows 11 Release 22H2 Administrative Templates v1.0 (or newer).

Impact:

Users will not have access to experimental features in the command line tool, winget to discover, install, upgrade, remove, configure, or distribute applications.

See Also

https://workbench.cisecurity.org/benchmarks/17689

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 64f7f8082edfb28d3f227fc7abc6b3e7e79d85ad120274f8925c5d2632114e54