18.10.57.3.3.4 Ensure 'Do not allow location redirection' is set to 'Enabled'

Information

This policy setting controls the redirection of location data to the remote computer in a Remote Desktop Services session.

The recommended state for this setting is: Enabled

In a more security-sensitive environment, it is desirable to reduce the possible attack surface. The need for location data redirection within a Remote Desktop session is rare, so it makes sense to reduce the number of unexpected avenues for malicious activity to occur.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Administrative Templates\Windows Components\Remote Desktop Services\Remote Desktop Session Host\Device and Resource Redirection\Do not allow location redirection

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template TerminalServer.admx/adml that is included with the Microsoft Windows 10 Release 21H2 Administrative Templates (or newer).

Impact:

Users will not be able to redirect their location data to the remote computer.

See Also

https://workbench.cisecurity.org/benchmarks/15301

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4

Plugin: Windows

Control ID: 99910e7e766e448c16189b7adc804e49a7d7e95846548071e149210350f25231