18.10.18.7 (L2) Ensure 'Enable Windows Package Manager command line interfaces' is set to 'Disabled'

Information

This policy setting controls whether a user can perform actions using the Windows Package Manager through a command line interface (Windows CLI or PowerShell).

The recommended state for this setting is: Disabled

Note: This policy does not override the

Enable App Installer

policy, which is set to Disabled in the L2 profile of the CIS Windows Operating System Benchmarks.

Windows Package Manager is a command line tool can be used to discover, install, upgrade, remove and configure applications. It can also be used as a distribution channel for software packages containing tools and applications. Users should not have access to these types of development tools.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\Desktop App Installer\Enable Windows Package Manager command line interfaces

Note: This Group Policy path is provided by the Group Policy template DesktopAppInstaller.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).

Impact:

Users will not have the ability to use Windows Package Manager with Windows CLI or PowerShell.

See Also

https://workbench.cisecurity.org/benchmarks/21344

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: abe1c1697710b35f99328a489e0f18300b385dfefa76c9b08799c054276711df