Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
All 11 checks on this page
- 19.5 Start Menu and Taskbar
- Ensure Toast Notifications On The Lock Screen Are Turned Off
- 19.6 System
- Ensure Help Experience Improvement Program Is Turned Off
- 19.7 Windows Components
- Ensure Antivirus Programs Are Notified When Opening Attachments
- Ensure Zone Information Is Preserved In File Attachments
- Ensure All Windows Spotlight Features Are Turned Off
- Ensure Diagnostic Data Is Not Used For Tailored Experiences
- Ensure Spotlight Collection On Desktop Is Turned Off
- Ensure Third-Party Content Suggestions In Windows Spotlight Are Disabled
- Ensure Windows Spotlight On Lock Screen Is Disabled
- Ensure Users Are Prevented From Sharing Files Within Their Profile
- Ensure Windows Media Player Codec Download Is Prevented
19.5 Start Menu and Taskbar
Ensure Toast Notifications On The Lock Screen Are Turned Off
Finding: Toast notifications on the lock screen are not turned off.
Checks whether apps are blocked from raising toast notifications on the lock screen for each user.
This rule fails when any user's noToastApplicationNotificationOnLockScreen is not true.
Rationale: Toast notifications can reveal sensitive personal or business content on the lock screen while a device is left unattended.
Impact: Applications can no longer display toast notifications on the lock screen.
Remediation
Open User Configuration > Policies > Administrative Templates > Start Menu and Taskbar > Notifications > Turn off toast notifications on the lock screen and set Enabled.
From the command line:
reg add "HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\PushNotifications" /v NoToastApplicationNotificationOnLockScreen /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
19.6 System
Ensure Help Experience Improvement Program Is Turned Off
Finding: Help Experience Improvement Program is not turned off.
Checks whether users are prevented from participating in the Help Experience Improvement program, which reports Windows Help usage back to Microsoft.
This rule fails when any user's noImplicitFeedback is not true.
Rationale: Managed environments often need to stop client computers from sending usage information to external services.
Impact: Users can no longer join the Help Experience Improvement program.
Remediation
Open User Configuration > Policies > Administrative Templates > System > Internet Communication Management > Internet Communication Settings > Turn off Help Experience Improvement Program and set Enabled.
From the command line:
reg add "HKCU\Software\Policies\Microsoft\Assistance\Client\1.0" /v NoImplicitFeedback /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
19.7 Windows Components
Ensure Antivirus Programs Are Notified When Opening Attachments
Finding: Antivirus programs are not notified when opening attachments.
Checks whether registered antivirus programs are told to scan a file attachment when a user opens it.
This rule fails when any user's scanWithAntivirus is not true.
Rationale: Antivirus products that do not perform on-access checks may otherwise never scan a downloaded attachment before it is opened.
Impact: Windows asks the registered antivirus program(s) to scan an attachment on open, and blocks the attachment if the scan fails.
Remediation
Open User Configuration > Policies > Administrative Templates > Windows Components > Attachment Manager > Notify antivirus programs when opening attachments and set Enabled.
From the command line:
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments" /v ScanWithAntiVirus /t REG_DWORD /d 3 /f
- Framework mappings
- CIS Controls v8: 10.1 Deploy and Maintain Anti-Malware Software
- NIST SP 800-53 Rev. 5: MP-6 Media Sanitization
- NIST SP 800-171 Rev. 2: 3.14.2 Provide protection from malicious code at designated locations within organizational systems
- CMMC 2.0 Level 1: SI.L1-b.1.xiii Provide protection from malicious code at appropriate locations within organizational information systems
- CMMC 2.0 Level 2: SI.L2-3.14.2 Provide protection from malicious code at designated locations within organizational systems
- PCI DSS v4.0.1: 5.1.1 Malware protection policies and procedures kept documented, current, and applied; 5.2.1 Deploy anti-malware on all systems not evaluated as low risk; 5.2.2 Ensure anti-malware detects and removes or blocks all known malware; 5.3.2 Run periodic and real-time anti-malware scans or behavioral analysis
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Zone Information Is Preserved In File Attachments
Finding: Zone information is not preserved in file attachments.
Checks whether Windows keeps zone-of-origin information (Internet, intranet, restricted, local) on downloaded file attachments for each user.
This rule fails when any user's saveZoneInformation is not true.
Rationale: Preserving zone information lets the Attachment Manager warn users before opening or running files that came from an untrusted source; without it Windows cannot assess the risk.
Impact: None; retaining zone information on attachments is the default behavior.
Remediation
Open User Configuration > Policies > Administrative Templates > Windows Components > Attachment Manager > Do not preserve zone information in file attachments and set Disabled.
From the command line:
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments" /v SaveZoneInformation /t REG_DWORD /d 2 /f
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure All Windows Spotlight Features Are Turned Off
Finding: Windows Spotlight features are not turned off.
Checks whether every Windows Spotlight feature is turned off together for each user.
This rule fails when any user's disableWindowsSpotlightFeatures is not true.
Rationale: Windows Spotlight collects data and pulls suggested apps and internet images; turning all of its features off keeps that data from being shared with third parties.
Impact: Spotlight on the lock screen, Windows tips, consumer features, and related features are all turned off.
Remediation
Open User Configuration > Policies > Administrative Templates > Windows Components > Cloud Content > Turn off all Windows spotlight features and set Enabled.
From the command line:
reg add "HKCU\Software\Policies\Microsoft\Windows\CloudContent" /v DisableWindowsSpotlightFeatures /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Diagnostic Data Is Not Used For Tailored Experiences
Finding: Diagnostic data is used for tailored experiences.
Checks whether Windows is prevented from using the device's diagnostic data to personalize content for each user.
This rule fails when any user's disableTailoredExperiencesWithDiagnosticData is not true.
Rationale: Collecting and using personalized diagnostic data is a privacy concern for many organizations.
Impact: Recommendations, tips, and offers may still appear but are no longer personalized using this device's diagnostic data.
Remediation
Open User Configuration > Policies > Administrative Templates > Windows Components > Cloud Content > Do not use diagnostic data for tailored experiences and set Enabled.
From the command line:
reg add "HKCU\Software\Policies\Microsoft\Windows\CloudContent" /v DisableTailoredExperiencesWithDiagnosticData /t REG_DWORD /d 1 /f
Ensure Spotlight Collection On Desktop Is Turned Off
Finding: Spotlight collection on the desktop is not turned off.
Checks whether the Spotlight collection option is removed from Personalization so users cannot download daily images from Microsoft to the desktop.
This rule fails when any user's disableSpotlightCollectionOnDesktop is not true.
Rationale: The Spotlight collection feature collects data and downloads images from Microsoft; removing it prevents that data sharing.
Impact: Spotlight collection no longer appears in Personalization settings, so users cannot select it for daily desktop images.
Remediation
Open User Configuration > Policies > Administrative Templates > Windows Components > Cloud Content > Turn off Spotlight collection on Desktop and set Enabled.
From the command line:
reg add "HKCU\SOFTWARE\Policies\Microsoft\Windows\CloudContent" /v DisableSpotlightCollectionOnDesktop /t REG_DWORD /d 1 /f
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Third-Party Content Suggestions In Windows Spotlight Are Disabled
Finding: Third-party content suggestions in Windows Spotlight are enabled.
Checks whether Windows is stopped from suggesting apps and content from third-party publishers through Windows Spotlight surfaces for each user.
This rule fails when any user's disableThirdPartySuggestions is not true.
Rationale: Blocking third-party suggestions keeps user data from being shared with outside publishers via Spotlight, tips, and consumer features.
Impact: Spotlight, Windows tips, and consumer features no longer suggest third-party apps or content, though Microsoft feature tips may still appear.
Remediation
Open User Configuration > Policies > Administrative Templates > Windows Components > Cloud Content > Do not suggest third-party content in Windows spotlight and set Enabled.
From the command line:
reg add "HKCU\Software\Policies\Microsoft\Windows\CloudContent" /v DisableThirdPartySuggestions /t REG_DWORD /d 1 /f
Ensure Windows Spotlight On Lock Screen Is Disabled
Finding: Windows Spotlight on the lock screen is enabled.
Checks whether Windows Spotlight is prevented from acting as the lock screen provider for each user.
This rule fails when any user's configureWindowsSpotlight is not false.
Rationale: Windows Spotlight collects data and pulls suggested apps and internet images to the lock screen; disabling it keeps that data from being shared with third parties.
Impact: Windows Spotlight is turned off and users can no longer select it as their lock screen.
Remediation
Open User Configuration > Policies > Administrative Templates > Windows Components > Cloud Content > Configure Windows spotlight on lock screen and set Disabled.
From the command line:
reg add "HKCU\Software\Policies\Microsoft\Windows\CloudContent" /v ConfigureWindowsSpotlight /t REG_DWORD /d 2 /f
Ensure Users Are Prevented From Sharing Files Within Their Profile
Finding: Users can share files within their profile.
Checks whether users are blocked from using the sharing wizard to share files out of their own user profile.
This rule fails when any user's noInplaceSharing is not true.
Rationale: Sharing directly from a profile risks accidental exposure of sensitive data; enterprises should provide a managed location such as a file server or SharePoint instead.
Impact: Users cannot share files from within their profile with the sharing wizard, and the wizard cannot create shares under the Users directory.
Remediation
Open User Configuration > Policies > Administrative Templates > Windows Components > Network Sharing > Prevent users from sharing files within their profile. and set Enabled.
From the command line:
reg add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoInplaceSharing /t REG_DWORD /d 1 /f
Ensure Windows Media Player Codec Download Is Prevented
Finding: Windows Media Player can download codecs automatically.
Checks whether Windows Media Player is prevented from automatically downloading additional codecs to decode unfamiliar media files for each user.
This rule fails when any user's preventCodeDownload is not true.
Rationale: Opening a malicious media file that requests a new codec can introduce risk; required codecs should be vetted and supplied by IT instead of downloaded automatically.
Impact: Windows Media Player no longer downloads codecs automatically and the automatic-download option is unavailable in the player.
Remediation
Open User Configuration > Policies > Administrative Templates > Windows Components > Windows Media Player > Playback > Prevent Codec Download and set Enabled.
From the command line:
reg add "HKCU\Software\Policies\Microsoft\WindowsMediaPlayer" /v PreventCodecDownload /t REG_DWORD /d 1 /f
- Risk
- Insecure Application
- MITRE ATT&CK tactic
- Execution (TA0002)