---
title: CIS Windows 11 Administrative Templates (User) | Wartiva
description: Wartiva's 11 checks for section 19, Administrative Templates (User), of the CIS Microsoft Windows 11 Stand-alone Benchmark, with rationale and remediation.
url: https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/administrative-templates-user.html
updated: 2026-10-07
---

CIS Microsoft Windows 11 Stand-alone Benchmark · Section 19

# Windows 11 Administrative Templates (User): 11 Checks

Wartiva runs 11 checks for section 19, Administrative Templates (User), of the CIS Microsoft Windows 11 Stand-alone Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

## 19.5 Start Menu and Taskbar

### [Ensure Toast Notifications On The Lock Screen Are Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/administrative-templates-user.html#toast-notifications-on-the-lock-screen-are-turned-off)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 19.5.1

**Finding:** Toast notifications on the lock screen are not turned off.

Checks whether apps are blocked from raising toast notifications on the lock screen for each user.

This rule fails when any user's `noToastApplicationNotificationOnLockScreen` is not `true`.

**Rationale:** Toast notifications can reveal sensitive personal or business content on the lock screen while a device is left unattended.

**Impact:** Applications can no longer display toast notifications on the lock screen.

#### Remediation

Open **User Configuration > Policies > Administrative Templates > Start Menu and Taskbar > Notifications > Turn off toast notifications on the lock screen** and set **Enabled**.

From the command line:

```powershell
reg add "HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\PushNotifications" /v NoToastApplicationNotificationOnLockScreen /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 19.6 System

### [Ensure Help Experience Improvement Program Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/administrative-templates-user.html#help-experience-improvement-program-is-turned-off)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 19.6.6.1

**Finding:** Help Experience Improvement Program is not turned off.

Checks whether users are prevented from participating in the Help Experience Improvement program, which reports Windows Help usage back to Microsoft.

This rule fails when any user's `noImplicitFeedback` is not `true`.

**Rationale:** Managed environments often need to stop client computers from sending usage information to external services.

**Impact:** Users can no longer join the Help Experience Improvement program.

#### Remediation

Open **User Configuration > Policies > Administrative Templates > System > Internet Communication Management > Internet Communication Settings > Turn off Help Experience Improvement Program** and set **Enabled**.

From the command line:

```powershell
reg add "HKCU\Software\Policies\Microsoft\Assistance\Client\1.0" /v NoImplicitFeedback /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 19.7 Windows Components

### [Ensure Antivirus Programs Are Notified When Opening Attachments](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/administrative-templates-user.html#antivirus-programs-are-notified-when-opening-attachments)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 19.7.5

**Finding:** Antivirus programs are not notified when opening attachments.

Checks whether registered antivirus programs are told to scan a file attachment when a user opens it.

This rule fails when any user's `scanWithAntivirus` is not `true`.

**Rationale:** Antivirus products that do not perform on-access checks may otherwise never scan a downloaded attachment before it is opened.

**Impact:** Windows asks the registered antivirus program(s) to scan an attachment on open, and blocks the attachment if the scan fails.

#### Remediation

Open **User Configuration > Policies > Administrative Templates > Windows Components > Attachment Manager > Notify antivirus programs when opening attachments** and set **Enabled**.

From the command line:

```powershell
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments" /v ScanWithAntiVirus /t REG_DWORD /d 3 /f
```

Framework mappings

- **CIS Controls v8**: 10.1 Deploy and Maintain Anti-Malware Software
- **NIST SP 800-53 Rev. 5**: MP-6 Media Sanitization
- **NIST SP 800-171 Rev. 2**: 3.14.2 Provide protection from malicious code at designated locations within organizational systems
- **CMMC 2.0 Level 1**: SI.L1-b.1.xiii Provide protection from malicious code at appropriate locations within organizational information systems
- **CMMC 2.0 Level 2**: SI.L2-3.14.2 Provide protection from malicious code at designated locations within organizational systems
- **PCI DSS v4.0.1**: 5.1.1 Malware protection policies and procedures kept documented, current, and applied; 5.2.1 Deploy anti-malware on all systems not evaluated as low risk; 5.2.2 Ensure anti-malware detects and removes or blocks all known malware; 5.3.2 Run periodic and real-time anti-malware scans or behavioral analysis

Risk

Vulnerability

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Zone Information Is Preserved In File Attachments](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/administrative-templates-user.html#zone-information-is-preserved-in-file-attachments)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 19.7.5

**Finding:** Zone information is not preserved in file attachments.

Checks whether Windows keeps zone-of-origin information (Internet, intranet, restricted, local) on downloaded file attachments for each user.

This rule fails when any user's `saveZoneInformation` is not `true`.

**Rationale:** Preserving zone information lets the Attachment Manager warn users before opening or running files that came from an untrusted source; without it Windows cannot assess the risk.

**Impact:** None; retaining zone information on attachments is the default behavior.

#### Remediation

Open **User Configuration > Policies > Administrative Templates > Windows Components > Attachment Manager > Do not preserve zone information in file attachments** and set **Disabled**.

From the command line:

```powershell
reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments" /v SaveZoneInformation /t REG_DWORD /d 2 /f
```

Risk

Vulnerability

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure All Windows Spotlight Features Are Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/administrative-templates-user.html#all-windows-spotlight-features-are-turned-off)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 19.7.8

**Finding:** Windows Spotlight features are not turned off.

Checks whether every Windows Spotlight feature is turned off together for each user.

This rule fails when any user's `disableWindowsSpotlightFeatures` is not `true`.

**Rationale:** Windows Spotlight collects data and pulls suggested apps and internet images; turning all of its features off keeps that data from being shared with third parties.

**Impact:** Spotlight on the lock screen, Windows tips, consumer features, and related features are all turned off.

#### Remediation

Open **User Configuration > Policies > Administrative Templates > Windows Components > Cloud Content > Turn off all Windows spotlight features** and set **Enabled**.

From the command line:

```powershell
reg add "HKCU\Software\Policies\Microsoft\Windows\CloudContent" /v DisableWindowsSpotlightFeatures /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Diagnostic Data Is Not Used For Tailored Experiences](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/administrative-templates-user.html#diagnostic-data-is-not-used-for-tailored-experiences)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 19.7.8

**Finding:** Diagnostic data is used for tailored experiences.

Checks whether Windows is prevented from using the device's diagnostic data to personalize content for each user.

This rule fails when any user's `disableTailoredExperiencesWithDiagnosticData` is not `true`.

**Rationale:** Collecting and using personalized diagnostic data is a privacy concern for many organizations.

**Impact:** Recommendations, tips, and offers may still appear but are no longer personalized using this device's diagnostic data.

#### Remediation

Open **User Configuration > Policies > Administrative Templates > Windows Components > Cloud Content > Do not use diagnostic data for tailored experiences** and set **Enabled**.

From the command line:

```powershell
reg add "HKCU\Software\Policies\Microsoft\Windows\CloudContent" /v DisableTailoredExperiencesWithDiagnosticData /t REG_DWORD /d 1 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Spotlight Collection On Desktop Is Turned Off](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/administrative-templates-user.html#spotlight-collection-on-desktop-is-turned-off)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 19.7.8

**Finding:** Spotlight collection on the desktop is not turned off.

Checks whether the Spotlight collection option is removed from Personalization so users cannot download daily images from Microsoft to the desktop.

This rule fails when any user's `disableSpotlightCollectionOnDesktop` is not `true`.

**Rationale:** The Spotlight collection feature collects data and downloads images from Microsoft; removing it prevents that data sharing.

**Impact:** Spotlight collection no longer appears in Personalization settings, so users cannot select it for daily desktop images.

#### Remediation

Open **User Configuration > Policies > Administrative Templates > Windows Components > Cloud Content > Turn off Spotlight collection on Desktop** and set **Enabled**.

From the command line:

```powershell
reg add "HKCU\SOFTWARE\Policies\Microsoft\Windows\CloudContent" /v DisableSpotlightCollectionOnDesktop /t REG_DWORD /d 1 /f
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Third-Party Content Suggestions In Windows Spotlight Are Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/administrative-templates-user.html#third-party-content-suggestions-in-windows-spotlight-are-disabled)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 19.7.8

**Finding:** Third-party content suggestions in Windows Spotlight are enabled.

Checks whether Windows is stopped from suggesting apps and content from third-party publishers through Windows Spotlight surfaces for each user.

This rule fails when any user's `disableThirdPartySuggestions` is not `true`.

**Rationale:** Blocking third-party suggestions keeps user data from being shared with outside publishers via Spotlight, tips, and consumer features.

**Impact:** Spotlight, Windows tips, and consumer features no longer suggest third-party apps or content, though Microsoft feature tips may still appear.

#### Remediation

Open **User Configuration > Policies > Administrative Templates > Windows Components > Cloud Content > Do not suggest third-party content in Windows spotlight** and set **Enabled**.

From the command line:

```powershell
reg add "HKCU\Software\Policies\Microsoft\Windows\CloudContent" /v DisableThirdPartySuggestions /t REG_DWORD /d 1 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Windows Spotlight On Lock Screen Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/administrative-templates-user.html#windows-spotlight-on-lock-screen-is-disabled)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 19.7.8

**Finding:** Windows Spotlight on the lock screen is enabled.

Checks whether Windows Spotlight is prevented from acting as the lock screen provider for each user.

This rule fails when any user's `configureWindowsSpotlight` is not `false`.

**Rationale:** Windows Spotlight collects data and pulls suggested apps and internet images to the lock screen; disabling it keeps that data from being shared with third parties.

**Impact:** Windows Spotlight is turned off and users can no longer select it as their lock screen.

#### Remediation

Open **User Configuration > Policies > Administrative Templates > Windows Components > Cloud Content > Configure Windows spotlight on lock screen** and set **Disabled**.

From the command line:

```powershell
reg add "HKCU\Software\Policies\Microsoft\Windows\CloudContent" /v ConfigureWindowsSpotlight /t REG_DWORD /d 2 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Users Are Prevented From Sharing Files Within Their Profile](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/administrative-templates-user.html#users-are-prevented-from-sharing-files-within-their-profile)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 19.7.26

**Finding:** Users can share files within their profile.

Checks whether users are blocked from using the sharing wizard to share files out of their own user profile.

This rule fails when any user's `noInplaceSharing` is not `true`.

**Rationale:** Sharing directly from a profile risks accidental exposure of sensitive data; enterprises should provide a managed location such as a file server or SharePoint instead.

**Impact:** Users cannot share files from within their profile with the sharing wizard, and the wizard cannot create shares under the Users directory.

#### Remediation

Open **User Configuration > Policies > Administrative Templates > Windows Components > Network Sharing > Prevent users from sharing files within their profile.** and set **Enabled**.

From the command line:

```powershell
reg add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v NoInplaceSharing /t REG_DWORD /d 1 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Windows Media Player Codec Download Is Prevented](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/administrative-templates-user.html#windows-media-player-codec-download-is-prevented)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 19.7.46.2

**Finding:** Windows Media Player can download codecs automatically.

Checks whether Windows Media Player is prevented from automatically downloading additional codecs to decode unfamiliar media files for each user.

This rule fails when any user's `preventCodeDownload` is not `true`.

**Rationale:** Opening a malicious media file that requests a new codec can introduce risk; required codecs should be vetted and supplied by IT instead of downloaded automatically.

**Impact:** Windows Media Player no longer downloads codecs automatically and the automatic-download option is unavailable in the player.

#### Remediation

Open **User Configuration > Policies > Administrative Templates > Windows Components > Windows Media Player > Playback > Prevent Codec Download** and set **Enabled**.

From the command line:

```powershell
reg add "HKCU\Software\Policies\Microsoft\WindowsMediaPlayer" /v PreventCodecDownload /t REG_DWORD /d 1 /f
```

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
