Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
All 4 checks on this page
- Ensure Allow Online Tips Is Disabled
- 18.1.1 Personalization
- Ensure Prevent Enabling Lock Screen Camera Is Enabled
- Ensure Prevent Enabling Lock Screen Slide Show Is Enabled
- 18.1.2 Regional and Language Options
- Ensure Online Speech Recognition Services Are Disabled
Ensure Allow Online Tips Is Disabled
Finding: Online tips retrieval for the Settings app is allowed.
Checks whether the Settings app is prevented from retrieving online tips and help content.
This rule fails when allowOnlineTips is not false.
Rationale: Contacting external content services can leak information to third parties; in high-security environments data should not be shared without explicit consent.
Impact: The Settings app will not contact Microsoft content services for tips and help.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Control Panel > Allow Online Tips and set it to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v AllowOnlineTips /t REG_DWORD /d 0 /f
18.1.1 Personalization
Ensure Prevent Enabling Lock Screen Camera Is Enabled
Finding: Lock screen camera is not prevented.
Checks whether the lock screen camera toggle is disabled so a camera cannot be invoked from the lock screen.
This rule fails when noLockScreenCamera is not true.
Rationale: Extending the lock screen protection to camera features prevents an unattended, locked device from being used to capture images.
Impact: Users can no longer enable or disable lock screen camera access, and the camera cannot be invoked on the lock screen.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Control Panel > Personalization > Prevent enabling lock screen camera and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Personalization" /v NoLockScreenCamera /t REG_DWORD /d 1 /f
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Prevent Enabling Lock Screen Slide Show Is Enabled
Finding: Lock screen slide show is not prevented.
Checks whether the lock screen slide show is disabled so no slide show plays on the lock screen.
This rule fails when noLockScreenSlideshow is not true.
Rationale: A slide show on a locked device can display file contents to a passer-by; disabling it extends the lock screen's protection to slide show contents.
Impact: Users can no longer modify slide show settings and no slide show will start on the lock screen.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Control Panel > Personalization > Prevent enabling lock screen slide show and set it to Enabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Personalization" /v NoLockScreenSlideshow /t REG_DWORD /d 1 /f
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
18.1.2 Regional and Language Options
Ensure Online Speech Recognition Services Are Disabled
Finding: Online speech recognition and input personalization are allowed.
Checks whether automatic learning of speech, inking, and typing (input personalization) is turned off.
This rule fails when allowInputPersonalization is not false.
Rationale: Automatic learning collects speech and handwriting patterns, typing history, contacts, and calendar data, some of which is uploaded to the cloud where it may expose sensitive information.
Impact: Automatic learning stops and users cannot re-enable it from PC Settings.
Remediation
Open Computer Configuration > Policies > Administrative Templates > Control Panel > Regional and Language Options > Allow users to enable online speech recognition services and set it to Disabled.
From the command line:
reg add "HKLM\SOFTWARE\Policies\Microsoft\InputPersonalization" /v AllowInputPersonalization /t REG_DWORD /d 0 /f
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)