---
title: CIS Windows 11 Control Panel: 4 Checks | Wartiva
description: Wartiva's 4 checks for section 18.1, Control Panel, of the CIS Microsoft Windows 11 Stand-alone Benchmark: what each one finds, why it matters, and how to fix it.
url: https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/control-panel.html
updated: 2026-10-07
---

CIS Microsoft Windows 11 Stand-alone Benchmark · Section 18.1

# Windows 11 Control Panel: 4 Checks

Wartiva runs 4 checks for section 18.1, Control Panel, of the CIS Microsoft Windows 11 Stand-alone Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

### [Ensure Allow Online Tips Is Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/control-panel.html#allow-online-tips-is-disabled)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.1

**Finding:** Online tips retrieval for the Settings app is allowed.

Checks whether the Settings app is prevented from retrieving online tips and help content.

This rule fails when `allowOnlineTips` is not `false`.

**Rationale:** Contacting external content services can leak information to third parties; in high-security environments data should not be shared without explicit consent.

**Impact:** The Settings app will not contact Microsoft content services for tips and help.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Control Panel > Allow Online Tips** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v AllowOnlineTips /t REG_DWORD /d 0 /f
```

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 18.1.1 Personalization

### [Ensure Prevent Enabling Lock Screen Camera Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/control-panel.html#prevent-enabling-lock-screen-camera-is-enabled)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.1.1

**Finding:** Lock screen camera is not prevented.

Checks whether the lock screen camera toggle is disabled so a camera cannot be invoked from the lock screen.

This rule fails when `noLockScreenCamera` is not `true`.

**Rationale:** Extending the lock screen protection to camera features prevents an unattended, locked device from being used to capture images.

**Impact:** Users can no longer enable or disable lock screen camera access, and the camera cannot be invoked on the lock screen.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Control Panel > Personalization > Prevent enabling lock screen camera** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Personalization" /v NoLockScreenCamera /t REG_DWORD /d 1 /f
```

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Prevent Enabling Lock Screen Slide Show Is Enabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/control-panel.html#prevent-enabling-lock-screen-slide-show-is-enabled)

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.1.1

**Finding:** Lock screen slide show is not prevented.

Checks whether the lock screen slide show is disabled so no slide show plays on the lock screen.

This rule fails when `noLockScreenSlideshow` is not `true`.

**Rationale:** A slide show on a locked device can display file contents to a passer-by; disabling it extends the lock screen's protection to slide show contents.

**Impact:** Users can no longer modify slide show settings and no slide show will start on the lock screen.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Control Panel > Personalization > Prevent enabling lock screen slide show** and set it to **Enabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Personalization" /v NoLockScreenSlideshow /t REG_DWORD /d 1 /f
```

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## 18.1.2 Regional and Language Options

### [Ensure Online Speech Recognition Services Are Disabled](https://wartiva.com/policy-rules/microsoft-windows-11-stand-alone/control-panel.html#online-speech-recognition-services-are-disabled)

Medium severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.1.2

**Finding:** Online speech recognition and input personalization are allowed.

Checks whether automatic learning of speech, inking, and typing (input personalization) is turned off.

This rule fails when `allowInputPersonalization` is not `false`.

**Rationale:** Automatic learning collects speech and handwriting patterns, typing history, contacts, and calendar data, some of which is uploaded to the cloud where it may expose sensitive information.

**Impact:** Automatic learning stops and users cannot re-enable it from PC Settings.

#### Remediation

Open **Computer Configuration > Policies > Administrative Templates > Control Panel > Regional and Language Options > Allow users to enable online speech recognition services** and set it to **Disabled**.

From the command line:

```powershell
reg add "HKLM\SOFTWARE\Policies\Microsoft\InputPersonalization" /v AllowInputPersonalization /t REG_DWORD /d 0 /f
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
