CIS Microsoft Windows 11 Stand-alone Benchmark · Section 18.8

Windows 11 Start Menu and Taskbar: 2 Checks

Wartiva runs 2 checks for section 18.8, Start Menu and Taskbar, of the CIS Microsoft Windows 11 Stand-alone Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

All 2 checks on this page

Ensure Personalized Website Recommendations Are Removed From The Start Menu

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.8

Finding: Personalized website recommendations are shown in the Start Menu.

Checks whether personalized website recommendations are removed from the Recommended section of the Start Menu.

This rule fails when hideRecommendedPersonalizedSites is not true.

Rationale: Personalized recommendations are derived from user activity data that could contain sensitive information.

Impact: Personalized website recommendations will not be shown in the Start Menu.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Start Menu and Taskbar > Remove Personalized Website Recommendations from the Recommended section in the Start Menu and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v HideRecommendedPersonalizedSites /t REG_DWORD /d 1 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

18.8.1 Notifications

Ensure Notifications Network Usage Is Turned Off

Low severity · Wartiva check · CIS Microsoft Windows 11 Stand-alone Benchmark 18.8.1

Finding: Notifications network usage is not turned off.

Checks whether applications are blocked from using the network (the Windows Push Notification Service) to send tile, badge, toast, or raw notifications.

This rule fails when noCloudApplicationNotification is not true.

Rationale: Blocking WNS prevents externally hosted systems from influencing secure workstations through cloud-delivered notifications.

Impact: Applications and system features will not receive notifications from the network via WNS or notification polling APIs.

Remediation

Open Computer Configuration > Policies > Administrative Templates > Start Menu and Taskbar > Notifications > Turn off notifications network usage and set it to Enabled.

From the command line:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\PushNotifications" /v NoCloudApplicationNotification /t REG_DWORD /d 1 /f
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)