22.06.2016 Views

CIS Microsoft Windows 10 Enterprise RTM (Release 1507) Benchmark

CIS_Microsoft_Windows_10_Enterprise_RTM_Release_1507_Benchmark_v1.0.0

CIS_Microsoft_Windows_10_Enterprise_RTM_Release_1507_Benchmark_v1.0.0

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

18.8.23 Locale Services<br />

This section contains recommendations for Locale Services settings.<br />

18.8.23.1 (L2) Set 'Disallow copying of user input methods to the system<br />

account for sign-in' to 'Enabled' (Scored)<br />

Profile Applicability:<br />

Level 2<br />

Level 2 + BitLocker<br />

Description:<br />

This policy prevents automatic copying of user input methods to the system account for use<br />

on the sign-in screen. The user is restricted to the set of input methods that are enabled in<br />

the system account.<br />

The recommended state for this setting is: Enabled.<br />

Rationale:<br />

This is a way to increase the security of the system account.<br />

Audit:<br />

Navigate to the UI Path articulated in the Remediation section and confirm it is set as<br />

prescribed. This group policy setting is backed by the following registry location:<br />

HKEY_LOCAL_MACHINE\Software\Policies\<strong>Microsoft</strong>\Control<br />

Panel\International:BlockUserInputMethodsForSignIn<br />

Remediation:<br />

To establish the recommended configuration via GP, set the following UI path to Enabled:<br />

Computer Configuration\Policies\Administrative Templates\System\Locale<br />

Services\Disallow copying of user input methods to the system account for sign-in<br />

Impact:<br />

If the policy is Enabled, then the user will get input methods enabled for the system<br />

account on the sign-in page.<br />

509 | P a g e

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!