22.06.2016 Views

CIS Microsoft Windows 10 Enterprise RTM (Release 1507) Benchmark

CIS_Microsoft_Windows_10_Enterprise_RTM_Release_1507_Benchmark_v1.0.0

CIS_Microsoft_Windows_10_Enterprise_RTM_Release_1507_Benchmark_v1.0.0

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

19.5 Start Menu and Taskbar<br />

This section contains recommendations for Start Menu and Taskbar settings.<br />

19.5.1 Notifications<br />

This section contains recommendations for Notification settings.<br />

19.5.1.1 (L1) Set 'Turn off toast notifications on the lock screen' to<br />

'Enabled' (Scored)<br />

Profile Applicability:<br />

Level 1<br />

Level 1 + BitLocker<br />

Description:<br />

This policy setting turns off toast notifications on the lock screen. If you enable this policy<br />

setting, applications will not be able to raise toast notifications on the lock screen. If you<br />

disable or do not configure this policy setting, toast notifications on the lock screen are<br />

enabled and can be turned off by the administrator or user. No reboots or service restarts<br />

are required for this policy setting to take effect.<br />

The recommended state for this setting is Enabled.<br />

Rationale:<br />

While this feature can be handy for users applications that provide toast notifications<br />

might display sensitive personal or business data while the device is unattended.<br />

Audit:<br />

Navigate to the UI Path articulated in the Remediation section and confirm it is set as<br />

prescribed. This group policy setting is backed by the following registry location:<br />

HKEY_USERS\\SOFTWARE\Policies\<strong>Microsoft</strong>\<strong>Windows</strong>\CurrentVersion\PushNotifications\<br />

NoToastApplicationNotificationOnLockScreen<br />

848 | P a g e

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!