CIS Microsoft Windows 10 Enterprise Release 1909 Benchmark
18.8.21.5 (L1) Ensure 'Turn off background refresh of Group Policy' is set to 'Disabled' (Scored)
ProfileApplicability:
Level 1 (L1) - Corporate/Enterprise Environment (general use)
Description:
This policy setting prevents Group Policy frombeing updated while the computer is in use. This policy setting applies to Group Policy for computers, users and Domain Controllers.
The recommended state for this setting is: Disabled .
Rationale:
This setting ensures that group policy changes take effect more quickly, as compared to waiting until the next user logon or system restart.
Audit:
Navigate to the UI Path articulated in the Remediation section and confirm it is set as prescribed. This group policy setting is in effect when the following registry location does not exist:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System: DisableBkGndGroupPolicy
Remediation:
To establish the recommended configuration via GP, set the following UI path to Disabled :
Computer Configuration\Policies\Administrative Templates\System\Group Policy\Turn off background refresh of Group Policy
Note: This Group Policy path is provided by the Group Policy template GroupPolicy.admx/adml that is included with all versions of the Microsoft Windows Administrative Templates.
Impact:
None - this is the default behavior.
665 | P a g e
Made with FlippingBook - Online magazine maker