Configure User Profile Restrictions for PAWs

Target Scope

  • Applicable Systems: Privileged Access Workstations (PAWs) used for Tier 0 directory administration.
  • Operating Systems: Windows 10 Enterprise (1607+) and Windows 11 Enterprise.

Implementation Details

  • Priority: Medium
  • GPO Paths / Registry Locations:
    • GPO Paths: Multiple policies under Administrative Templates and Security Settings.
    • Registry Locations: Stored inside local HKLM and HKCU security hives under custom settings.

Rationale

Enforcing User Profile Restrictions on PAWs prevents information disclosure on locked consoles, blocks advertising or unapproved telemetry/consumer features, and locks down installer paths to guarantee administrative console isolation.

This submodule contains individual requirement rules for each User Profile restriction setting configured on Privileged Access Workstations.


Legacy Impact & Compatibility

  • Minimal Impact: Operational impact is non-existent because PAW consoles do not host standard user sessions or productivity applications. Custom drivers and management utilities must be pre-approved and signed.

Enforced User Profile Restrictions on PAWs

The following individual User Profile restriction rules must be configured:

  1. REQ-PAW-115 - User Profile: Toast Notifications Lock Screen Restrictions for PAWs
  2. REQ-PAW-116 - User Profile: Spotlight and Consumer Features Restrictions for PAWs
  3. REQ-PAW-117 - User Profile: Windows Copilot Restrictions for PAWs
  4. REQ-PAW-118 - User Profile: In-Place Sharing Restrictions for PAWs
  5. REQ-PAW-119 - User Profile: Shell RunAs User Suppression for PAWs
  6. REQ-PAW-120 - User Profile: Personalization and Privacy Restrictions for PAWs
  7. REQ-PAW-121 - User Profile: Group Policy Processing Behaviors for PAWs
  8. REQ-PAW-122 - User Profile: Telemetry and Inventory Collection Restrictions for PAWs
  9. REQ-PAW-123 - User Profile: Explorer Security and Memory Protections for PAWs
  10. REQ-PAW-124 - User Profile: Internet Explorer Options and Feeds Restrictions for PAWs
  11. REQ-PAW-125 - User Profile: Interactive Logon Warning Banners for PAWs
  12. REQ-PAW-126 - User Profile: Interactive Logon Inactivity Timeout for PAWs
  13. REQ-PAW-127 - User Profile: Windows Installer Hardening for PAWs
  14. REQ-PAW-128 - User Profile: Secondary Logon Service Lockdown for PAWs
  15. REQ-PAW-140 - User Profile: Structured Exception Handling Overwrite Protection (SEOP) for PAWs
  16. REQ-PAW-141 - User Profile: Directory Protection Mode for PAWs
  17. REQ-PAW-142 - User Profile: Address Space Layout Randomization (ASLR) Image Relocation for PAWs
  18. REQ-PAW-143 - User Profile: Speculative Execution Mitigations (Spectre/Meltdown) for PAWs
  19. REQ-PAW-144 - User Profile: Authenticode Certificate Padding Check for PAWs
  20. REQ-PAW-145 - User Profile: Command Processor Batch File Locking for PAWs
  21. REQ-PAW-146 - User Profile: Time-Travel Debugging (TTD) Recording Policy for PAWs
  22. REQ-PAW-147 - User Profile: Trusted Root Store Protected Roots Certificate Restriction for PAWs
  23. REQ-PAW-148 - User Profile: Disabling Injection of AppInit DLLs for PAWs
  24. REQ-PAW-149 - User Profile: Preservation of Attachment Zone Information for PAWs
  25. REQ-PAW-150 - User Profile: Disable Windows Game DVR for PAWs
  26. REQ-PAW-151 - User Profile: Restrict Windows Ink Workspace on Lock Screen for PAWs

Sources & Compliance References

  • CIS Microsoft Windows Benchmark: PAW workstation restrictions
  • ANSSI Active Directory Hardening Guide: Workstation baseline guide

results matching ""

    No results matching ""