Configure User Profile Restrictions for PAWs
Target Scope
- Applicable Systems: Privileged Access Workstations (PAWs) used for Tier 0 directory administration.
- Operating Systems: Windows 10 Enterprise (1607+) and Windows 11 Enterprise.
Implementation Details
- Priority: Medium
- GPO Paths / Registry Locations:
- GPO Paths: Multiple policies under Administrative Templates and Security Settings.
- Registry Locations: Stored inside local HKLM and HKCU security hives under custom settings.
Rationale
Enforcing User Profile Restrictions on PAWs prevents information disclosure on locked consoles, blocks advertising or unapproved telemetry/consumer features, and locks down installer paths to guarantee administrative console isolation.
This submodule contains individual requirement rules for each User Profile restriction setting configured on Privileged Access Workstations.
Legacy Impact & Compatibility
- Minimal Impact: Operational impact is non-existent because PAW consoles do not host standard user sessions or productivity applications. Custom drivers and management utilities must be pre-approved and signed.
Enforced User Profile Restrictions on PAWs
The following individual User Profile restriction rules must be configured:
- REQ-PAW-115 - User Profile: Toast Notifications Lock Screen Restrictions for PAWs
- REQ-PAW-116 - User Profile: Spotlight and Consumer Features Restrictions for PAWs
- REQ-PAW-117 - User Profile: Windows Copilot Restrictions for PAWs
- REQ-PAW-118 - User Profile: In-Place Sharing Restrictions for PAWs
- REQ-PAW-119 - User Profile: Shell RunAs User Suppression for PAWs
- REQ-PAW-120 - User Profile: Personalization and Privacy Restrictions for PAWs
- REQ-PAW-121 - User Profile: Group Policy Processing Behaviors for PAWs
- REQ-PAW-122 - User Profile: Telemetry and Inventory Collection Restrictions for PAWs
- REQ-PAW-123 - User Profile: Explorer Security and Memory Protections for PAWs
- REQ-PAW-124 - User Profile: Internet Explorer Options and Feeds Restrictions for PAWs
- REQ-PAW-125 - User Profile: Interactive Logon Warning Banners for PAWs
- REQ-PAW-126 - User Profile: Interactive Logon Inactivity Timeout for PAWs
- REQ-PAW-127 - User Profile: Windows Installer Hardening for PAWs
- REQ-PAW-128 - User Profile: Secondary Logon Service Lockdown for PAWs
- REQ-PAW-140 - User Profile: Structured Exception Handling Overwrite Protection (SEOP) for PAWs
- REQ-PAW-141 - User Profile: Directory Protection Mode for PAWs
- REQ-PAW-142 - User Profile: Address Space Layout Randomization (ASLR) Image Relocation for PAWs
- REQ-PAW-143 - User Profile: Speculative Execution Mitigations (Spectre/Meltdown) for PAWs
- REQ-PAW-144 - User Profile: Authenticode Certificate Padding Check for PAWs
- REQ-PAW-145 - User Profile: Command Processor Batch File Locking for PAWs
- REQ-PAW-146 - User Profile: Time-Travel Debugging (TTD) Recording Policy for PAWs
- REQ-PAW-147 - User Profile: Trusted Root Store Protected Roots Certificate Restriction for PAWs
- REQ-PAW-148 - User Profile: Disabling Injection of AppInit DLLs for PAWs
- REQ-PAW-149 - User Profile: Preservation of Attachment Zone Information for PAWs
- REQ-PAW-150 - User Profile: Disable Windows Game DVR for PAWs
- REQ-PAW-151 - User Profile: Restrict Windows Ink Workspace on Lock Screen for PAWs
Sources & Compliance References
- CIS Microsoft Windows Benchmark: PAW workstation restrictions
- ANSSI Active Directory Hardening Guide: Workstation baseline guide