Configure User Profile Restrictions

Target Scope

  • Applicable Systems: Tier 2 Client Workstations
  • Operating Systems: Windows 10 (and above) Enterprise/Professional

Implementation Details

  • Priority: Medium
  • GPO Paths / Registry Locations:
    • GPO Paths: Multiple policies under Administrative Templates and Security Settings.
    • Registry Locations: Stored inside local HKLM and HKCU security hives under custom settings.

Rationale

Securing user profile characteristics and administrative explorer behaviors prevents exposure of sensitive information, restricts arbitrary file execution pathways, disables unapproved telemetry/consumer features, and locks down potential privilege escalation points.

This submodule contains individual requirement rules for each User Profile restriction setting configured on standard client workstations.


Legacy Impact & Compatibility

  • User Customization Limits: Users cannot customize lock screen slideshows, cameras, and Windows consumer feature recommendations. Legacy applications that rely on custom DLL loads via AppInit_DLLs or dynamically self-modifying batch processes may require exclusions or manual policy configurations.

Enforced User Profile Restrictions

The following individual User Profile restriction rules must be configured:

  1. REQ-END-126 - User Profile: Toast Notifications Lock Screen Restrictions
  2. REQ-END-127 - User Profile: Spotlight and Consumer Features Restrictions
  3. REQ-END-128 - User Profile: Windows Copilot Restrictions
  4. REQ-END-129 - User Profile: In-Place Sharing Restrictions
  5. REQ-END-130 - User Profile: Shell RunAs User Suppression
  6. REQ-END-131 - User Profile: Personalization and Privacy Restrictions
  7. REQ-END-132 - User Profile: Group Policy Processing Behaviors
  8. REQ-END-133 - User Profile: Telemetry and Inventory Collection Restrictions
  9. REQ-END-134 - User Profile: Explorer Security and Memory Protections
  10. REQ-END-135 - User Profile: Internet Explorer Options and Feeds Restrictions
  11. REQ-END-136 - User Profile: Interactive Logon Warning Banners
  12. REQ-END-137 - User Profile: Interactive Logon Inactivity Timeout
  13. REQ-END-138 - User Profile: Windows Installer Hardening
  14. REQ-END-139 - User Profile: Secondary Logon Service Lockdown
  15. REQ-END-151 - User Profile: Structured Exception Handling Overwrite Protection (SEHOP) for Endpoints
  16. REQ-END-152 - User Profile: Directory Protection Mode for Endpoints
  17. REQ-END-153 - User Profile: Address Space Layout Randomization (ASLR) Image Relocation for Endpoints
  18. REQ-END-154 - User Profile: Speculative Execution Mitigations (Spectre/Meltdown) for Endpoints
  19. REQ-END-155 - User Profile: Authenticode Certificate Padding Check for Endpoints
  20. REQ-END-156 - User Profile: Command Processor Batch File Locking for Endpoints
  21. REQ-END-157 - User Profile: Time-Travel Debugging (TTD) Recording Policy for Endpoints
  22. REQ-END-158 - User Profile: Trusted Root Store Protected Roots Certificate Restriction for Endpoints
  23. REQ-END-159 - User Profile: Disabling Injection of AppInit DLLs for Endpoints
  24. REQ-END-160 - User Profile: Preservation of Attachment Zone Information for Endpoints
  25. REQ-END-161 - User Profile: Disable Windows Game DVR for Endpoints
  26. REQ-END-162 - User Profile: Restrict Windows Ink Workspace on Lock Screen for Endpoints

Sources & Compliance References

  • CIS Microsoft Windows 10/11 Benchmark: Section 18.8 (User Profile Settings)
  • ANSSI Active Directory Hardening Guide: Client security baselines

results matching ""

    No results matching ""