Configure User Profile Restrictions
Target Scope
- Applicable Systems: Tier 2 Client Workstations
- Operating Systems: Windows 10 (and above) Enterprise/Professional
Implementation Details
- Priority: Medium
- GPO Paths / Registry Locations:
- GPO Paths: Multiple policies under Administrative Templates and Security Settings.
- Registry Locations: Stored inside local HKLM and HKCU security hives under custom settings.
Rationale
Securing user profile characteristics and administrative explorer behaviors prevents exposure of sensitive information, restricts arbitrary file execution pathways, disables unapproved telemetry/consumer features, and locks down potential privilege escalation points.
This submodule contains individual requirement rules for each User Profile restriction setting configured on standard client workstations.
Legacy Impact & Compatibility
- User Customization Limits: Users cannot customize lock screen slideshows, cameras, and Windows consumer feature recommendations. Legacy applications that rely on custom DLL loads via AppInit_DLLs or dynamically self-modifying batch processes may require exclusions or manual policy configurations.
Enforced User Profile Restrictions
The following individual User Profile restriction rules must be configured:
- REQ-END-126 - User Profile: Toast Notifications Lock Screen Restrictions
- REQ-END-127 - User Profile: Spotlight and Consumer Features Restrictions
- REQ-END-128 - User Profile: Windows Copilot Restrictions
- REQ-END-129 - User Profile: In-Place Sharing Restrictions
- REQ-END-130 - User Profile: Shell RunAs User Suppression
- REQ-END-131 - User Profile: Personalization and Privacy Restrictions
- REQ-END-132 - User Profile: Group Policy Processing Behaviors
- REQ-END-133 - User Profile: Telemetry and Inventory Collection Restrictions
- REQ-END-134 - User Profile: Explorer Security and Memory Protections
- REQ-END-135 - User Profile: Internet Explorer Options and Feeds Restrictions
- REQ-END-136 - User Profile: Interactive Logon Warning Banners
- REQ-END-137 - User Profile: Interactive Logon Inactivity Timeout
- REQ-END-138 - User Profile: Windows Installer Hardening
- REQ-END-139 - User Profile: Secondary Logon Service Lockdown
- REQ-END-151 - User Profile: Structured Exception Handling Overwrite Protection (SEHOP) for Endpoints
- REQ-END-152 - User Profile: Directory Protection Mode for Endpoints
- REQ-END-153 - User Profile: Address Space Layout Randomization (ASLR) Image Relocation for Endpoints
- REQ-END-154 - User Profile: Speculative Execution Mitigations (Spectre/Meltdown) for Endpoints
- REQ-END-155 - User Profile: Authenticode Certificate Padding Check for Endpoints
- REQ-END-156 - User Profile: Command Processor Batch File Locking for Endpoints
- REQ-END-157 - User Profile: Time-Travel Debugging (TTD) Recording Policy for Endpoints
- REQ-END-158 - User Profile: Trusted Root Store Protected Roots Certificate Restriction for Endpoints
- REQ-END-159 - User Profile: Disabling Injection of AppInit DLLs for Endpoints
- REQ-END-160 - User Profile: Preservation of Attachment Zone Information for Endpoints
- REQ-END-161 - User Profile: Disable Windows Game DVR for Endpoints
- REQ-END-162 - User Profile: Restrict Windows Ink Workspace on Lock Screen for Endpoints
Sources & Compliance References
- CIS Microsoft Windows 10/11 Benchmark: Section 18.8 (User Profile Settings)
- ANSSI Active Directory Hardening Guide: Client security baselines