Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-75207 | WNDF-AV-000011 | SV-89887r3_rule | Medium |
Description |
---|
This policy setting configures behavior of samples submission when opt-in for MAPS telemetry is set. Possible options are: (0x0) Always prompt (0x1) Send safe samples automatically (0x2) Never send (0x3) Send all samples automatically. |
STIG | Date |
---|---|
MS Windows Defender Antivirus Security Technical Implementation Guide | 2019-03-12 |
Check Text ( C-74999r3_chk ) |
---|
This is applicable to unclassified systems, for other systems this is NA. Verify the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Defender Antivirus -> MAPS -> "Send file samples when further analysis is required" is set to "Enabled" and "Send safe samples" selected from the drop down box. Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows Defender\Spynet Criteria: If the value "SubmitSamplesConsent" is REG_DWORD = 1, this is not a finding. |
Fix Text (F-81859r4_fix) |
---|
This is applicable to unclassified systems, for other systems this is NA. Set the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Windows Defender Antivirus -> MAPS -> "Send file samples when further analysis is required" to "Enabled" and select "Send safe samples" from the drop down box. |