[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-98636-4

Platform: cpe:/o:microsoft:windows_10Date: (C)2022-06-20   (M)2023-07-04



This policy setting allows you to decide whether data should persist across different sessions in Microsoft Defender Application Guard. If you enable this setting, Application Guard saves user-downloaded files and other items (such as, cookies, Favorites, and so on) for use in future Application Guard sessions. Note: If you enable this setting, you can still delete a user's data from a specific device using the Reset-ApplicationGuard PowerShell command. Running this command deletes all employee data, regardless of configuration, and can result in data loss for the employee. If you disable or don't configure this setting, Application Guard deletes all user data within the Application Guard container. Fix: (1) GPO: Computer ConfigurationAdministrative TemplatesWindows ComponentsMicrosoft Defender Application GuardAllow data persistence for Microsoft Defender Application Guard (2) REG: HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftAppHVSI!AllowPersistence


Parameter:

[enable/disable]


Technical Mechanism:

(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Microsoft Defender Application Guard\Allow data persistence for Microsoft Defender Application Guard (2) REG: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\AppHVSI!AllowPersistence

CCSS Severity:CCSS Metrics:
CCSS Score : 8.8Attack Vector: LOCAL
Exploit Score: 2.0Attack Complexity: LOW
Impact Score: 6.0Privileges Required: LOW
Severity: HIGHUser Interaction: NONE
Vector: AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HScope: CHANGED
 Confidentiality: HIGH
 Integrity: HIGH
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:81726


OVAL    1
oval:org.secpod.oval:def:81726
XCCDF    1
xccdf_org.secpod_benchmark_general_Windows_10

© SecPod Technologies