Skip to main content

Windows Telemetry

Summary

Automate role to detect if a Windows agent has telemetry enabled. If the Windows Telemetry role is detected, telemetry data is being sent to Microsoft. This includes any configuration that does not have telemetry disabled.

Settings

Role Name

  • Windows Telemetry

Type

  • PowerShell

Sub-Type

  • Security

Detection String

  • {%-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DataCollection:AllowTelemetry-%}

Comparator

  • Regex Match

Result

  • [1-3]

Applicable OS

  • Windows