Windows Telemetry
Summary
Automate role to detect if a Windows agent has telemetry enabled. If the Windows Telemetry role is detected, telemetry data is being sent to Microsoft. This includes any configuration that does not have telemetry disabled.
Settings
Role Name
- Windows Telemetry
Type
- PowerShell
Sub-Type
- Security
Detection String
- {%-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DataCollection:AllowTelemetry-%}
Comparator
- Regex Match
Result
- [1-3]
Applicable OS
- Windows