STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← Back to VMware Horizon 7.13 Agent Security Technical Implementation Guide

V-246869

CAT II (Medium)

The Horizon Agent must not allow drag and drop for Blast.

Rule ID

SV-246869r768567_rule

STIG

VMware Horizon 7.13 Agent Security Technical Implementation Guide

Version

V1R1

CCIs

CCI-000366

Discussion

Data loss prevention is a primary concern for the DoD, maintaining positive control of data at all times and only allowing flows over channels that are for that explicit purpose and monitored appropriately. Additionally, data coming into the environment must be through allowed channels and inspected appropriately. By default, the Blast protocol on the Horizon Agent will allow drag and drop actions from the client to the desktop. This must be configured to disabled in both directions.

Check Content

Ensure the vdm_blast.admx template is added. Open the "Group Policy Management" MMC snap-in. Open the site-specific GPO applying Horizon settings to the VDI desktops or RDS hosts.

Navigate to Computer Configuration >> Policies >> Administrative Templates >> VMware Blast. Double-click the "Configure drag and drop direction" setting.

If "Configure drag and drop direction" is not "Enabled", this is a finding.

In the drop-down under "Configure drag and drop", if "Disabled in both directions" is not selected, this is a finding.

Fix Text

Ensure the vdm_blast.admx template is added. Open the "Group Policy Management" MMC snap-in. Open the site-specific GPO applying Horizon settings to the VDI desktops or RDS hosts.

Navigate to Computer Configuration >> Policies >> Administrative Templates >> VMware Blast. Double-click the "Configure drag and drop" setting.

Click the radio button next to "Enabled".

In the drop-down under "Configure drag and drop", select "Disabled in both directions". Click "OK".