Copilot must be disabled for Windows 11.

STIG ID: WN11-00-000125  |  SRG: SRG-OS-000096-GPOS-00050 |  Severity: medium |  CCI: CCI-000382 |  Vulnerability Id: V-268317

Vulnerability Discussion

Some features may communicate with the vendor, sending system information or downloading data or components for the feature. Turning off this capability will prevent potentially sensitive information from being sent outside the enterprise and uncontrolled updates to the system.

Check

Run the following PowerShell command as an administrator:

Get-AppxPackage -AllUsers | Where-Object { $_.Name -like "*Copilot*" }

If Microsoft.Copilot displays, this is a finding.

Fix

Open PowerShell as an administrator. Run the following command:

Get-AppxPackage -AllUsers *CoPilot* | Remove-AppxPackage -AllUsers