Microsoft Edge Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates +56 −43
Comparison against the immediately-prior release (V1R0.1). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Added rules 56
- V-235719 Medium User control of proxy settings must be disabled.
- V-235720 Medium Bypassing Microsoft Defender SmartScreen prompts for sites must be disabled.
- V-235721 Medium Bypassing of Microsoft Defender SmartScreen warnings about downloads must be disabled.
- V-235722 Low The list of domains for which Microsoft Defender SmartScreen will not trigger warnings must be whitelisted if used.
- V-235723 Medium InPrivate mode must be disabled.
- V-235724 Medium Background processing must be disabled.
- V-235725 Medium The ability of sites to show pop-ups must be disabled.
- V-235726 Medium The default search provider must be set to use an encrypted connection.
- V-235727 Low Data Synchronization must be disabled.
- V-235728 Medium Network prediction must be disabled.
- V-235729 Medium Search suggestions must be disabled.
- V-235730 Medium Importing of autofill form data must be disabled.
- V-235731 Low Importing of browser settings must be disabled.
- V-235732 Medium Importing of cookies must be disabled.
- V-235733 Medium Importing of extensions must be disabled.
- V-235734 Medium Importing of browsing history must be disabled.
- V-235735 Medium Importing of home page settings must be disabled.
- V-235736 Medium Importing of open tabs must be disabled.
- V-235737 Medium Importing of payment info must be disabled.
- V-235738 Medium Importing of saved passwords must be disabled.
- V-235739 Medium Importing of search engine settings must be disabled.
- V-235740 Medium Importing of shortcuts must be disabled.
- V-235741 Medium Autoplay must be disabled.
- V-235742 Medium WebUSB must be disabled.
- V-235743 Medium Google Cast must be disabled.
- V-235744 Medium Web Bluetooth API must be disabled.
- V-235745 Medium Autofill for Credit Cards must be disabled.
- V-235746 Medium Autofill for addresses must be disabled.
- V-235747 Medium Online revocation checks must be performed.
- V-235748 Medium Personalization of ads, search, and news by sending browsing history to Microsoft must be disabled.
- V-235749 Medium Site tracking of a user’s location must be disabled.
- V-235750 Medium Browser history must be saved.
- V-235751 Low Edge development tools must be disabled.
- V-235752 Low Download restrictions must be configured.
- V-235753 Medium URLs must be whitelisted for plugin use.
- V-235754 Medium Extensions installation must be blocklisted by default.
- V-235755 Medium Extensions that are approved for use must be allowlisted.
- V-235756 Medium The Password Manager must be disabled.
- V-235757 Medium The HTTPS warning page must not be able to be bypassed.
- V-235758 High The version of Microsoft Edge running on the system must be a supported version.
- V-235759 High Edge must be configured to allow only TLS.
- V-235760 Medium Site isolation for every site must be enabled.
- V-235761 Medium Supported authentication schemes must be configured.
- V-235762 Medium Messaging hosts that are used must be installed with administrative privileges.
- V-235763 Medium Microsoft Defender SmartScreen must be enabled.
- V-235764 Medium Microsoft Defender SmartScreen must be configured to block potentially unwanted apps.
- V-235765 Low The download location prompt must be configured.
- V-235766 Medium Tracking of browsing activity must be disabled.
- V-235767 Medium A website's ability to query for payment methods must be disabled.
- V-235768 Medium Suggestions of similar web pages in the event of a navigation error must be disabled.
- V-235769 Medium User feedback must be disabled.
- V-235770 Medium The collections feature must be disabled.
- V-235771 Medium The Share Experience feature must be disabled.
- V-235772 Medium Guest mode must be disabled.
- V-235773 Medium Relaunch notification must be required.
- V-235774 Medium The built-in DNS client must be disabled.
Removed rules 43
- EDGE-00-000001 Medium User control of proxy settings must be disabled.
- EDGE-00-000002 Medium Bypassing Microsoft Defender SmartScreen prompts for sites must be disabled.
- EDGE-00-000003 Medium Bypassing of Microsoft Defender SmartScreen warnings about downloads must be disabled.
- EDGE-00-000004 Low The list of domains for which Microsoft Defender SmartScreen will not trigger warnings must be whitelisted if utilized.
- EDGE-00-000005 Medium InPrivate mode must be disabled.
- EDGE-00-000006 Medium Background processing must be disabled.
- EDGE-00-000007 Medium The ability of sites to show desktop notifications must be disabled.
- EDGE-00-000008 Medium The ability of sites to show pop-ups must be disabled.
- EDGE-00-000009 Medium The default search provider must be set to use an encrypted connection.
- EDGE-00-000010 Medium Data Synchronization must be disabled.
- EDGE-00-000011 Medium Network prediction must be disabled.
- EDGE-00-000012 Medium Search suggestions must be disabled.
- EDGE-00-000013 Medium Importing of autofill form data must be disabled.
- EDGE-00-000014 Medium Importing of browser settings must be disabled.
- EDGE-00-000015 Medium Importing of Cookies must be disabled.
- EDGE-00-000016 Medium Importing of extensions must be disabled.
- EDGE-00-000017 Medium Importing of browsing history must be disabled.
- EDGE-00-000018 Medium Importing of home page settings must be disabled.
- EDGE-00-000019 Medium Importing of open tabs must be disabled.
- EDGE-00-000020 Medium Importing of payment info must be disabled.
- EDGE-00-000021 Medium Importing of saved passwords must be disabled.
- EDGE-00-000022 Medium Importing of search engine settings must be disabled.
- EDGE-00-000023 Medium Importing of shortcuts must be disabled.
- EDGE-00-000024 Medium Autoplay must be disabled.
- EDGE-00-000025 Medium WebUSB must be disabled.
- EDGE-00-000026 Medium Google Cast must be disabled.
- EDGE-00-000027 Medium Web Bluetooth API must be disabled.
- EDGE-00-000028 Medium Autofill for Credit Cards must be disabled.
- EDGE-00-000029 Medium Autofill for addresses must be disabled.
- EDGE-00-000030 Medium Online revocation checks must be performed.
- EDGE-00-000031 Medium Personalization of ads, search, and news by sending browsing history to Microsoft must be disabled.
- EDGE-00-000032 Medium Site tracking of a user’s location must be disabled.
- EDGE-00-000033 Medium Browser history must be saved.
- EDGE-00-000034 Low Edge development tools must be disabled.
- EDGE-00-000035 Medium Flash plugin must be disabled by default.
- EDGE-00-000036 Low Download restrictions must be configured.
- EDGE-00-000039 Medium URLs must be whitelisted for plugin use.
- EDGE-00-000041 Medium Extensions installation must be blocklisted by default.
- EDGE-00-000042 Medium Extensions that are approved for use must be allowlisted.
- EDGE-00-000043 Medium The Password Manager must be disabled.
- EDGE-00-000044 Medium The HTTPS warning page must not be able to be bypassed.
- EDGE-00-000045 High The version of Microsoft Edge running on the system must be a supported version.
- EDGE-00-000046 High Edge must be configured to allow only TLS.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- EDGE-00-000001
- Vuln IDs
-
- V-235719
- Rule IDs
-
- SV-235719r626523_rule
Checks: C-38938r626353_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Proxy server/ProxySettings" must be set to one of the following options: "ProxyMode", "ProxyPacUrl", "ProxyServer", or "ProxyBypassList". If "ProxyMode" is used, one of the following must be set: "direct", "system", "auto_detect", "fixed_server", "pac_script" Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "ProxySettings" is not set to one of the above selections, this is a finding.
Fix: F-38901r626354_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Proxy server/ProxySettings" must be set to "ProxyMode", "ProxyPacUrl", "ProxyServer", or "ProxyBypassList".
- RMF Control
- MA-3
- Severity
- M
- CCI
- CCI-000870
- Version
- EDGE-00-000002
- Vuln IDs
-
- V-235720
- Rule IDs
-
- SV-235720r626523_rule
Checks: C-38939r626356_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/SmartScreen settings/Prevent bypassing Microsoft Defender SmartScreen prompts for sites" must be set to "enabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "PreventSmartScreenPromptOverride" is not set to "enabled", this is a finding. If this machine is on SIPRNet, this is Not Applicable.
Fix: F-38902r626357_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/SmartScreen settings/Prevent bypassing Microsoft Defender SmartScreen prompts for sites" to "enabled".
- RMF Control
- MA-3
- Severity
- M
- CCI
- CCI-000870
- Version
- EDGE-00-000003
- Vuln IDs
-
- V-235721
- Rule IDs
-
- SV-235721r626523_rule
Checks: C-38940r626359_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/SmartScreen settings/Prevent bypassing of Microsoft Defender SmartScreen warnings about downloads" must be set to "enabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "PreventSmartScreenPromptOverrideForFiles" is not set to "enabled", this is a finding. If this machine is on SIPRNet, this is Not Applicable.
Fix: F-38903r626360_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/SmartScreen settings/Prevent bypassing of Microsoft Defender SmartScreen warnings about downloads" must to "enabled".
- RMF Control
- MA-3
- Severity
- L
- CCI
- CCI-000870
- Version
- EDGE-00-000004
- Vuln IDs
-
- V-235722
- Rule IDs
-
- SV-235722r626523_rule
Checks: C-38941r626362_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/SmartScreen settings/Configure the list of domains for which Microsoft Defender SmartScreen won't trigger warnings" may be set to "allow" for whitelisted domains. Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge SmartScreenAllowListDomains may be set as follows: HKLM\SOFTWARE\Policies\Microsoft\Edge\SmartScreenAllowListDomains\1 = mydomain.com HKLM\SOFTWARE\Policies\Microsoft\Edge\SmartScreenAllowListDomains\2 = myagency.mil This requirement for "SmartScreenAllowListDomains" is not required; this is optional. If configured, the list of domains for which Microsoft Defender SmartScreen will not trigger warnings must be whitelisted; otherwise this is a finding. If this machine is on SIPRNet, this is Not Applicable.
Fix: F-38904r626363_fix
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/SmartScreen settings/Configure the list of domains for which Microsoft Defender SmartScreen won't trigger warnings" may be set to "allow" for whitelisted domains.
- RMF Control
- AU-10
- Severity
- M
- CCI
- CCI-000166
- Version
- EDGE-00-000005
- Vuln IDs
-
- V-235723
- Rule IDs
-
- SV-235723r626523_rule
Checks: C-38942r626365_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Configure InPrivate mode availability" must be set to "enabled" with the option value set to "InPrivate mode disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "InPrivateModeAvailability" is not set to "REG_DWORD = 1", this is a finding.
Fix: F-38905r626366_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Configure InPrivate mode availability" to "enabled" and select "InPrivate mode disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000006
- Vuln IDs
-
- V-235724
- Rule IDs
-
- SV-235724r626523_rule
Checks: C-38943r626368_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Continue running background apps after Microsoft Edge closes" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge\Recommended If the value for "BackgroundModeEnabled" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38906r626369_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Continue running background apps after Microsoft Edge closes" to "disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000008
- Vuln IDs
-
- V-235725
- Rule IDs
-
- SV-235725r626523_rule
Checks: C-38944r626371_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Content settings/Default pop-up window setting" must be set to "Enabled" with the option value set to "Do not allow any site to show pop-ups". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for DefaultPopupsSetting is not set to "REG_DWORD = 2", this is a finding.
Fix: F-38907r626372_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Content settings/Default pop-up window setting" to "Enabled" with the option value set to "Do not allow any site to show pop-ups".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000009
- Vuln IDs
-
- V-235726
- Rule IDs
-
- SV-235726r626523_rule
Checks: C-38945r626374_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Manage Search Engines" must be configured. Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge\Recommended Example REG_SZ value text: [{"allow_search_engine_discovery": false},{"is_default": true,"name": "Microsoft Bing","keyword": "bing","search_url": "https://www.bing.com/search?q={searchTerms}"},{"name": "Google","keyword": "google","search_url": "https://www.google.com/search?q={searchTerms}"}] If any of the search URLs in the list do not begin with "https", this is a finding.
Fix: F-38908r626375_fix
Configure the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Manage Search Engines".
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- EDGE-00-000010
- Vuln IDs
-
- V-235727
- Rule IDs
-
- SV-235727r626523_rule
Checks: C-38946r626377_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Disable synchronization of data using Microsoft sync services" must be set to "enabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge\Recommended If the value for "SyncDisabled" is not set to "REG_DWORD = 1", this is a finding.
Fix: F-38909r626378_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Disable synchronization of data using Microsoft sync services" to "enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000011
- Vuln IDs
-
- V-235728
- Rule IDs
-
- SV-235728r626523_rule
Checks: C-38947r626380_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Enable network prediction" must be set to "Enabled" with the option value set to "Don't predict network actions on any network connection". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge\Recommended If the value for NetworkPredictionOptions is not set to "REG_DWORD = 2", this is a finding.
Fix: F-38910r626381_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Enable network prediction" to "Enabled" with the option value set to "Don't predict network actions on any network connection".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000012
- Vuln IDs
-
- V-235729
- Rule IDs
-
- SV-235729r626523_rule
Checks: C-38948r626383_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Enable search suggestions" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge\Recommended If the value for "SearchSuggestEnabled" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38911r626384_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Enable search suggestions" to "disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000013
- Vuln IDs
-
- V-235730
- Rule IDs
-
- SV-235730r626523_rule
Checks: C-38949r626386_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of autofill form data" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "ImportAutofillFormData" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38912r626387_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of autofill form data" to "disabled".
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- EDGE-00-000014
- Vuln IDs
-
- V-235731
- Rule IDs
-
- SV-235731r626523_rule
Checks: C-38950r626389_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of browser settings" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "ImportBrowserSettings" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38913r626390_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of browser settings" to "disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000015
- Vuln IDs
-
- V-235732
- Rule IDs
-
- SV-235732r626523_rule
Checks: C-38951r626392_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of cookies" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "ImportCookies" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38914r626393_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of cookies" to "disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000016
- Vuln IDs
-
- V-235733
- Rule IDs
-
- SV-235733r626523_rule
Checks: C-38952r626395_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of extensions" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "ImportExtensions" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38915r626396_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of extensions" to "disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000017
- Vuln IDs
-
- V-235734
- Rule IDs
-
- SV-235734r626540_rule
Checks: C-38953r626538_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of browsing history" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "ImportHistory" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38916r626539_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of browsing history" to "disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000018
- Vuln IDs
-
- V-235735
- Rule IDs
-
- SV-235735r626523_rule
Checks: C-38954r626401_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of home page settings" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "ImportHomepage" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38917r626402_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of home page settings" to "disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000019
- Vuln IDs
-
- V-235736
- Rule IDs
-
- SV-235736r626523_rule
Checks: C-38955r626404_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of open tabs" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "ImportOpenTabs" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38918r626405_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of open tabs" to "disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000020
- Vuln IDs
-
- V-235737
- Rule IDs
-
- SV-235737r626523_rule
Checks: C-38956r626407_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of payment info" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "ImportPaymentInfo" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38919r626408_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of payment info" to "disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000021
- Vuln IDs
-
- V-235738
- Rule IDs
-
- SV-235738r626523_rule
Checks: C-38957r626410_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of saved passwords" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "ImportSavedPasswords" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38920r626411_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of saved passwords" to "disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000022
- Vuln IDs
-
- V-235739
- Rule IDs
-
- SV-235739r626523_rule
Checks: C-38958r626413_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of search engine settings" must be set to "disabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "ImportSearchEngine" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38921r626414_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of search engine settings" to "disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000023
- Vuln IDs
-
- V-235740
- Rule IDs
-
- SV-235740r626523_rule
Checks: C-38959r626416_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of shortcuts" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "ImportShortcuts" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38922r626417_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow importing of shortcuts" to "disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000024
- Vuln IDs
-
- V-235741
- Rule IDs
-
- SV-235741r626523_rule
Checks: C-38960r626419_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow media autoplay for websites" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "AutoplayAllowed" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38923r626420_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow media autoplay for websites" to "disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000025
- Vuln IDs
-
- V-235742
- Rule IDs
-
- SV-235742r626523_rule
Checks: C-38961r626422_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Content settings/Control use of the WebUSB API" must be set to "enabled" with the option value set to "Do not allow any site to request access to USB devices via the WebUSB API". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "DefaultWebUsbGuardSetting" is not set to "REG_DWORD = 2", this is a finding.
Fix: F-38924r626423_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Content settings/Control use of the WebUSB API" to enabled" and select "Do not allow any site to request access to USB devices via the WebUSB API".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000026
- Vuln IDs
-
- V-235743
- Rule IDs
-
- SV-235743r626523_rule
Checks: C-38962r626425_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Cast/Enable Google Cast" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "EnableMediaRouter" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38925r626426_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Cast/Enable Google Cast" to "disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000027
- Vuln IDs
-
- V-235744
- Rule IDs
-
- SV-235744r626523_rule
Checks: C-38963r626428_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Content settings/Control use of the Web Bluetooth API" must be set to "enabled" with the option value set to "Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "DefaultWebBluetoothGuardSetting" is not set to "REG_DWORD = 2", this is a finding.
Fix: F-38926r626521_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Content settings/Control use of the Web Bluetooth API" to "enabled" with the option value set to "Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000028
- Vuln IDs
-
- V-235745
- Rule IDs
-
- SV-235745r626523_rule
Checks: C-38964r626431_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Enable AutoFill for credit cards" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "AutofillCreditCardEnabled" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38927r626432_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Enable AutoFill for credit cards" to "disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000029
- Vuln IDs
-
- V-235746
- Rule IDs
-
- SV-235746r626523_rule
Checks: C-38965r626434_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Enable AutoFill for addresses" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "AutofillAddressEnabled" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38928r626435_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Enable AutoFill for addresses" to "disabled".
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000185
- Version
- EDGE-00-000030
- Vuln IDs
-
- V-235747
- Rule IDs
-
- SV-235747r626523_rule
Checks: C-38966r626437_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Specify if online OCSP/CRL checks are required for local trust anchors" must be set to "enabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "RequireOnlineRevocationChecksForLocalAnchors" is not set to "REG_DWORD = 1", this is a finding.
Fix: F-38929r626438_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Specify if online OCSP/CRL checks are required for local trust anchors" to "enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000031
- Vuln IDs
-
- V-235748
- Rule IDs
-
- SV-235748r626523_rule
Checks: C-38967r626440_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow personalization of ads, search and news by sending browsing history to Microsoft" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "PersonalizationReportingEnabled" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38930r626441_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow personalization of ads, search and news by sending browsing history to Microsoft" to "disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000032
- Vuln IDs
-
- V-235749
- Rule IDs
-
- SV-235749r626523_rule
Checks: C-38968r626443_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Content settings/Default geolocation setting" must be set to "enabled" with the option value set to "Don't allow any site to track users' physical location". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "DefaultGeolocationSetting" is not set to "REG_DWORD = 2", this is a finding.
Fix: F-38931r626444_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Content settings/Default geolocation setting" to "enabled" and select "Don't allow any site to track users' physical location".
- RMF Control
- AU-10
- Severity
- M
- CCI
- CCI-000166
- Version
- EDGE-00-000033
- Vuln IDs
-
- V-235750
- Rule IDs
-
- SV-235750r626523_rule
Checks: C-38969r626446_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Enable deleting browser and download history" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "AllowDeletingBrowserHistory" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38932r626447_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Enable deleting browser and download history" to "disabled".
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- EDGE-00-000034
- Vuln IDs
-
- V-235751
- Rule IDs
-
- SV-235751r626523_rule
Checks: C-38970r626449_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Control where developer tools can be used" with the option value set to "Don't allow using the developer tools". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "DeveloperToolsAvailability" is not set to "REG_DWORD = 2", this is a finding.
Fix: F-38933r626450_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Control where developer tools can be used" to "enabled" and select "Don't allow using the developer tools".
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- EDGE-00-000036
- Vuln IDs
-
- V-235752
- Rule IDs
-
- SV-235752r640149_rule
Checks: C-38971r640147_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow download restrictions" must be set to "enabled" with the option value set to "Block potentially dangerous or unwanted downloads". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "DownloadRestrictions" is not set to "REG_DWORD = 1", or "REG_DWORD = 2", this is a finding.
Fix: F-38934r640148_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow download restrictions" to "enabled" and select "BlockDangerousDownloads" or "Block potentially dangerous or unwanted downloads".
- RMF Control
- CM-11
- Severity
- M
- CCI
- CCI-001812
- Version
- EDGE-00-000039
- Vuln IDs
-
- V-235753
- Rule IDs
-
- SV-235753r626523_rule
Checks: C-38972r626455_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Content settings/Allow pop-up windows on specific sites" must be set to "Enabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge "PopupsAllowedForUrls" must be set as follows: HKLM\SOFTWARE\Policies\Microsoft\Edge\PopupsAllowedForUrls\1 = mydomain.com HKLM\SOFTWARE\Policies\Microsoft\Edge\PopupsAllowedForUrls\2 = myagency.mil If the value for "PopupsAllowedForUrls" is not set, this is a finding. If no URLs in the agency require whitelisting for plugin use, this is Not Applicable.
Fix: F-38935r626456_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Content settings/Allow pop-up windows on specific sites" to "Enabled". A list of whitelisted URLs may be specified here.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000041
- Vuln IDs
-
- V-235754
- Rule IDs
-
- SV-235754r626523_rule
Checks: C-38973r626458_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Extensions/Control which extensions cannot be installed" must be set to "Enabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "ExtensionInstallBlocklist" is not set to "REG_SZ = *", this is a finding.
Fix: F-38936r626459_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Extensions/Control which extensions cannot be installed" to "Enabled". A list of blacklisted extensions may then be specified.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-001774
- Version
- EDGE-00-000042
- Vuln IDs
-
- V-235755
- Rule IDs
-
- SV-235755r626523_rule
Checks: C-38974r626461_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Extensions/Allow specific extensions to be installed" must be set to "Enabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge "ExtensionInstallAllowlist" must be set as follows: HKLM\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallAllowlist\1 = "extension_id1" HKLM\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallAllowlist\2 = "extension_id2" If the value for "ExtensionInstallAllowlist" is not set, this is a finding. If no extensions in the agency require whitelisting for use, this is Not Applicable.
Fix: F-38937r626462_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Extensions/Allow specific extensions to be installed" to "Enabled". A list of whitelisted extensions may then be specified.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-002007
- Version
- EDGE-00-000043
- Vuln IDs
-
- V-235756
- Rule IDs
-
- SV-235756r626523_rule
Checks: C-38975r626464_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Password manager and protection/Enable saving passwords to the password manager" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "PasswordManagerEnabled" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38938r626465_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Password manager and protection/Enable saving passwords to the password manager" to "disabled".
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-002470
- Version
- EDGE-00-000044
- Vuln IDs
-
- V-235757
- Rule IDs
-
- SV-235757r626523_rule
Checks: C-38976r626467_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow users to proceed from the HTTPS warning page" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "SSLErrorOverrideAllowed" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38939r626468_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow users to proceed from the HTTPS warning page" to "disabled".
- RMF Control
- SI-2
- Severity
- H
- CCI
- CCI-002605
- Version
- EDGE-00-000045
- Vuln IDs
-
- V-235758
- Rule IDs
-
- SV-235758r626523_rule
Checks: C-38977r626470_chk
Cross-reference the build information displayed with the Microsoft Edge site to identify, at minimum, the oldest supported build available. If the installed version of Edge is not supported by Microsoft, this is a finding.
Fix: F-38940r626471_fix
Install a supported version of Edge.
- RMF Control
- AC-17
- Severity
- H
- CCI
- CCI-001453
- Version
- EDGE-00-000046
- Vuln IDs
-
- V-235759
- Rule IDs
-
- SV-235759r626523_rule
Checks: C-38978r626473_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Minimum TLS version enabled" must be set to "TLS 1.2". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for SSLVersionMin is not set to "REG_SZ = tls1.2", this is a finding.
Fix: F-38941r626474_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Minimum TLS version enabled" to "TLS 1.2".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000047
- Vuln IDs
-
- V-235760
- Rule IDs
-
- SV-235760r626523_rule
Checks: C-38979r626476_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Enable site isolation for every site" must be set to "enabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "SitePerProcess" is not set to "REG_DWORD = 1", this is a finding.
Fix: F-38942r626477_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Enable site isolation for every site" to "enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- EDGE-00-000048
- Vuln IDs
-
- V-235761
- Rule IDs
-
- SV-235761r626523_rule
Checks: C-38980r626479_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/HTTP authentication/Supported authentication schemes" must be set to "enabled" with the option value set to "ntlm,negotiate". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "AuthSchemes" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38943r626480_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/HTTP authentication/Supported authentication schemes" to "ntlm,negotiate".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000049
- Vuln IDs
-
- V-235762
- Rule IDs
-
- SV-235762r626543_rule
Checks: C-38981r626542_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Native Messaging/Allow user-level native messaging hosts (installed without admin permissions)" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "NativeMessagingUserLevelHosts" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38944r626541_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Native Messaging/Allow user-level native messaging hosts (installed without admin permissions)" to "disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000050
- Vuln IDs
-
- V-235763
- Rule IDs
-
- SV-235763r626523_rule
Checks: C-38982r626485_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/SmartScreen settings/Configure Microsoft Defender SmartScreen" must be set to "enabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge\Recommended If the value for "SmartScreenEnabled" is not set to "REG_DWORD = 1", this is a finding. If this machine is on SIPRNet, this is Not Applicable.
Fix: F-38945r626486_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/SmartScreen settings/Configure Microsoft Defender SmartScreen" to "enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000051
- Vuln IDs
-
- V-235764
- Rule IDs
-
- SV-235764r626523_rule
Checks: C-38983r626488_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/SmartScreen settings/Configure Microsoft Defender SmartScreen to block potentially unwanted apps" must be set to "enabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge\Recommended If the value for SmartScreenPuaEnabled is not set to "REG_DWORD = 1", this is a finding. If this machine is on SIPRNet, this is Not Applicable.
Fix: F-38946r626489_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/SmartScreen settings/Configure Microsoft Defender SmartScreen to block potentially unwanted apps" to "enabled".
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- EDGE-00-000052
- Vuln IDs
-
- V-235765
- Rule IDs
-
- SV-235765r626523_rule
Checks: C-38984r626491_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Ask where to save downloaded files" must be set to "enabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "PromptForDownloadLocation" is not set to "REG_DWORD = 1", this is a finding.
Fix: F-38947r626492_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Ask where to save downloaded files" to "enabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000388
- Version
- EDGE-00-000054
- Vuln IDs
-
- V-235766
- Rule IDs
-
- SV-235766r626523_rule
Checks: C-38985r626494_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Block tracking of users' web-browsing activity" must be set to "enabled" with the option value set to "2" or "3". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "TrackingPrevention" is not set to "REG_DWORD = 1", this is a finding.
Fix: F-38948r626495_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Block tracking of users' web-browsing activity" to "2" or "3".
- RMF Control
- CM-8
- Severity
- M
- CCI
- CCI-000389
- Version
- EDGE-00-000055
- Vuln IDs
-
- V-235767
- Rule IDs
-
- SV-235767r626523_rule
Checks: C-38986r626497_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow websites to query for available payment methods" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for PaymentMethodQueryEnabled is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38949r626498_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow websites to query for available payment methods" to "disabled".
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000767
- Version
- EDGE-00-000056
- Vuln IDs
-
- V-235768
- Rule IDs
-
- SV-235768r626523_rule
Checks: C-38987r626500_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Suggest similar pages when a webpage can't be found" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge\Recommended If the value for AlternateErrorPagesEnabled is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38950r626501_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Suggest similar pages when a webpage can't be found" to "disabled".
- RMF Control
- CM-8
- Severity
- M
- CCI
- CCI-000392
- Version
- EDGE-00-000057
- Vuln IDs
-
- V-235769
- Rule IDs
-
- SV-235769r626523_rule
Checks: C-38988r626503_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow user feedback" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for UserFeedbackAllowed is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38951r626504_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Allow user feedback" to "disabled".
- RMF Control
- CM-8
- Severity
- M
- CCI
- CCI-000393
- Version
- EDGE-00-000058
- Vuln IDs
-
- V-235770
- Rule IDs
-
- SV-235770r626523_rule
Checks: C-38989r626506_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Enable the Collections feature" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "EdgeCollectionsEnabled" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38952r626507_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Enable the Collections feature" to "disabled".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000059
- Vuln IDs
-
- V-235771
- Rule IDs
-
- SV-235771r626523_rule
Checks: C-38990r626509_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Configure the Share experience" must be set to "enabled" with the option value set to "Don't allow using the Share experience". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "ConfigureShare" is not set to "REG_DWORD = 1", this is a finding.
Fix: F-38953r626510_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Configure the Share experience" to "Don't allow using the Share experience".
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- EDGE-00-000060
- Vuln IDs
-
- V-235772
- Rule IDs
-
- SV-235772r626523_rule
Checks: C-38991r626512_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Enable guest mode" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "BrowserGuestModeEnabled" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38954r626513_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Enable guest mode" to "disabled".
- RMF Control
- CM-8
- Severity
- M
- CCI
- CCI-000396
- Version
- EDGE-00-000061
- Vuln IDs
-
- V-235773
- Rule IDs
-
- SV-235773r626523_rule
Checks: C-38992r626515_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Notify a user that a browser restart is recommended or required for pending updates" must be set to "enabled" with the option value set to "Required". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "RelaunchNotification" is not set to "REG_DWORD = 2", this is a finding.
Fix: F-38955r626516_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Notify a user that a browser restart is recommended or required for pending updates" web-browsing activity to "Required".
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001942
- Version
- EDGE-00-000062
- Vuln IDs
-
- V-235774
- Rule IDs
-
- SV-235774r626523_rule
Checks: C-38993r626518_chk
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Use built-in DNS client" must be set to "disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "BuiltInDnsClientEnabled" is not set to "REG_DWORD = 0", this is a finding.
Fix: F-38956r626519_fix
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Use built-in DNS client" to "disabled".