2.2 Ensure 'Default notification setting' is set to 'Enabled' with 'Do not allow any site to show desktop notifications'

Information

Google Chrome offers websites to display desktop notifications. These are push messages which are sent from the website operator through Google infrastructure to Chrome.
Rationale:
If the website operator decides to send messages unencrypted Google's servers may process it as plain text. Furthermore, potentially compromised or faked notifications might trick users into clicking on a malicious link.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled with Do not allow any site to show desktop notifications selected from the drop down:
Computer Configuration\Administrative Templates\Google\Google Chrome\Content Settings\Default notification setting
Impact:
If this setting is enabled and set to Do not allow any site to show desktop notifications, notifications will not be displayed for any sites and the user will not be asked.
Default Value:
Enabled: AskNotifications.

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv7|7

Plugin: Windows

Control ID: 3adb0ff8e89d6a4a39bca415523b550ab8ea7c7bd06397cc6ac1417f1f452bac