4.2.7 Ensure 'Allow Window Management permission on these sites' Is Configured

Information

This setting can automatically allow access to the window management permissions for specific sites.

If the value for WindowManagementAllowedForUrls is not changed from the default, it will follow the configuration of DefaultWindowManagementSetting.

Rationale:

Allowing only specific sites to have access to Window Management will only allow permitted sites to see information about the device's screens, open additional browser windows specifying location, and size of the window.

Impact:

Enforcing this recommendation can cause visited sites to not display as intended.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled and set Show to the approved URLs:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Content settings\Allow Window Management permission on these sites

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3

Plugin: Windows

Control ID: 57304a6ee64393a54ea8445ab4d046e4e866f1cfcbd0ef21e5583d0951bcfe99