8.3.30 Set 'Allow META REFRESH' to 'Enabled:Disable'

Information



This policy setting allows you to manage whether a user's browser can be redirected to
another Web page if the author of the Web page uses the Meta Refresh setting to redirect
browsers to another Web page. The recommended state for this setting is-
Enabled-Disable.

*Rationale*

It is possible that users will unknowingly be redirected to a site hosting malicious content.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow META REFRESHThen set the Allow META REFRESH option to Disable.

Impact-If you enable this policy setting, a user's browser that loads a page containing an active
Meta Refresh setting can be redirected to another Web page. If you disable this policy
setting, a user's browser that loads a page containing an active Meta Refresh setting cannot
be redirected to another Web page. If you do not configure this policy setting, a user's
browser that loads a page containing an active Meta Refresh setting cannot be redirected to
another Web page.

Default Value-Disabled

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: d42b355728d6ffb3357cd95afcddd3d50028aaba01548934225d69d04953bc76