8.3.4 Set 'Script ActiveX controls marked safe for scripting' to 'Enabled:Disable'

Information



This policy setting allows you to manage whether an ActiveX control marked safe for
scripting can interact with a script. The recommended state for this setting is-
Enabled-Disable.

*Rationale*

If you enable this policy setting, script interaction can occur automatically without user
intervention.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Script ActiveX
controls marked safe for scriptingThen set the Script ActiveX controls marked safe for scripting option to Disable.

Impact-If you enable this policy setting, script interaction can occur automatically without user
intervention. If you select Prompt in the drop-down box, users are queried to choose
whether to allow script interaction. If you disable this policy setting or do not configure this
policy setting, script interaction is prevented from occurring.

Default Value-
Disabled

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(3)

Plugin: Windows

Control ID: 8b66b32cb1db304910e1eb72cab94d69fb36a8c5b1c3b6877953c529c5a1a905