8.1.17 Set 'Allow installation of desktop items' to 'Enabled:Disable'

Information



This policy setting allows you to manage whether users can install Active Desktop items
from this zone. The recommended state for this setting is- Enabled-Disable.

*Rationale*

Active Desktop items could contain links to unauthorized websites or other undesirable
content, it is prudent to prevent users from installing desktop items from this security
zone.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Internet Zone\Allow installation of
desktop itemsThen set the Allow installation of desktop items option to Disable.

Impact-The settings for this option are- Enabled, users can install desktop items from this zone
automatically. Prompt, users are queried to choose whether to install desktop items from
this zone. Disabled, users are prevented from installing desktop items from this zone. If you
do not configure this policy setting, users are prevented from installing desktop items from
this zone.


Default Value-Prompt

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(4)

Plugin: Windows

Control ID: be49809095ba14171c540b4d38e14bb36fe38a213e50bc567a86f1a6c902308a