1.1 Set 'Turn on Enhanced Protected Mode' to 'Enabled'

Information



Enhanced Protected Mode provides additional protection against malicious websites by
using 64-bit processes on 64-bit versions of Windows. For computers running Windows 8
and above, Enhanced Protected Mode also limits the locations Internet Explorer can read
from in the registry and the file system.
If you enable this policy setting, Enhanced Protected Mode will be turned on. Any zone that
has Protected Mode enabled will use Enhanced Protected Mode. Users will not be able to
disable Enhanced Protected Mode.
If you disable this policy setting, Enhanced Protected Mode will be turned off. Any zone that
has Protected Mode enabled will use the version of Protected Mode introduced in Internet
Explorer 7 for Windows Vista.
If you do not configure this policy, users will be able to turn on or turn off Enhanced
Protected Mode on the Advanced tab of the Internet Options dialog. The recommended
state for this setting is- Enabled.

*Rationale*

Enhanced Protected Mode provides additional protection against malicious websites by
using 64-bit processes on 64-bit versions of Windows. For computers running Windows 8
and above, Enhanced Protected Mode also limits the locations Internet Explorer can read
from in the registry and the file system.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Advanced Page\Turn on Enhanced Protected Mode

Impact-If you enable this policy setting, Enhanced Protected Mode will be turned on. Any zone that
has Protected Mode enabled will use Enhanced Protected Mode. Users will not be able to
disable Enhanced Protected Mode.
If you disable this policy setting, Enhanced Protected Mode will be turned off. Any zone that
has Protected Mode enabled will use the version of Protected Mode introduced in Internet
Explorer 7 for Windows Vista.
If you do not configure this policy, users will be able to turn on or turn off Enhanced
Protected Mode on the Advanced tab of the Internet Options dialog.

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-3

Plugin: Windows

Control ID: 268089bb345dfac40d48dbe571a3ddd2f292cf3d1982532552ada3dab266d73f