8.3.40 Set 'Enable dragging of content from different domains across windows' to 'Enabled:Disable'

Information



This policy setting allows you to set options for dragging content from one domain to a
different domain when the source and destination are in different windows. If you enable
this policy setting and click Enable, users can drag content from one domain to a different
domain when the source and destination are in different windows. Users cannot change
this setting. If you enable this policy setting and click Disable, users cannot drag content
from one domain to a different domain when both the source and destination are in
different windows. Users cannot change this setting. In Internet Explorer 10, if you disable
this policy setting or do not configure it, users cannot drag content from one domain to a
different domain when the source and destination are in different windows. Users can
change this setting in the Internet Options dialog. In Internet Explorer 9 and earlier
versions, if you disable this policy or do not configure it, users can drag content from one
domain to a different domain when the source and destination are in different windows.
Users cannot change this setting. The recommended state for this setting is-
Enabled-Disable.

*Rationale*

Content hosted on untrusted sites are more likely to contain malicious payloads and
therefor this feature should be blocked for this zone.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Enable dragging of
content from different domains across windowsThen set the Enable dragging of content from different domains across windows
option to Disable.

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(3), CSCv6|3.1

Plugin: Windows

Control ID: 458dab04e60ce04397a1e80fc2a09c8f03ec2b43ade219f762980b6a5a24242b