8.2.3 Set 'Intranet Sites: Include all network paths (UNCs)' to 'Disabled'

Information



This policy setting controls whether URLs representing UNCs are mapped into the local
Intranet security zone. The recommended state for this setting is- Disabled.

*Rationale*

Some UNC paths could refer to servers not managed by the organization which means they
could host malicious content and therefor it is safest to not include all UNC paths in the
Intranet Sites zone.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Disabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Intranet Sites- Include all network
paths (UNCs)

Impact-
If you enable this policy setting, all network paths are mapped into the Intranet Zone. If you
disable this policy setting, network paths are not necessarily mapped into the Intranet
Zone (other rules might map one there).
If you do not configure this policy setting, users choose whether network paths are mapped
into the Intranet Zone.

Default Value-Not configured.

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|3.1

Plugin: Windows

Control ID: 3d2e09de56b03cb5056f217a152d1e383327c28245cdb509d2bf39d48daaf409