Information
This policy setting determines whether a page can control embedded WebBrowser controls
via script. If you enable this policy setting, script access to the WebBrowser control is
allowed. If you disable this policy setting, script access to the WebBrowser control is not
allowed.
If you do not configure this policy setting, the user can enable or disable script access to the
WebBrowser control. By default, script access to the WebBrowser control is allowed only in
the Local Machine and Intranet zones. The recommended state for this setting is-
Enabled-Disable.
*Rationale*
A website hosted by a malicious person could attempt to exploit this feature. For example,
in the past there have been cross-site scripting vulnerabilities that were exploited to use
various WebBrowser controls.
Solution
To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.
Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Internet Zone\Allow scripting of
Internet Explorer WebBrowser controlsThen set the Internet Explorer web browser control option to Disable.
Impact-If you enable this policy setting, script access to the WebBrowser control is allowed. If you
disable this policy setting, script access to the WebBrowser control is not allowed. If you do
not configure this policy setting, the user can enable or disable script access to the
WebBrowser control. By default, script access to the WebBrowser control is allowed only in
the Local Machine and Intranet zones.