9.9 Set 'Prevent 'Fix settings' functionality' to 'Disabled'

Information



This policy setting prevents users from performing the 'Fix settings' functionality related
to the Security Settings Check in Internet Explorer. The recommended state for this setting
is- Disabled.

*Rationale*

The 'Fix settings' feature is an easy way for users to restore secure settings for Internet
Explorer should the settings be misconfigured in some way, disabling will prevent users
from quickly returning the browser to its default configuration.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Disabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Prevent 'Fix settings' functionality

Impact-If you enable this policy setting, users cannot click the Fix Settings For Me option in the
Information bar context menu that appears when Internet Explorer determines that its
configuration is not secure.

Default Value-Disabled

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: ACCESS CONTROL

References: 800-53|AC-6(10)

Plugin: Windows

Control ID: e2b48737f075a4905bd4519f88b95750ace93c8ce132cc6515dffcf720027ed7