8.3.39 Configure 'First-Run Opt-In'

Information



This policy setting controls the first-run response that the user sees on a zone-by-zone
basis. When the user encounters a new control that has not previously run in Internet
Explorer, he or she may be prompted to approve the control. This policy setting determines
whether the user is prompted. If you enable this policy setting, the first-run prompt is
turned off in the corresponding zone. If you disable this policy setting, the first-run prompt
is turned on in the corresponding zone. If you do not configure this policy setting, the first-
run prompt is turned off by default. Configure this setting in a manner that is consistent
with security and operational requirements of your organization.

*Rationale*

The first-run prompt may help the user to avoid some types of malware hosted on sites run
by malicious people.

Solution


To establish the recommended configuration via Group Policy, set the following UI path to
Not Configured.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Turn off first-run
prompt- First-Run Opt-In

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|3.1

Plugin: Windows

Control ID: c6735075396cd14e60231874c0f8056ec7909054e756d8377cf8d44ee4a12339