Information
The MK Protocol Security Restriction policy setting reduces attack surface area by
preventing the MK protocol. Resources hosted on the MK protocol will fail. If you enable
this policy setting, the MK Protocol is prevented for File Explorer and Internet Explorer,
and resources hosted on the MK protocol will fail. If you disable this policy setting,
applications can use the MK protocol API. Resources hosted on the MK protocol will work
for the File Explorer and Internet Explorer processes. If you do not configure this policy
setting, the MK Protocol is prevented for File Explorer and Internet Explorer, and resources
hosted on the MK protocol will fail. The recommended state for this setting is- Enabled.
*Rationale*
Because the MK protocol is not widely used, it should be blocked wherever it is not needed.
Solution
To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.
Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Security Features\MK Protocol Security Restriction\Internet Explorer
Processes
Default Value-Enabled