9.14 Set 'Turn on the auto-complete feature for user names and passwords on forms' to 'Disabled'

Information



This AutoComplete feature can remember and suggest User names and passwords on
Forms.
If you enable this setting, the user cannot change 'User name and passwords on forms' or
'prompt me to save passwords'. The Auto Complete feature for User names and passwords
on Forms will be turned on. You have to decide whether to select 'prompt me to save
passwords'.
If you disable this setting the user cannot change 'User name and passwords on forms' or
'prompt me to save passwords'. The Auto Complete feature for User names and passwords
on Forms is turned off. The user also cannot opt to be prompted to save passwords.
If you do not configure this setting, the user has the freedom of turning on Auto complete
for User name and passwords on forms and the option of prompting to save passwords. To
display this option, the users open the Internet Options dialog box, click the Contents Tab
and click the Settings button. The recommended state for this setting is- Disabled.

*Rationale*

It is possible that malware could be developed which would be able to extract the cached
user names and passwords from the currently logged on user, which an attacker could then
use to compromise that user's online accounts.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Disabled.User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn
on the auto-complete feature for user names and passwords on forms

Impact-
If you disable this policy setting, the check boxes for User Names and Passwords on Forms
and Prompt Me to Save Passwords are dimmed and users are prevented from saving
passwords locally.

Default Value-Disabled

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CSCv6|3.1

Plugin: Windows

Control ID: 831850f64029999e6d962cc68d51e23a2658d06f4f8e8ba3b2e2a42ad00c6926