9.15 Set 'Turn on 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows' to 'Enabled'

Information



This policy setting determines whether Internet Explorer 11 uses 64-bit processes (for
greater security) or 32-bit processes (for greater compatibility) when running in Enhanced
Protected Mode on 64-bit versions of Windows.If you enable this policy setting, Internet Explorer 11 will use 64-bit tab processes when
running in Enhanced Protected Mode on 64-bit versions of Windows.If you disable this policy setting, Internet Explorer 11 will use 32-bit tab processes when
running in Enhanced Protected Mode on 64-bit versions of Windows.If you don't configure this policy setting, users can turn this feature on or off using Internet
Explorer settings. This feature is turned off by default.

*Rationale*

Enabling 64-bit tab processes will improve the efficacy of exploit mitigations, such as
Address Space Layout Randomization (ASLR).

Solution


To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Advanced Page

Impact-Some ActiveX controls and toolbars may not be available when 64-bit processes are used.

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-3

Plugin: Windows

Control ID: 6cc8a6f2e35be8a827d496730788b09f6d02a5c04ba20cb6e6608907d1c7bbe6