8.3.8 Set 'Allow META REFRESH' to 'Enabled:Disable'

Information

*Description*

This policy setting allows you to manage whether a user's browser can be redirected to
another Web page if the author of the Web page uses the Meta Refresh setting to redirect
browsers to another Web page. The recommended state for this setting is-
Enabled-Disable.

*Rationale*

It is possible that users will unknowingly be redirected to a site hosting malicious content.

Solution

To implement the recommended configuration state, set the following Group Policy setting
to Enabled.
Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow META
REFRESH\Allow META REFRESH

Then set the Allow META REFRESH option to Disable.

Impact-If you enable this policy setting, a user's browser that loads a page containing an active
Meta Refresh setting can be redirected to another Web page. If you disable this policy
setting, a user's browser that loads a page containing an active Meta Refresh setting cannot
be redirected to another Web page. If you do not configure this policy setting, a user's
browser that loads a page containing an active Meta Refresh setting cannot be redirected to
another Web page.

See Also

https://workbench.cisecurity.org/files/1516

Item Details

Audit Name: CIS IE 9 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: b82ed88b813bb271973784b4406f5ab541089d3c280962b122aaa67a5b67eed6