2.4 Set 'Turn on ActiveX Filtering' to 'Enabled'

Information

*Description*

This policy setting controls the ActiveX Filtering feature for websites running ActiveX
controls. The user can choose to turn off ActiveX Filtering for specific websites so that its
ActiveX controls can run properly. If you enable this policy setting, ActiveX Filtering will be
enabled by default for the user. The user cannot turn off ActiveX Filtering although they
may add per-site exceptions. If you disable this policy setting or do not configure it, ActiveX
Filtering will not be enabled by default for the user. The user can turn ActiveX Filtering on
or off. The recommended state for this setting is- Enabled.

*Rationale*

ActiveX Filtering allows you to make an informed decision about every ActiveX control you
run by giving you the ability to block ActiveX controls for all sites, and then turn them on
for only the sites that you trust. This can help improve your protection against risky and
unreliable ActiveX controls.

Solution

To implement the recommended configuration state, set the following Group Policy setting
to Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Turn on ActiveX Filtering

Impact-If you enable this policy setting, ActiveX Filtering will be enabled by default for the user.
The user cannot turn off ActiveX Filtering although they may add per-site exceptions. If you
disable this policy setting or do not configure it, ActiveX Filtering will not be enabled by
default for the user. The user can turn ActiveX Filtering on or off.

See Also

https://workbench.cisecurity.org/files/1516

Item Details

Audit Name: CIS IE 9 v1.0.0

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18, CSCv6|3.1

Plugin: Windows

Control ID: 602eef5cc4e254e6be8829c38350cbe2350a1db904399dd33d27b2161336519a