9.5 Set 'Prevent 'Fix settings' functionality' to 'Disabled'

Information

*Description*

This policy setting prevents users from performing the 'Fix settings' functionality related
to the Security Settings Check in Internet Explorer. The recommended state for this setting
is- Disabled.

*Rationale*

The 'Fix settings' feature is an easy way for users to restore secure settings for Internet
Explorer should the settings be misconfigured in some way, disabling will prevent users
from quickly returning the browser to its default configuration.

Solution

To implement the recommended configuration state, set the following Group Policy setting
to Disabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Prevent 'Fix settings' functionality

Impact-If you enable this policy setting, users cannot click the Fix Settings For Me option in the
Information bar context menu that appears when Internet Explorer determines that its
configuration is not secure.

See Also

https://workbench.cisecurity.org/files/1516

Item Details

Audit Name: CIS IE 9 v1.0.0

Category: ACCESS CONTROL

References: 800-53|AC-6(10)

Plugin: Windows

Control ID: ed93de09ec97c32c43d58cc86c144ca9124d851dd7b0a584508e8d608f00b055