18.9.48.12 Ensure 'Prevent certificate error overrides' is set to 'Enabled'

Information

This policy controls whether users can choose to override certificate errors.

The recommended state for this setting is: Enabled.

Rationale:

Web security certificates are used to ensure a site your users go to is legitimate, and in some circumstances encrypts the data. Preventing websites from opening if there are errors in their SSL certificate chain will help to block malicious websites.

Impact:

Overriding certificate errors is not allowed. Internal websites at an organization may not load if they use self-signed SSL certificates that are not issued from a trusted PKI source.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:

Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Edge\Prevent certificate error overrides

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MicrosoftEdge.admx/adml that is included with the Microsoft Windows 10 Release 1809 & Server 2019 Administrative Templates (or newer).




Default Value:

Disabled. (Overriding certificate errors is allowed.)

See Also

https://workbench.cisecurity.org/files/3350