18.9.48.5 Ensure 'Configure cookies' is set to 'Enabled: Block only 3rd-party cookies' or higher

Information

This setting lets you configure how your company deals with cookies.

The recommended state for this setting is: Enabled: Block only 3rd-party cookies. Configuring this setting to Enabled: Block all cookies also conforms to the benchmark.

Rationale:

Cookies can pose a serious privacy concern, although many websites depend on them for operation. It is recommended when possible to block 3rd party cookies in order to reduce tracking.

Impact:

If you select 'Block only 3rd-party cookies', cookies from 3rd-party websites will be blocked, but 1st-party website cookies will still be permitted. If you select 'Block all cookies', cookies from all websites will be blocked.

Note: Blocking all cookies may interfere with functionality on some websites that depend on them for session tracking and/or login credentials.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Block only 3rd-party cookies (or, if applicable for your environment, Enabled: Block all cookies):

Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Edge\Configure cookies

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MicrosoftEdge.admx/adml that is included with the Microsoft Windows 10 Release 1507 Administrative Templates (or newer).
Note #2: In the Microsoft Windows 10 Release 1507 Administrative Templates, this setting was named Configure how Microsoft Edge treats cookies, but it was renamed starting with the Windows 10 Release 1511 Administrative Templates.

Default Value:

Allow all cookies. (Allows all cookies from all websites.)

See Also

https://workbench.cisecurity.org/files/2992