18.9.48.4 Ensure 'Allow Sideloading of extension' is set to 'Disabled'

Information

This policy controls whether unverified extensions can be sideloaded in Microsoft Edge.

The recommended state for this setting is: Disabled.

Note: This policy does not prevent sideloading of Microsoft Edge extensions using Add-AppxPackage via PowerShell, or from an approved source such as:

Microsoft Store

Microsoft Store for Business

Enterprise storefront (such as a company portal)

Rationale:

Unverified Microsoft Edge extensions could be malicious and should be prevented from installation, unless they come from a verified and trusted source.

Impact:

Sideloading of unverified extensions in Microsoft Edge is not allowed.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Edge\Allow Sideloading of extension

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MicrosoftEdge.admx/adml that is included with the Microsoft Windows 10 Release 1809 & Server 2019 Administrative Templates (or newer).

Default Value:

Enabled. (Sideloading of unverified extensions in Microsoft Edge is allowed.)

See Also

https://workbench.cisecurity.org/files/2992