18.9.48.2 Ensure 'Allow Adobe Flash' is set to 'Disabled'

Information

This setting lets you decide whether employees can run Adobe Flash in Microsoft Edge.

The recommended state for this setting is: Disabled.

Rationale:

Adobe Flash is a very insecure product and has been a frequent attack vector on the web. In more highly security-sensitive environments, Adobe Flash should be disabled completely to eliminate this attack vector.

Note: This setting will not prevent or remove Adobe Flash usage from other web browsers, so we recommend also uninstalling Adobe Flash completely from all systems in highly security-sensitive environments.

Impact:

Users will not be able to use Adobe Flash in Microsoft Edge.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Edge\Allow Adobe Flash

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MicrosoftEdge.admx/adml that is included with the Microsoft Windows 10 Release 1703 Administrative Templates (or newer).


Default Value:

Enabled. (Users will be able to use Adobe Flash in Microsoft Edge.)

See Also

https://workbench.cisecurity.org/files/3350