1.1.49 Ensure 'Enable network prediction' is set to 'Enabled: Don't predict network actions on any network connection'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This policy setting controls the network prediction feature which controls DNS prefetching, TCP and SSL pre-connection and pre-rendering of web pages.

The recommended state for this setting is Enabled: Don't predict network actions on any network connection.

Rationale:

Opening connections to resources that may not be used could allow un-needed connections increasing attack surface and in some cases could lead to opening connections to resources which the user did not intend to utilize.

Impact:

None - this is the default behavior, with the exception of users being able to change the default.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Don't predict network actions on any network connection

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Enable network prediction

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from Microsoft here.


Default Value:

Enabled - But the user can change the policy.

See Also

https://workbench.cisecurity.org/files/3005