1.25 Ensure 'Allow features to download assets from the Asset Delivery Service' is set to 'Disabled'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This policy setting configures the Microsoft Edge Asset Delivery Service. The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients. These assets can be configuration files or Machine Learning models that power the features that use this service.

The recommended state for this setting is Disabled.

Rationale:

To reduce the attack surface of the system, downloads such as those described in this recommendation should not be allowed to download automatically without the approval of an Administrator.

Impact:

Microsoft Edge features will not be able to download assets needed for them to run correctly.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Allow features to download assets from the Asset Delivery Service

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from Microsoft here.

Default Value:

Not configured.

See Also

https://workbench.cisecurity.org/files/4094