1.99 Ensure 'Enhance the security state in Microsoft Edge' is set to 'Enabled: Balanced mode'

Information

This policy setting configures 'enhance the security state' in Microsoft Edge. Enhanced security in Microsoft Edge helps safeguard against memory-related vulnerabilities by disabling just-in-time (JIT) JavaScript compilation and enabling additional operating system protections for the browser. These protections include Hardware-enforced Stack Protection and Arbitrary Code Guard (ACG).

Enhanced security provides two levels of browsing security: Balanced and Strict. Balanced mode is an adaptive mode that builds on a user's behavior on a particular device. Strict mode applies added security protections for all the sites a user visits. Users may report some challenges accomplishing their usual tasks when in strict mode.

The recommended state for this setting is: Enabled: Balanced mode.

Rationale:

Balance mode will help reduce the risk of an attack by automatically applying stricter security settings on unfamiliar sites while adapting to browsing habits over time.

Impact:

Users will no longer be able to bypass protection for previously visited unfamiliar sites.

Edge will apply added security protections to sites that are not visited often or are unknown. Websites that are browsed frequently will be left out.

Note: Most sites will work as expected.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Balanced mode:

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Enhance the security state in Microsoft Edge

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from: Download Microsoft Edge for Business - Microsoft.

Default Value:

Disabled.

See Also

https://workbench.cisecurity.org/benchmarks/11865

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: 7c62f5f2986b75d63287f7c6e1be0e65545522d85d2137b0ebb41fd2d2e7396e