1.28 (L1) Ensure 'Allow download restrictions' is set to 'Enabled: Block malicious downloads'

Information

This policy setting controls whether Microsoft Edge blocks certain types of downloads, and prevents users from bypassing security warnings, depending on the classification of Safe Browsing.

The recommended state for this setting is: Enabled: Block malicious downloads

Note: These restrictions only apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, or to the 'Save as PDF' option from the printing options. For more information on Microsoft Defender SmartScreen, please visit

Microsoft Defender SmartScreen Frequently Asked Questions

.

Note #2: Microsoft Edge relies on Internet Explorer zones (Local Machine, Local Intranet, Trusted, Internet, Restricted) to determine which sites may bypass this policy setting. Please see

Security Zones in Edge - text/plain

for more information.

Downloads could contain malware that has the potential to exfiltrate sensitive data or encrypt critical systems for ransom.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Block malicious downloads :

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Allow download restrictions

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from:

Download Microsoft Edge for Business - Microsoft

.

Impact:

Users will be prevented from downloading certain types of files and will not be able to bypass security warnings.

See Also

https://workbench.cisecurity.org/benchmarks/18501

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: 58e38b0036e2cf5c121f5ef576eaf86bdcf5cacc6d268ccd222ca85e4c661a1e