1.63 (L1) Ensure 'Configure browser process code integrity guard setting' is set to 'Enabled: Enable code integrity guard enforcement in the browser process.'

Information

This policy setting controls the use of code integrity guard in the browser process, which only allows Microsoft signed binaries to load.

The recommended state for this setting is: Enabled: Enable code integrity guard enforcement in the browser process.

Code Integrity Guard ensures Microsoft's digital signature is present when loading binaries into a process. Binaries without Microsoft's digital signature are blocked to protect the system from unknown binaries and prevent the injection of untrustworthy binaries into a process.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Enable code integrity guard enforcement in the browser process. :

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Configure browser process code integrity guard setting

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from:

Download Microsoft Edge for Business - Microsoft

.

Impact:

Binaries without Microsoft's digital signature are blocked from being loaded into a process.

See Also

https://workbench.cisecurity.org/benchmarks/18501

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: 982c0acbc0eea2402222368cebab8c85f9a9e34c9ddb4d84247af8615a0fe538