1.106 (L1) Ensure 'Enable warnings for insecure forms' is set to 'Enabled'

Information

This policy setting controls the handling of insecure forms (forms submitted over HTTP) embedded in secure (HTTPS) sites in the browser.

When enabled, a full-page warning will be shown, and autofill will be disabled for those forms. When disabled, warnings will not be shown for insecure forms, and autofill will work normally.

The recommended state for this setting is: Enabled

The default setting of enabled warnings for insecure forms enforces secure connections when domains are capable of HTTPS and prevents auto-filling of data imported from a non-secure source.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Enable warnings for insecure forms

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from:

Download Microsoft Edge for Business - Microsoft

.

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/18501

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: f84f13f5f043656049b07514b57496dbf030def490b41dcc9a1b7912e342c60e