1.95 (L1) Ensure 'Enable network prediction' is set to 'Enabled: Don't predict network actions on any network connection'

Information

This policy setting controls the network prediction feature which controls DNS prefetching, TCP and SSL pre-connection and pre-rendering of web pages.

The recommended state for this setting is: Enabled: Don't predict network actions on any network connection

Opening connections to resources that may not be used could allow un-needed connections increasing attack surface and, in some cases, could lead to opening connections to resources which the user did not intend to utilize.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Don't predict network actions on any network connection :

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Enable network prediction

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from:

Download Microsoft Edge for Business - Microsoft

.

Impact:

None - this is the default behavior, apart from users being able to change the default.

See Also

https://workbench.cisecurity.org/benchmarks/18501

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 2f9edd2f91cc08d17fc4fff398e74abac5bcc3044a9d21cb72a94ce01bcda05e