1.3.8 (L1) Ensure 'Default automatic downloads setting' is set to 'Enabled: Don't allow any website to perform automatic downloads'

Information

This policy setting controls whether websites can perform multiple downloads successively without user interaction.

The recommended state for this setting is: Enabled: Don't allow any website to perform automatic downloads

Unintentional malicious content could be downloaded without user interaction if websites are allowed to perform automatic downloads.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Don't allow any website to perform automatic downloads :

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Content settings\Default automatic downloads setting

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from:

Download Microsoft Edge for Business - Microsoft

.

Impact:

Websites will not be able to perform automatic downloads.

See Also

https://workbench.cisecurity.org/benchmarks/18501

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-2c.

Plugin: Windows

Control ID: 5cc535b46b01d9ea714b69b6352e909fdb4c83a761f50cbf84369a45f7766338