1.29 (L2) Ensure 'Allow features to download assets from the Asset Delivery Service' is set to 'Disabled'

Information

This policy setting configures the Microsoft Edge Asset Delivery Service. The Edge Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients. These assets can be configuration files or Machine Learning models that power the features that use this service.

The recommended state for this setting is: Disabled

To reduce the attack surface of the system, downloads such as those described in this recommendation should not be allowed to automatically download without the approval of an Administrator.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Allow features to download assets from the Asset Delivery Service

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from:

Download Microsoft Edge for Business - Microsoft

.

Impact:

Microsoft Edge features will not be able to download assets needed for them to run correctly.

See Also

https://workbench.cisecurity.org/benchmarks/18501

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(5), 800-53|CM-10, CSCv7|2.7

Plugin: Windows

Control ID: 9bcc5a6b2c8bc9c7f4e16e14f911de9efb1948b58b7d0c75be386848251e6407