1.53 (L2) Ensure 'AutoLaunch Protocols Component Enabled' is set to 'Disabled'

Information

This policy setting controls the AutoLaunch Protocols Component. This Component allows Microsoft to provide a list similar to the

AutoLaunchProtocolsFromOrigins (Define a list of Protocols that can launch an external application from listed origins without prompting the user)

policy, which allows certain external Protocols to launch without prompt or blocking certain Protocols (on specified origins).

The recommended state for this setting is: Disabled

Allowing applications to AutoLaunch without prompting users for websites in Microsoft Edge, could open an organization up to malicious sites that may capture proprietary information through the browser app.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Administrative Templates\Microsoft Edge\AutoLaunch Protocols Component Enabled

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from:

Download Microsoft Edge for Business - Microsoft

.

Impact:

Disabling this setting will prompt users whether to allow or deny Microsoft Edge to open certain links in their associated application, no protocols can launch without prompt.

See Also

https://workbench.cisecurity.org/benchmarks/18501

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-10, 800-53|CM-11, 800-53|SC-18, CSCv7|7.2

Plugin: Windows

Control ID: d57231eab0615869e23cba6daeea9e5e3d3ff7f2d4572963d8591d9d431bfab2