1.56 (L2) Ensure 'Block third party cookies' is set to 'Enabled'

Information

This policy controls whether web page elements from a domain other than that in the address bar can set cookies.

The recommended state for this setting is: Enabled

Allowing third-party cookies could potentially allow tracking of your web activities by third-party entities which may expose information that could be used for an attack on the end-user.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Block third party cookies

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from:

Download Microsoft Edge for Business - Microsoft

.

Impact:

Disabling third-party cookies could cause some websites to not function as expected (e.g., Microsoft 365 or Salesforce).

See Also

https://workbench.cisecurity.org/benchmarks/18501

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: afae7ad598cc529abf20bd76b4c85c41b3fed369cfe3fbe9203e18eb55e5074e