1.1.6.2 (L1) Ensure 'Cookie Behavior in private browsing' is set to 'Enabled: Reject cookies for known trackers and partition third-party cookies'

Information

This policy setting configures the ability for third-party cookies to be downloaded to the system. Third party cookies are cookies sent by a domain that differs from the domain in the browser's address bar.

The recommended state for this setting is: Enabled: Reject cookies for known trackers and partition third-party cookies

Third party cookies are often used for tracking user browsing behaviors, which has privacy implications.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Reject cookies for known trackers and partition third-party cookies :

Computer Configuration\Policies\Administrative Templates\Mozilla\Firefox\Cookies\Cookie Behavior in private browsing

Note: This Group Policy path does not exist by default. An additional Group Policy template ( firefox.admx/adml ) is required - it is available to download at this

link

.

Impact:

Blocking third-party cookies may adversely affect the functionality of some sites.

See Also

https://workbench.cisecurity.org/benchmarks/18454

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(10)

Plugin: Windows

Control ID: b9e5cfc4f51d3328c509cf89d87e1238e39b22095394c9b42f2dda30e3e84b85