Information
This policy setting configures the ability to view HTTP content such as JavaScript, CSS, objects, and xhr requests.
The recommended state for this setting is: Enabled
Blocking active mixed content minimizes the risk of man-in-the-middle attacks.
Solution
To establish the recommended configuration via GP, set the following UI path to Enabled :
Computer Configuration\Policies\Administrative Templates\Mozilla\Firefox\Preferences (Deprecated)\security.mixed_content.block_active_content
Note: This Group Policy path does not exist by default. An additional Group Policy template ( firefox.admx/adml ) is required - it is available to download at this
link
.
Impact:
None - this is the default behavior.