1.1.1.1 (L1) Ensure 'Allow add-on installs from websites' is set to 'Disabled'

Information

This policy setting configures the ability for websites to automatically install add-ons without an allow list.

The recommended state for this setting is: Disabled

Note: If this setting is enabled, an allow list will be needed for approved add-ons.

Add-ons are extensions of the browser that add new functionality to Firefox or change its appearance. These run in a user session allowing them to manipulate data and the behavior of the way Firefox interacts with other applications and user commands. If malicious add-ons are installed automatically, a user's security could be completely compromised.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Mozilla\Firefox\Addons\Allow add-on installs from websites

Note: This Group Policy path does not exist by default. An additional Group Policy template ( firefox.admx/adml ) is required - it is available to download at this

link

.

Impact:

Users will not be able to download and install add-ons from websites unless an allow list is created.

See Also

https://workbench.cisecurity.org/benchmarks/18454

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-10, 800-53|CM-11, 800-53|SC-18, CSCv7|7.2

Plugin: Windows

Control ID: c5475e37c9f8b107a466d7cb08ec694fb3cc2d00ddfb94230ceb76446dea461e