1.1.18.4 (L1) Ensure 'dom.allow_scripts_to_close_windows' is set to 'Disabled'

Information

This policy setting allows the configuration of how Firefox handles scripts from closing browser windows.

The recommended state for this setting is: Disabled

Preventing an arbitrary web site from closing the browser window will reduce the probability of a user losing work or state being performed in another tab within the same window.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Mozilla\Firefox\Preferences (Deprecated)\dom.allow_scripts_to_close_windows

Note: This Group Policy path does not exist by default. An additional Group Policy template ( firefox.admx/adml ) is required - it is available to download at this

link

.

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/18454

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|CM-7, 800-53|CM-7(1), 800-53|SI-7, 800-53|SI-7(1), CSCv7|7.3

Plugin: Windows

Control ID: e28d8ca0929dd5c6b302cce61a72becbdaf1ae96c69968b0e691e0cf8b020d0a