EDGE-00-000047 - Site isolation for every site must be enabled.

Information

The 'SitePerProcess' policy can be used to prevent users from opting out of the default behavior of isolating all sites. The 'IsolateOrigins' policy can be used to isolate additional, finer-grained origins.

Enabling this policy prevents users from opting out of the default behavior where each site runs in its own process.

If this policy is not disabled or configured, a user can opt out of site isolation (e.g., by using 'Disable site isolation' entry in edge://flags.) Disabling the policy or not configuring the policy does not turn off Site Isolation.

Solution

Set the policy value for 'Computer Configuration/Administrative Templates/Microsoft Edge/Enable site isolation for every site' to 'enabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Edge_V2R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCI|CCI-000381, Rule-ID|SV-235760r960963_rule, STIG-ID|EDGE-00-000047, Vuln-ID|V-235760

Plugin: Windows

Control ID: 3d26adc39d7c285f4b92454a0c363b9e67f0e658278b373ba55ab94c897bcab4