DTBI725 - AutoComplete feature for user names and passwords on forms must be disallowed.

Information

It is possible this feature will cache sensitive data and store it in the user's profile where it might not be protected as rigorously as required by organizational policy. This policy setting controls automatic completion of fields in forms on web pages. If you enable this setting, the user cannot change 'User name and passwords on forms' or 'prompt me to save passwords'. The Auto Complete feature for user names and passwords on forms will be turned on. If you disable this setting, the user cannot change 'User name and passwords on forms' or 'prompt me to save passwords'. The Auto Complete feature for user names and passwords on forms is turned off. The user also cannot opt to be prompted to save passwords. If you do not configure this setting, the user has the freedom of turning on Auto Complete for user name and passwords on forms, and the option of prompting to save passwords.

Solution

Set the policy value for User Configuration -> Administrative Templates -> Windows Components -> Internet Explorer -> 'Turn on the auto-complete feature for user names and passwords on forms' to 'Disabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Microsoft_IE9_V1R15_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCE|CCE-721, Rule-ID|SV-40694r1_rule, STIG-ID|DTBI725, Vuln-ID|V-15581

Plugin: Windows

Control ID: 251378a1482010dfbaa395e69c606b1085f428813798e14786fb49001f442e86