Microsoft Edge Security Technical Implementation Guide

Overview

VersionDateFinding Count (59)Downloads
22025-05-15CAT I (High): 1CAT II (Medium): 48CAT III (Low): 10
STIG Description
This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DOD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.
ClassifiedPublicSensitive
I - Mission Critical ClassifiedI - Mission Critical PublicI - Mission Critical Sensitive
II - Mission Support ClassifiedII - Mission Support PublicII - Mission Support Sensitive
III - Administrative ClassifiedIII - Administrative PublicIII - Administrative Sensitive

Findings - All

Finding IDSeverityTitleDescription
V-235758
LOWMEDIUMHIGH
The version of Microsoft Edge running on the system must be a supported version.Security flaws with software applications are discovered daily. Vendors are constantly updating and patching their products to address newly discovere...
V-235720
LOWMEDIUMHIGH
Bypassing Microsoft Defender SmartScreen prompts for sites must be disabled.This policy setting allows a decision to be made on whether users can override the Microsoft Defender SmartScreen warnings about potentially malicious...
V-235721
LOWMEDIUMHIGH
Bypassing of Microsoft Defender SmartScreen warnings about downloads must be disabled.This policy setting allows a decision to be made on whether users can override Microsoft Defender SmartScreen warnings about unverified downloads. If...
V-235723
LOWMEDIUMHIGH
InPrivate mode must be disabled.This setting specifies whether the user can open pages in InPrivate mode in Microsoft Edge. If this policy is not configured or set it to "Enabled", ...
V-235724
LOWMEDIUMHIGH
Background processing must be disabled.Background processing allows Microsoft Edge processes to start at OS sign-in and keep running after the last browser window is closed. In this scenari...
V-235725
LOWMEDIUMHIGH
The ability of sites to show pop-ups must be disabled.Set whether websites can show pop-up windows. Pop-ups can be allowed on all websites ("AllowPopups") or blocked on all sites ("BlockPopups"). If this...
V-235726
LOWMEDIUMHIGH
The default search provider must be set to use an encrypted connection.Allows a list of list of up to 10 search engines to be configured, one of which must be marked as the default search engine. The encoding does not nee...
V-235728
LOWMEDIUMHIGH
Network prediction must be disabled.Enables network prediction and prevents users from changing this setting. This controls DNS prefetching, TCP and SSL pre-connection, and pre-renderin...
V-235729
LOWMEDIUMHIGH
Search suggestions must be disabled.Enables web search suggestions in the Microsoft Edge Address Bar and Auto-Suggest List, and prevents users from changing this policy. If this policy ...
V-235730
LOWMEDIUMHIGH
Importing of autofill form data must be disabled.Allows users to import autofill form data from another browser into Microsoft Edge. If this policy is enabled, the option to manually import autofill...
V-235732
LOWMEDIUMHIGH
Importing of cookies must be disabled.Allows users to import cookies from another browser into Microsoft Edge. If this policy is disabled, cookies are not imported on first run. If this ...
V-235733
LOWMEDIUMHIGH
Importing of extensions must be disabled.Allows users to import extensions from another browser into Microsoft Edge. If this policy is enabled, the Extensions check box is automatically sele...
V-235734
LOWMEDIUMHIGH
Importing of browsing history must be disabled.Allows users to import their browsing history from another browser into Microsoft Edge. If this policy is enabled, the Browsing history check box is ...
V-235735
LOWMEDIUMHIGH
Importing of home page settings must be disabled.Allows users to import their home page setting from another browser into Microsoft Edge. If this policy is enabled, the option to manually import the...
V-235736
LOWMEDIUMHIGH
Importing of open tabs must be disabled.Allows users to import open and pinned tabs from another browser into Microsoft Edge. If this policy is enabled, the Open tabs check box is automatic...
V-235737
LOWMEDIUMHIGH
Importing of payment info must be disabled.Allows users to import payment info from another browser into Microsoft Edge. If this policy is enabled, the payment info check box is automatically ...
V-235738
LOWMEDIUMHIGH
Importing of saved passwords must be disabled.Allows users to import saved passwords from another browser into Microsoft Edge. If this policy is enabled, the option to manually import saved passw...
V-235739
LOWMEDIUMHIGH
Importing of search engine settings must be disabled.Allows users to import search engine settings from another browser into Microsoft Edge. If this policy is enabled, the option to import search engine...
V-235740
LOWMEDIUMHIGH
Importing of shortcuts must be disabled.Allows users to import Shortcuts from another browser into Microsoft Edge. If this policy is disabled, Shortcuts are not imported on first run. If t...
V-235741
LOWMEDIUMHIGH
AutoplayAllowed must be set to disabled.This policy sets the media autoplay policy for websites. The default setting "Not configured" respects the current media autoplay settings and lets u...
V-235742
LOWMEDIUMHIGH
WebUSB must be disabled.Set whether websites can access connected USB devices. Access can be blocked completely or the user asked each time a website wants to get access to c...
V-235743
LOWMEDIUMHIGH
Google Cast must be disabled.Enable this policy to enable Google Cast. Users will be able to launch it from the app menu, page context menus, media controls on Cast-enabled websit...
V-235744
LOWMEDIUMHIGH
Web Bluetooth API must be disabled.Control whether websites can access nearby Bluetooth devices. Access can be blocked completely or the site required to ask the user each time it wants...
V-235745
LOWMEDIUMHIGH
Autofill for Credit Cards must be disabled.Enables the Microsoft Edge AutoFill feature and lets users auto complete credit card information in web forms using previously stored information. If...
V-235746
LOWMEDIUMHIGH
Autofill for addresses must be disabled.Enables the AutoFill feature and allows users to auto-complete address information in web forms using previously stored information. If this policy i...
V-235747
LOWMEDIUMHIGH
Online revocation checks must be performed.If you enable this policy, Microsoft Edge will perform soft-fail, online OCSP/CRL checks. "Soft fail" means that if the revocation server can't be rea...
V-235748
LOWMEDIUMHIGH
Personalization of ads, search, and news by sending browsing history to Microsoft must be disabled.This policy prevents Microsoft from collecting a user's Microsoft Edge browsing history to be used for personalizing advertising, search, news and oth...
V-235749
LOWMEDIUMHIGH
Site tracking of a user’s location must be disabled.Set whether websites can track users' physical locations. Tracking can be allowed by default ("AllowGeolocation") or denied by default ("BlockGeolocat...
V-235750
LOWMEDIUMHIGH
Browser history must be saved.This setting disables deleting browser history and download history and prevents users from changing this setting....
V-235754
LOWMEDIUMHIGH
Extensions installation must be blocklisted by default.List specific extensions that users cannot install in Microsoft Edge. When this policy is deployed, any extensions on this list that were previously i...
V-235756
LOWMEDIUMHIGH
The Password Manager must be disabled.Enable Microsoft Edge to save user passwords. If this policy is enabled, users can save their passwords in Microsoft Edge. The next time the user vis...
V-235760
LOWMEDIUMHIGH
Site isolation for every site must be enabled.The "SitePerProcess" policy can be used to prevent users from opting out of the default behavior of isolating all sites. The "IsolateOrigins" policy c...
V-235761
LOWMEDIUMHIGH
Supported authentication schemes must be configured.This setting specifies which HTTP authentication schemes are supported. The policy can be configured by using these values: "basic", "digest", "ntlm"...
V-235763
LOWMEDIUMHIGH
Microsoft Defender SmartScreen must be enabled.This policy setting configures Microsoft Defender SmartScreen, which provides warning messages to help protect users from potential phishing scams an...
V-235764
LOWMEDIUMHIGH
Microsoft Defender SmartScreen must be configured to block potentially unwanted apps.This policy setting configures blocking for potentially unwanted apps with Microsoft Defender SmartScreen. Potentially unwanted app blocking with Micr...
V-235766
LOWMEDIUMHIGH
Tracking of browsing activity must be disabled.The setting allows websites to be blocked from tracking users' web-browsing activity. If this policy is disabled or is not configured, users can set ...
V-235767
LOWMEDIUMHIGH
A website's ability to query for payment methods must be disabled.This setting determines whether websites can check if the user has payment methods saved. If this policy is disabled, websites that use "PaymentReque...
V-235768
LOWMEDIUMHIGH
Suggestions of similar web pages in the event of a navigation error must be disabled.This setting allows Microsoft Edge to issue a connection to a web service to generate URL and search suggestions for connectivity issues such as DNS e...
V-235769
LOWMEDIUMHIGH
User feedback must be disabled.Microsoft Edge uses the Edge Feedback feature (enabled by default) to allow users to send feedback, suggestions, or customer surveys and to report any...
V-235770
LOWMEDIUMHIGH
The collections feature must be disabled.This setting allows users to access the Collections feature, where they can collect, organize, share, and export content more efficiently and with Off...
V-235771
LOWMEDIUMHIGH
The Share Experience feature must be disabled.If this policy is set to "ShareAllowed" (the default), users will be able to access the Windows 10 Share experience from the Settings and More menu in...
V-235772
LOWMEDIUMHIGH
Guest mode must be disabled.Enabling Guest mode allows the use of guest profiles in Microsoft Edge. In a guest profile, the browser does not import browsing data from existing pr...
V-235773
LOWMEDIUMHIGH
Relaunch notification must be required.Users must be required to restart the browser to finish installation of pending updates and prevent users from continually using an old/vulnerable bro...
V-235774
LOWMEDIUMHIGH
The built-in DNS client must be disabled.This setting controls whether to use the built-in DNS client. This does not affect which DNS servers are used; it only controls the software stack th...
V-246736
LOWMEDIUMHIGH
Use of the QUIC protocol must be disabled.QUIC is used by more than half of all connections from the Edge web browser to Google's servers, and this activity is undesirable in the DoD. If you ...
V-260465
LOWMEDIUMHIGH
Visual Search must be disabled.Visual Search allows for quick exploration of more related content about entities in an image. If this policy is enabled or not configured, Visual Se...
V-260466
LOWMEDIUMHIGH
Copilot must be disabled.The Sidebar is a launcher bar on the right side of Microsoft Edge's screen. If this policy is enabled or not configured, the Sidebar will be shown. I...
V-260467
LOWMEDIUMHIGH
Session only-based cookies must be enabled.Cookies must only be allowed per session and only for approved URLs as permanently stored cookies can be used for malicious intent. Approved URLs ma...
V-266981
LOWMEDIUMHIGH
FriendlyURLs must be disabled.If FriendlyURLs are enabled, Microsoft Edge will compute additional representations of the URL and place them on the clipboard. This policy configure...
V-235719
LOWMEDIUMHIGH
User control of proxy settings must be disabled.This action configures the proxy settings for Microsoft Edge. If this policy is enabled, Microsoft Edge ignores all proxy-related options specified f...
V-235722
LOWMEDIUMHIGH
The list of domains for which Microsoft Defender SmartScreen will not trigger warnings must be allowlisted if used.Configure the list of Microsoft Defender SmartScreen trusted domains. This means Microsoft Defender SmartScreen will not check for potentially malicio...
V-235727
LOWMEDIUMHIGH
Data Synchronization must be disabled.Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing. If this policy is not set or appli...
V-235731
LOWMEDIUMHIGH
Importing of browser settings must be disabled.Allows users to import browser settings from another browser into Microsoft Edge. If this policy is enabled, the Browser settings check box is automa...
V-235751
LOWMEDIUMHIGH
Edge development tools must be disabled.While the risk associated with browser development tools is more related to the proper design of a web application, a risk vector remains within the b...
V-235752
LOWMEDIUMHIGH
Download restrictions must be configured.This configures the type of downloads that Microsoft Edge completely blocks without allowing users to override the security decision. Set "BlockDange...
V-235753
LOWMEDIUMHIGH
URLs must be allowlisted for plugin use if used.Define a list of sites, based on URL patterns that can open pop-up windows....
V-235755
LOWMEDIUMHIGH
Extensions that are approved for use must be allowlisted if used.By default, all extensions are allowed. However, if all extensions are blocked by setting the "ExtensionInstallBlockList" policy to "*," users can onl...
V-235765
LOWMEDIUMHIGH
The download location prompt must be configured.This setting provides positive feedback before a download starts, limiting the possibility of inadvertent downloads without notifying the user....
V-251694
LOWMEDIUMHIGH
The list of domains media autoplay allows must be allowlisted if used.Define a list of sites, based on URL patterns, that are allowed to autoplay media. If this policy is not configured, the global default value from th...