V-235759 | High | Edge must be configured to allow only TLS. | Sets the minimum supported version of SSL. If this policy is not configured, Microsoft Edge uses a default minimum version, TLS 1.0.
If this policy is enabled, the minimum version can be set to... |
V-235758 | High | The version of Microsoft Edge running on the system must be a supported version. | Security flaws with software applications are discovered daily. Vendors are constantly updating and patching their products to address newly discovered security vulnerabilities. Organizations... |
V-235740 | Medium | Importing of shortcuts must be disabled. | Allows users to import Shortcuts from another browser into Microsoft Edge.
If this policy is disabled, Shortcuts are not imported on first run.
If this policy is not configured, Shortcuts are... |
V-246736 | Medium | Use of the QUIC protocol must be disabled. | QUIC is used by more than half of all connections from the Edge web browser to Google's servers, and this activity is undesirable in the DoD.
If you enable this policy or don't configure it, the... |
V-235733 | Medium | Importing of extensions must be disabled. | Allows users to import extensions from another browser into Microsoft Edge.
If this policy is enabled, the Extensions check box is automatically selected in the Import browser data dialog... |
V-235750 | Medium | Browser history must be saved. | This setting disables deleting browser history and download history and prevents users from changing this setting. |
V-235739 | Medium | Importing of search engine settings must be disabled. | Allows users to import search engine settings from another browser into Microsoft Edge.
If this policy is enabled, the option to import search engine settings is automatically selected.
If this... |
V-235738 | Medium | Importing of saved passwords must be disabled. | Allows users to import saved passwords from another browser into Microsoft Edge.
If this policy is enabled, the option to manually import saved passwords is automatically selected.
If this... |
V-235737 | Medium | Importing of payment info must be disabled. | Allows users to import payment info from another browser into Microsoft Edge.
If this policy is enabled, the payment info check box is automatically selected in the Import browser data dialog... |
V-235736 | Medium | Importing of open tabs must be disabled. | Allows users to import open and pinned tabs from another browser into Microsoft Edge.
If this policy is enabled, the Open tabs check box is automatically selected in the Import browser data... |
V-235735 | Medium | Importing of home page settings must be disabled. | Allows users to import their home page setting from another browser into Microsoft Edge.
If this policy is enabled, the option to manually import the home page setting is automatically... |
V-235755 | Medium | Extensions that are approved for use must be allowlisted. | By default, all extensions are allowed. However, if all extensions are blocked by setting the "ExtensionInstallBlockList" policy to "*," users can only install extensions defined in this policy. |
V-235732 | Medium | Importing of cookies must be disabled. | Allows users to import cookies from another browser into Microsoft Edge.
If this policy is disabled, cookies are not imported on first run.
If this policy is not configured, cookies are imported... |
V-235730 | Medium | Importing of autofill form data must be disabled. | Allows users to import autofill form data from another browser into Microsoft Edge.
If this policy is enabled, the option to manually import autofill data is automatically selected.
If this... |
V-235773 | Medium | Relaunch notification must be required. | Users must be required to restart the browser to finish installation of pending updates and prevent users from continually using an old/vulnerable browser version. |
V-235772 | Medium | Guest mode must be disabled. | Enabling Guest mode allows the use of guest profiles in Microsoft Edge. In a guest profile, the browser does not import browsing data from existing profiles, and it deletes browsing data when all... |
V-235771 | Medium | The Share Experience feature must be disabled. | If this policy is set to "ShareAllowed" (the default), users will be able to access the Windows 10 Share experience from the Settings and More menu in Microsoft Edge to share with other apps on... |
V-235734 | Medium | Importing of browsing history must be disabled. | Allows users to import their browsing history from another browser into Microsoft Edge.
If this policy is enabled, the Browsing history check box is automatically selected in the Import browser... |
V-235774 | Medium | The built-in DNS client must be disabled. | This setting controls whether to use the built-in DNS client.
This does not affect which DNS servers are used; it only controls the software stack that is used to communicate with them. For... |
V-235719 | Medium | User control of proxy settings must be disabled. | This action configures the proxy settings for Microsoft Edge.
If this policy is enabled, Microsoft Edge ignores all proxy-related options specified from the command line.
If this policy is not... |
V-235754 | Medium | Extensions installation must be blocklisted by default. | List specific extensions that users cannot install in Microsoft Edge. When this policy is deployed, any extensions on this list that were previously installed will be disabled, and the user will... |
V-235753 | Medium | URLs must be whitelisted for plugin use. | Define a list of sites, based on URL patterns that can open pop-up windows. |
V-235757 | Medium | The HTTPS warning page must not be able to be bypassed. | Microsoft Edge shows a warning page when users visit sites that have SSL errors.
If this policy is enabled or not configured (default), users can click through these warning pages.
If this... |
V-235756 | Medium | The Password Manager must be disabled. | Enable Microsoft Edge to save user passwords.
If this policy is enabled, users can save their passwords in Microsoft Edge. The next time the user visits the site, Microsoft Edge will enter the... |
V-235746 | Medium | Autofill for addresses must be disabled. | Enables the AutoFill feature and allows users to auto-complete address information in web forms using previously stored information.
If this policy is disabled, AutoFill never suggests or fills... |
V-235745 | Medium | Autofill for Credit Cards must be disabled. | Enables the Microsoft Edge AutoFill feature and lets users auto complete credit card information in web forms using previously stored information.
If this policy is disabled, AutoFill never... |
V-235747 | Medium | Online revocation checks must be performed. | If you enable this policy, Microsoft Edge will perform soft-fail, online OCSP/CRL checks. "Soft fail" means that if the revocation server can't be reached, the certificate will be considered... |
V-235742 | Medium | WebUSB must be disabled. | Set whether websites can access connected USB devices. Access can be blocked completely or the user asked each time a website wants to get access to connected USB devices.
Override this policy... |
V-235770 | Medium | The collections feature must be disabled. | This setting allows users to access the Collections feature, where they can collect, organize, share, and export content more efficiently and with Office integration.
If this policy is enabled or... |
V-235728 | Medium | Network prediction must be disabled. | Enables network prediction and prevents users from changing this setting.
This controls DNS prefetching, TCP and SSL pre-connection, and pre-rendering of web pages.
If this policy is not... |
V-235729 | Medium | Search suggestions must be disabled. | Enables web search suggestions in the Microsoft Edge Address Bar and Auto-Suggest List, and prevents users from changing this policy.
If this policy is enabled, web search suggestions are... |
V-235724 | Medium | Background processing must be disabled. | Background processing allows Microsoft Edge processes to start at OS sign-in and keep running after the last browser window is closed. In this scenario, background apps and the current browsing... |
V-235725 | Medium | The ability of sites to show pop-ups must be disabled. | Set whether websites can show pop-up windows. Pop-ups can be allowed on all websites ("AllowPopups") or blocked on all sites ("BlockPopups").
If this policy is configured, pop-up windows are... |
V-235726 | Medium | The default search provider must be set to use an encrypted connection. | Allows a list of list of up to 10 search engines to be configured, one of which must be marked as the default search engine. The encoding does not need to be specified. Starting in Microsoft Edge... |
V-235720 | Medium | Bypassing Microsoft Defender SmartScreen prompts for sites must be disabled. | This policy setting allows a decision to be made on whether users can override the Microsoft Defender SmartScreen warnings about potentially malicious websites.
If this setting is enabled, users... |
V-235721 | Medium | Bypassing of Microsoft Defender SmartScreen warnings about downloads must be disabled. | This policy setting allows a decision to be made on whether users can override Microsoft Defender SmartScreen warnings about unverified downloads.
If this setting is enabled, users cannot ignore... |
V-235723 | Medium | InPrivate mode must be disabled. | This setting specifies whether the user can open pages in InPrivate mode in Microsoft Edge.
If this policy is not configured or set it to "Enabled", users can open pages in InPrivate mode.
Set... |
V-235760 | Medium | Site isolation for every site must be enabled. | The "SitePerProcess" policy can be used to prevent users from opting out of the default behavior of isolating all sites. The "IsolateOrigins" policy can be used to isolate additional,... |
V-235761 | Medium | Supported authentication schemes must be configured. | This setting specifies which HTTP authentication schemes are supported.
The policy can be configured by using these values: "basic", "digest", "ntlm", and "negotiate". Separate multiple values... |
V-235744 | Medium | Web Bluetooth API must be disabled. | Control whether websites can access nearby Bluetooth devices. Access can be blocked completely or the site required to ask the user each time it wants to access a Bluetooth device.
If this policy... |
V-235763 | Medium | Microsoft Defender SmartScreen must be enabled. | This policy setting configures Microsoft Defender SmartScreen, which provides warning messages to help protect users from potential phishing scams and malicious software. By default, Microsoft... |
V-235764 | Medium | Microsoft Defender SmartScreen must be configured to block potentially unwanted apps. | This policy setting configures blocking for potentially unwanted apps with Microsoft Defender SmartScreen. Potentially unwanted app blocking with Microsoft Defender SmartScreen provides warning... |
V-235743 | Medium | Google Cast must be disabled. | Enable this policy to enable Google Cast. Users will be able to launch it from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar... |
V-235766 | Medium | Tracking of browsing activity must be disabled. | The setting allows websites to be blocked from tracking users' web-browsing activity.
If this policy is disabled or is not configured, users can set their own level of tracking... |
V-235767 | Medium | A website's ability to query for payment methods must be disabled. | This setting determines whether websites can check if the user has payment methods saved.
If this policy is disabled, websites that use "PaymentRequest.canMakePayment" or... |
V-235768 | Medium | Suggestions of similar web pages in the event of a navigation error must be disabled. | This setting allows Microsoft Edge to issue a connection to a web service to generate URL and search suggestions for connectivity issues such as DNS errors.
If this policy is enabled, a web... |
V-235769 | Medium | User feedback must be disabled. | Microsoft Edge uses the Edge Feedback feature (enabled by default) to allow users to send feedback, suggestions, or customer surveys and to report any issues with the browser. By default, users... |
V-235741 | Medium | Autoplay must be disabled. | This policy sets the media autoplay policy for websites.
The default setting, "Not configured" respects the current media autoplay settings and lets users configure their autoplay... |
V-235748 | Medium | Personalization of ads, search, and news by sending browsing history to Microsoft must be disabled. | This policy prevents Microsoft from collecting a user's Microsoft Edge browsing history to be used for personalizing advertising, search, news and other Microsoft services.
This setting is only... |
V-235749 | Medium | Site tracking of a user’s location must be disabled. | Set whether websites can track users' physical locations. Tracking can be allowed by default ("AllowGeolocation") or denied by default ("BlockGeolocation"), or the user can be asked each time a... |
V-235752 | Low | Download restrictions must be configured. | Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.
Set "BlockDangerousDownloads" to allow all downloads except for those... |
V-235731 | Low | Importing of browser settings must be disabled. | Allows users to import browser settings from another browser into Microsoft Edge.
If this policy is enabled, the Browser settings check box is automatically selected in the Import browser data... |
V-235765 | Low | The download location prompt must be configured. | This setting provides positive feedback before a download starts, limiting the possibility of inadvertent downloads without notifying the user. |
V-235727 | Low | Data Synchronization must be disabled. | Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing.
If this policy is not set or applied as recommended, users will be able to turn... |
V-235722 | Low | The list of domains for which Microsoft Defender SmartScreen will not trigger warnings must be whitelisted if used. | Configure the list of Microsoft Defender SmartScreen trusted domains. This means Microsoft Defender SmartScreen will not check for potentially malicious resources, such as phishing software and... |
V-235751 | Low | Edge development tools must be disabled. | While the risk associated with browser development tools is more related to the proper design of a web application, a risk vector remains within the browser. The developer tools allow end users... |