UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Automatic configuration of Internet Explorer must be disallowed.


Overview

Finding ID Version Rule ID IA Controls Severity
V-15490 DTBI305 SV-40530r1_rule ECSC-1 Medium
Description
This setting specifies to automatically detect the proxy server settings used to connect to the Internet and customize Internet Explorer. This setting specifies that Internet Explorer use the configuration settings provided in a file by the system administrator. If you enable this policy setting, the user will not be able to do automatic configuration. You can import current connection settings using Internet Explorer Maintenance under Admin Templates using group policy editor. If you disable or do not configure this policy setting, the user will have the freedom to automatically configure these settings.
STIG Date
Microsoft Internet Explorer 9 Security Technical Implementation Guide 2012-09-11

Details

Check Text ( C-39308r2_chk )
The policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer -> "Disable changing Automatic Configuration settings" must be “Enabled”.

Procedure: Use the Windows Registry Editor to navigate to the following key:
HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel

Criteria: If the value Autoconfig is REG_DWORD = 1 (Hex), this is not a finding.
Fix Text (F-34419r1_fix)
Set the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer -> "Disable changing Automatic Configuration settings" to “Enabled”.