CIS Microsoft Edge Benchmark

Secure configuration guidelines for Microsoft Edge enterprise browser

v3.0.0 January 2025

Overview

▶

This CIS Benchmark provides prescriptive guidance for establishing a secure configuration posture for Microsoft Edge. Recommendations cover extension management, privacy and search settings, SmartScreen and security features, content filtering, authentication, and update policies for enterprise-managed deployments.

~120Recommendations
6Sections
2Profile Levels
SectionAreaFocus
1ExtensionsInstall policies, sources
2PrivacyCookies, search, permissions
3SecuritySmartScreen, passwords
4ContentDownloads, pop-ups
5NetworkDNS, auth, proxy
6UpdatesAuto-update, telemetry

Profile Definitions

▶
ProfileDescriptionIntended Use
L1Level 1 — StandardEssential security for all Microsoft Edge deployments; minimal performance impact.
L2Level 2 — HardenedAdvanced hardening for PCI-DSS, HIPAA, or high-security environments.

1 — Extension Management

▶

1.1 Extension Policies

▶
1.1.1 Ensure Extension Install Blocklist Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Extension Install Blocklist Is Configured on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Extension Install Blocklist Is Configured. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Extension Install Blocklist Is Configured. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

1.1.2 Ensure Extension Install Allowlist Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Extension Install Allowlist Is Configured on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Extension Install Allowlist Is Configured. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Extension Install Allowlist Is Configured. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

1.1.3 Ensure Extensions Are Installed by Policy Only (Automated)
L2 Auto
Description

This recommendation verifies that Extensions Are Installed by Policy Only on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Extensions Are Installed by Policy Only. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Extensions Are Installed by Policy Only. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

1.1.4 Ensure Unpacked Extensions Are Disabled (Automated)
L1 Auto
Description

This recommendation verifies that Unpacked Extensions Are Disabled on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Unpacked Extensions Are Disabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Unpacked Extensions Are Disabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

1.2 Extension Sources

▶
1.2.1 Ensure External Extension Installation Is Blocked (Automated)
L1 Auto
Description

This setting ensures that External Extension Installation Is Blocked on the Microsoft Edge browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Edge browser is essential for defense in depth.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that External Extension Installation Is Blocked. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure External Extension Installation Is Blocked. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

1.2.2 Ensure Sideloading of Extensions Is Disabled (Automated)
L1 Auto
Description

This recommendation verifies that Sideloading of Extensions Is Disabled on the Microsoft Edge browser. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.

Rationale

Running unnecessary components on the Microsoft Edge browser increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Sideloading of Extensions Is Disabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Sideloading of Extensions Is Disabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

1.2.3 Ensure Extension Permissions Are Restricted (Manual)
L2 Manual
Description

This setting ensures that Extension Permissions Are Restricted on the Microsoft Edge browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Edge browser is essential for defense in depth.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Extension Permissions Are Restricted. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Extension Permissions Are Restricted. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

2 — Privacy & Search

▶

2.1 Privacy Settings

▶
2.1.1 Ensure Do Not Track Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Do Not Track Is Enabled on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Do Not Track Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Do Not Track Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

2.1.2 Ensure Third-Party Cookies Are Blocked (Automated)
L2 Auto
Description

This setting ensures that Third-Party Cookies Are Blocked on the Microsoft Edge browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Edge browser is essential for defense in depth.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Third-Party Cookies Are Blocked. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Third-Party Cookies Are Blocked. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

2.1.3 Ensure Site Permissions Are Restricted (Automated)
L1 Auto
Description

This setting ensures that Site Permissions Are Restricted on the Microsoft Edge browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Edge browser is essential for defense in depth.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Site Permissions Are Restricted. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Site Permissions Are Restricted. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

2.1.4 Ensure Autofill for Payment Instruments Is Disabled (Automated)
L2 Auto
Description

This recommendation verifies that Autofill for Payment Instruments Is Disabled on the Microsoft Edge browser. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.

Rationale

Running unnecessary components on the Microsoft Edge browser increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Autofill for Payment Instruments Is Disabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Autofill for Payment Instruments Is Disabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

2.2 Search Configuration

▶
2.2.1 Ensure Default Search Provider Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Default Search Provider Is Configured on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Default Search Provider Is Configured. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Default Search Provider Is Configured. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

2.2.2 Ensure Search Suggestions Are Disabled (Automated)
L2 Auto
Description

This recommendation verifies that Search Suggestions Are Disabled on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Search Suggestions Are Disabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Search Suggestions Are Disabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

2.2.3 Ensure Address Bar Search Is Controlled (Automated)
L1 Auto
Description

This setting ensures that Address Bar Search Is Controlled on the Microsoft Edge browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Edge browser is essential for defense in depth.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Address Bar Search Is Controlled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Address Bar Search Is Controlled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

3 — Security Features

▶

3.1 SmartScreen & Protection

▶
3.1.1 Ensure SmartScreen Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that SmartScreen Is Enabled on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that SmartScreen Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure SmartScreen Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

3.1.2 Ensure Potentially Unwanted App Blocking Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Potentially Unwanted App Blocking Is Enabled on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Potentially Unwanted App Blocking Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Potentially Unwanted App Blocking Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

3.1.3 Ensure Enhanced Security Mode Is Configured (Automated)
L2 Auto
Description

This recommendation verifies that Enhanced Security Mode Is Configured on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Enhanced Security Mode Is Configured. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Enhanced Security Mode Is Configured. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

3.1.4 Ensure Typosquatting Checker Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Typosquatting Checker Is Enabled on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Typosquatting Checker Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Typosquatting Checker Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

3.2 Password Management

▶
3.2.1 Ensure Password Manager Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Password Manager Is Configured on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Password Manager Is Configured. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Password Manager Is Configured. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

3.2.2 Ensure Password Leak Detection Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Password Leak Detection Is Enabled on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Password Leak Detection Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Password Leak Detection Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

3.2.3 Ensure Password Generator Is Enabled (Automated)
L2 Auto
Description

This recommendation verifies that Password Generator Is Enabled on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Password Generator Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Password Generator Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

4 — Content & Downloads

▶

4.1 Content Settings

▶
4.1.1 Ensure JavaScript JIT Is Disabled for Untrusted Sites (Automated)
L2 Auto
Description

This recommendation verifies that JavaScript JIT Is Disabled for Untrusted Sites on the Microsoft Edge browser. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.

Rationale

Running unnecessary components on the Microsoft Edge browser increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that JavaScript JIT Is Disabled for Untrusted Sites. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure JavaScript JIT Is Disabled for Untrusted Sites. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

4.1.2 Ensure Pop-ups Are Blocked by Default (Automated)
L1 Auto
Description

This setting ensures that Pop-ups Are Blocked by Default on the Microsoft Edge browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Edge browser is essential for defense in depth.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Pop-ups Are Blocked by Default. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Pop-ups Are Blocked by Default. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

4.1.3 Ensure Notifications Are Controlled (Automated)
L1 Auto
Description

This setting ensures that Notifications Are Controlled on the Microsoft Edge browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Edge browser is essential for defense in depth.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Notifications Are Controlled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Notifications Are Controlled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

4.2 Download Security

▶
4.2.1 Ensure Download Restrictions Are Configured (Automated)
L1 Auto
Description

This recommendation verifies that Download Restrictions Are Configured on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Download Restrictions Are Configured. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Download Restrictions Are Configured. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

4.2.2 Ensure Safe Browsing for Downloads Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Safe Browsing for Downloads Is Enabled on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Safe Browsing for Downloads Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Safe Browsing for Downloads Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

4.2.3 Ensure Automatic Downloads Are Blocked (Automated)
L2 Auto
Description

This setting ensures that Automatic Downloads Are Blocked on the Microsoft Edge browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Edge browser is essential for defense in depth.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Automatic Downloads Are Blocked. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Automatic Downloads Are Blocked. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

5 — Network & Authentication

▶

5.1 Network Security

▶
5.1.1 Ensure DNS-over-HTTPS Is Configured (Automated)
L2 Auto
Description

This recommendation verifies that DNS-over-HTTPS Is Configured on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that DNS-over-HTTPS Is Configured. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure DNS-over-HTTPS Is Configured. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

5.1.2 Ensure QUIC Protocol Is Controlled (Automated)
L1 Auto
Description

This setting ensures that QUIC Protocol Is Controlled on the Microsoft Edge browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Edge browser is essential for defense in depth.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that QUIC Protocol Is Controlled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure QUIC Protocol Is Controlled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

5.1.3 Ensure Proxy Settings Are Managed (Automated)
L1 Auto
Description

This recommendation verifies that Proxy Settings Are Managed on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Proxy Settings Are Managed. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Proxy Settings Are Managed. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

5.2 Authentication

▶
5.2.1 Ensure Browser Sign-In Policy Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Browser Sign-In Policy Is Configured on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Browser Sign-In Policy Is Configured. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Browser Sign-In Policy Is Configured. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

5.2.2 Ensure HTTP Authentication Schemes Are Restricted (Automated)
L2 Auto
Description

This setting ensures that HTTP Authentication Schemes Are Restricted on the Microsoft Edge browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Edge browser is essential for defense in depth.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that HTTP Authentication Schemes Are Restricted. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure HTTP Authentication Schemes Are Restricted. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

5.2.3 Ensure Integrated Windows Authentication Is Configured (Manual)
L1 Manual
Description

This recommendation verifies that Integrated Windows Authentication Is Configured on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Integrated Windows Authentication Is Configured. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Integrated Windows Authentication Is Configured. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

6 — Updates & Telemetry

▶

6.1 Update Policies

▶
6.1.1 Ensure Auto-Update Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Auto-Update Is Enabled on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Auto-Update Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Auto-Update Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

6.1.2 Ensure Update Channel Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Update Channel Is Configured on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Update Channel Is Configured. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Update Channel Is Configured. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

6.1.3 Ensure Update Notifications Are Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Update Notifications Are Enabled on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Update Notifications Are Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Update Notifications Are Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

6.2 Telemetry & Diagnostics

▶
6.2.1 Ensure Diagnostic Data Collection Is Minimized (Automated)
L2 Auto
Description

This recommendation verifies that Diagnostic Data Collection Is Minimized on the Microsoft Edge browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Microsoft Edge browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Diagnostic Data Collection Is Minimized. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Diagnostic Data Collection Is Minimized. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

6.2.2 Ensure Crash Reporting Is Controlled (Automated)
L1 Auto
Description

This setting ensures that Crash Reporting Is Controlled on the Microsoft Edge browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Microsoft Edge browser is essential for defense in depth.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Crash Reporting Is Controlled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Crash Reporting Is Controlled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

6.2.3 Ensure Usage Statistics Reporting Is Disabled (Automated)
L2 Auto
Description

This recommendation verifies that Usage Statistics Reporting Is Disabled on the Microsoft Edge browser. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.

Rationale

Running unnecessary components on the Microsoft Edge browser increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.

Audit

Verify via Microsoft Edge enterprise browser policy or Group Policy that Usage Statistics Reporting Is Disabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Microsoft Edge enterprise browser policy to ensure Usage Statistics Reporting Is Disabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).