CIS Mozilla Firefox Benchmark
Secure configuration guidelines for Mozilla Firefox enterprise browser
v2.0.0 October 2024Overview
▶This CIS Benchmark provides prescriptive guidance for establishing a secure configuration posture for Mozilla Firefox. Recommendations cover extension management, privacy and tracking protection, network security, content restrictions, certificate management, and enterprise policy configuration.
| Section | Area | Focus |
|---|---|---|
| 1 | Extensions | Add-on policies, plugins |
| 2 | Privacy | Tracking, telemetry |
| 3 | Network | HTTPS, DNS, protocols |
| 4 | Content | Permissions, downloads |
| 5 | Certificates | Trust, authentication |
| 6 | Updates | Auto-update, policies |
Profile Definitions
▶| Profile | Description | Intended Use |
|---|---|---|
| L1 | Level 1 — Standard | Essential security for all Mozilla Firefox deployments; minimal performance impact. |
| L2 | Level 2 — Hardened | Advanced hardening for PCI-DSS, HIPAA, or high-security environments. |
1 — Extension & Plugin Management
▶1.1 Extension Policies
▶This setting ensures that Extension Installation Is Restricted on the Mozilla Firefox browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Mozilla Firefox browser is essential for defense in depth.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Extension Installation Is Restricted. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Extension Installation Is Restricted. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This recommendation ensures that Add-on Signing Requirement Is Enforced on the Mozilla Firefox browser. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Mozilla Firefox browser may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Add-on Signing Requirement Is Enforced. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Add-on Signing Requirement Is Enforced. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This recommendation verifies that Legacy Extensions Are Disabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Legacy Extensions Are Disabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Legacy Extensions Are Disabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
1.2 Plugin Settings
▶This recommendation verifies that Flash Plugin Is Disabled on the Mozilla Firefox browser. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.
Running unnecessary components on the Mozilla Firefox browser increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Flash Plugin Is Disabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Flash Plugin Is Disabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This recommendation verifies that Plugin Click-to-Play Is Enabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Plugin Click-to-Play Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Plugin Click-to-Play Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This setting ensures that DRM Content Is Controlled on the Mozilla Firefox browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Mozilla Firefox browser is essential for defense in depth.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that DRM Content Is Controlled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure DRM Content Is Controlled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
2 — Privacy & Tracking Protection
▶2.1 Tracking Protection
▶This recommendation verifies that Enhanced Tracking Protection Is Set to Strict on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Enhanced Tracking Protection Is Set to Strict. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Enhanced Tracking Protection Is Set to Strict. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This recommendation verifies that Do Not Track Is Enabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Do Not Track Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Do Not Track Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This setting ensures that Third-Party Cookies Are Blocked on the Mozilla Firefox browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Mozilla Firefox browser is essential for defense in depth.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Third-Party Cookies Are Blocked. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Third-Party Cookies Are Blocked. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This recommendation verifies that Fingerprinting Protection Is Enabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Fingerprinting Protection Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Fingerprinting Protection Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
2.2 Data Collection
▶This recommendation verifies that Telemetry Is Disabled on the Mozilla Firefox browser. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.
Running unnecessary components on the Mozilla Firefox browser increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Telemetry Is Disabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Telemetry Is Disabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This recommendation verifies that Crash Reporter Is Disabled on the Mozilla Firefox browser. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.
Running unnecessary components on the Mozilla Firefox browser increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Crash Reporter Is Disabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Crash Reporter Is Disabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This recommendation verifies that Health Report Is Disabled on the Mozilla Firefox browser. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.
Running unnecessary components on the Mozilla Firefox browser increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Health Report Is Disabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Health Report Is Disabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
3 — Network Security
▶3.1 Connection Security
▶This recommendation verifies that DNS-over-HTTPS Is Configured on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that DNS-over-HTTPS Is Configured. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure DNS-over-HTTPS Is Configured. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This recommendation verifies that HTTPS-Only Mode Is Enabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that HTTPS-Only Mode Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure HTTPS-Only Mode Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This recommendation verifies that Proxy Settings Are Managed on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Proxy Settings Are Managed. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Proxy Settings Are Managed. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This recommendation verifies that WebRTC IP Leak Is Prevented on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that WebRTC IP Leak Is Prevented. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure WebRTC IP Leak Is Prevented. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
3.2 Protocol Configuration
▶This recommendation verifies that TLS 1.2 Is the Minimum Version on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that TLS 1.2 Is the Minimum Version. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure TLS 1.2 Is the Minimum Version. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This recommendation verifies that Weak Cipher Suites Are Disabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Weak Cipher Suites Are Disabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Weak Cipher Suites Are Disabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This recommendation verifies that OCSP Stapling Is Enabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that OCSP Stapling Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure OCSP Stapling Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
4 — Content & Permissions
▶4.1 Content Settings
▶This recommendation verifies that Pop-up Blocking Is Enabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Pop-up Blocking Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Pop-up Blocking Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This setting ensures that JavaScript Is Controlled for Untrusted Sites on the Mozilla Firefox browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Mozilla Firefox browser is essential for defense in depth.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that JavaScript Is Controlled for Untrusted Sites. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure JavaScript Is Controlled for Untrusted Sites. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This recommendation ensures that Notifications Require Approval on the Mozilla Firefox browser. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Mozilla Firefox browser may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Notifications Require Approval. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Notifications Require Approval. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
4.2 Download Security
▶This recommendation verifies that Safe Browsing Is Enabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Safe Browsing Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Safe Browsing Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This setting ensures that Download Actions Are Restricted on the Mozilla Firefox browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Mozilla Firefox browser is essential for defense in depth.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Download Actions Are Restricted. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Download Actions Are Restricted. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This setting ensures that Automatic File Download Is Blocked on the Mozilla Firefox browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Mozilla Firefox browser is essential for defense in depth.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Automatic File Download Is Blocked. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Automatic File Download Is Blocked. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
5 — Certificates & Authentication
▶5.1 Certificate Management
▶This recommendation verifies that Enterprise Root Certificates Are Trusted on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Enterprise Root Certificates Are Trusted. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Enterprise Root Certificates Are Trusted. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This recommendation ensures that Certificate Transparency Is Enforced on the Mozilla Firefox browser. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Mozilla Firefox browser may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Certificate Transparency Is Enforced. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Certificate Transparency Is Enforced. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This recommendation verifies that Revocation Checking Is Enabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Revocation Checking Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Revocation Checking Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
5.2 Authentication
▶This recommendation ensures that Master Password Is Enforced on the Mozilla Firefox browser. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.
Without this enforcement, the Mozilla Firefox browser may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Master Password Is Enforced. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Master Password Is Enforced. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This setting ensures that Autofill for Credentials Is Controlled on the Mozilla Firefox browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Mozilla Firefox browser is essential for defense in depth.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Autofill for Credentials Is Controlled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Autofill for Credentials Is Controlled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This setting ensures that NTLM Authentication Is Restricted on the Mozilla Firefox browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Mozilla Firefox browser is essential for defense in depth.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that NTLM Authentication Is Restricted. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure NTLM Authentication Is Restricted. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
6 — Updates & Enterprise Policies
▶6.1 Update Configuration
▶This recommendation verifies that Auto-Update Is Enabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Auto-Update Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Auto-Update Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This recommendation verifies that Update Channel Is Configured on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Update Channel Is Configured. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Update Channel Is Configured. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
6.2 Enterprise Policies
▶This recommendation verifies that Enterprise Policies Are Applied via policies.json on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to implement this control may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Enterprise Policies Are Applied via policies.json. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Enterprise Policies Are Applied via policies.json. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This recommendation verifies that Default Browser Check Is Configured on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.
Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Default Browser Check Is Configured. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Default Browser Check Is Configured. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This recommendation verifies that Sync Is Disabled or Managed on the Mozilla Firefox browser. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.
Running unnecessary components on the Mozilla Firefox browser increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that Sync Is Disabled or Managed. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure Sync Is Disabled or Managed. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).
This setting ensures that about:config Access Is Restricted on the Mozilla Firefox browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.
Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Mozilla Firefox browser is essential for defense in depth.
Verify via Mozilla Firefox enterprise browser policy or Group Policy that about:config Access Is Restricted. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.
Configure Mozilla Firefox enterprise browser policy to ensure about:config Access Is Restricted. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).