CIS Mozilla Firefox Benchmark

Secure configuration guidelines for Mozilla Firefox enterprise browser

v2.0.0 October 2024

Overview

▶

This CIS Benchmark provides prescriptive guidance for establishing a secure configuration posture for Mozilla Firefox. Recommendations cover extension management, privacy and tracking protection, network security, content restrictions, certificate management, and enterprise policy configuration.

~100Recommendations
6Sections
2Profile Levels
SectionAreaFocus
1ExtensionsAdd-on policies, plugins
2PrivacyTracking, telemetry
3NetworkHTTPS, DNS, protocols
4ContentPermissions, downloads
5CertificatesTrust, authentication
6UpdatesAuto-update, policies

Profile Definitions

▶
ProfileDescriptionIntended Use
L1Level 1 — StandardEssential security for all Mozilla Firefox deployments; minimal performance impact.
L2Level 2 — HardenedAdvanced hardening for PCI-DSS, HIPAA, or high-security environments.

1 — Extension & Plugin Management

▶

1.1 Extension Policies

▶
1.1.1 Ensure Extension Installation Is Restricted (Automated)
L1 Auto
Description

This setting ensures that Extension Installation Is Restricted on the Mozilla Firefox browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Mozilla Firefox browser is essential for defense in depth.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Extension Installation Is Restricted. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Extension Installation Is Restricted. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

1.1.2 Ensure Add-on Signing Requirement Is Enforced (Automated)
L1 Auto
Description

This recommendation ensures that Add-on Signing Requirement Is Enforced on the Mozilla Firefox browser. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Mozilla Firefox browser may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Add-on Signing Requirement Is Enforced. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Add-on Signing Requirement Is Enforced. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

1.1.3 Ensure Legacy Extensions Are Disabled (Automated)
L1 Auto
Description

This recommendation verifies that Legacy Extensions Are Disabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Legacy Extensions Are Disabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Legacy Extensions Are Disabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

1.2 Plugin Settings

▶
1.2.1 Ensure Flash Plugin Is Disabled (Automated)
L1 Auto
Description

This recommendation verifies that Flash Plugin Is Disabled on the Mozilla Firefox browser. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.

Rationale

Running unnecessary components on the Mozilla Firefox browser increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Flash Plugin Is Disabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Flash Plugin Is Disabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

1.2.2 Ensure Plugin Click-to-Play Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Plugin Click-to-Play Is Enabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Plugin Click-to-Play Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Plugin Click-to-Play Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

1.2.3 Ensure DRM Content Is Controlled (Automated)
L2 Auto
Description

This setting ensures that DRM Content Is Controlled on the Mozilla Firefox browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Mozilla Firefox browser is essential for defense in depth.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that DRM Content Is Controlled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure DRM Content Is Controlled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

2 — Privacy & Tracking Protection

▶

2.1 Tracking Protection

▶
2.1.1 Ensure Enhanced Tracking Protection Is Set to Strict (Automated)
L1 Auto
Description

This recommendation verifies that Enhanced Tracking Protection Is Set to Strict on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Enhanced Tracking Protection Is Set to Strict. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Enhanced Tracking Protection Is Set to Strict. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

2.1.2 Ensure Do Not Track Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Do Not Track Is Enabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Do Not Track Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Do Not Track Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

2.1.3 Ensure Third-Party Cookies Are Blocked (Automated)
L2 Auto
Description

This setting ensures that Third-Party Cookies Are Blocked on the Mozilla Firefox browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Mozilla Firefox browser is essential for defense in depth.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Third-Party Cookies Are Blocked. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Third-Party Cookies Are Blocked. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

2.1.4 Ensure Fingerprinting Protection Is Enabled (Automated)
L2 Auto
Description

This recommendation verifies that Fingerprinting Protection Is Enabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Fingerprinting Protection Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Fingerprinting Protection Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

2.2 Data Collection

▶
2.2.1 Ensure Telemetry Is Disabled (Automated)
L2 Auto
Description

This recommendation verifies that Telemetry Is Disabled on the Mozilla Firefox browser. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.

Rationale

Running unnecessary components on the Mozilla Firefox browser increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Telemetry Is Disabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Telemetry Is Disabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

2.2.2 Ensure Crash Reporter Is Disabled (Automated)
L2 Auto
Description

This recommendation verifies that Crash Reporter Is Disabled on the Mozilla Firefox browser. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.

Rationale

Running unnecessary components on the Mozilla Firefox browser increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Crash Reporter Is Disabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Crash Reporter Is Disabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

2.2.3 Ensure Health Report Is Disabled (Automated)
L1 Auto
Description

This recommendation verifies that Health Report Is Disabled on the Mozilla Firefox browser. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.

Rationale

Running unnecessary components on the Mozilla Firefox browser increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Health Report Is Disabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Health Report Is Disabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

3 — Network Security

▶

3.1 Connection Security

▶
3.1.1 Ensure DNS-over-HTTPS Is Configured (Automated)
L2 Auto
Description

This recommendation verifies that DNS-over-HTTPS Is Configured on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that DNS-over-HTTPS Is Configured. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure DNS-over-HTTPS Is Configured. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

3.1.2 Ensure HTTPS-Only Mode Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that HTTPS-Only Mode Is Enabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that HTTPS-Only Mode Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure HTTPS-Only Mode Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

3.1.3 Ensure Proxy Settings Are Managed (Automated)
L1 Auto
Description

This recommendation verifies that Proxy Settings Are Managed on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Proxy Settings Are Managed. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Proxy Settings Are Managed. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

3.1.4 Ensure WebRTC IP Leak Is Prevented (Automated)
L2 Auto
Description

This recommendation verifies that WebRTC IP Leak Is Prevented on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that WebRTC IP Leak Is Prevented. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure WebRTC IP Leak Is Prevented. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

3.2 Protocol Configuration

▶
3.2.1 Ensure TLS 1.2 Is the Minimum Version (Automated)
L1 Auto
Description

This recommendation verifies that TLS 1.2 Is the Minimum Version on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that TLS 1.2 Is the Minimum Version. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure TLS 1.2 Is the Minimum Version. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

3.2.2 Ensure Weak Cipher Suites Are Disabled (Automated)
L1 Auto
Description

This recommendation verifies that Weak Cipher Suites Are Disabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Weak Cipher Suites Are Disabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Weak Cipher Suites Are Disabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

3.2.3 Ensure OCSP Stapling Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that OCSP Stapling Is Enabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that OCSP Stapling Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure OCSP Stapling Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

4 — Content & Permissions

▶

4.1 Content Settings

▶
4.1.1 Ensure Pop-up Blocking Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Pop-up Blocking Is Enabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Pop-up Blocking Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Pop-up Blocking Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

4.1.2 Ensure JavaScript Is Controlled for Untrusted Sites (Manual)
L2 Manual
Description

This setting ensures that JavaScript Is Controlled for Untrusted Sites on the Mozilla Firefox browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Mozilla Firefox browser is essential for defense in depth.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that JavaScript Is Controlled for Untrusted Sites. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure JavaScript Is Controlled for Untrusted Sites. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

4.1.3 Ensure Notifications Require Approval (Automated)
L1 Auto
Description

This recommendation ensures that Notifications Require Approval on the Mozilla Firefox browser. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Mozilla Firefox browser may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Notifications Require Approval. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Notifications Require Approval. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

4.2 Download Security

▶
4.2.1 Ensure Safe Browsing Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Safe Browsing Is Enabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Safe Browsing Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Safe Browsing Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

4.2.2 Ensure Download Actions Are Restricted (Automated)
L1 Auto
Description

This setting ensures that Download Actions Are Restricted on the Mozilla Firefox browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Mozilla Firefox browser is essential for defense in depth.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Download Actions Are Restricted. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Download Actions Are Restricted. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

4.2.3 Ensure Automatic File Download Is Blocked (Automated)
L2 Auto
Description

This setting ensures that Automatic File Download Is Blocked on the Mozilla Firefox browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Mozilla Firefox browser is essential for defense in depth.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Automatic File Download Is Blocked. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Automatic File Download Is Blocked. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

5 — Certificates & Authentication

▶

5.1 Certificate Management

▶
5.1.1 Ensure Enterprise Root Certificates Are Trusted (Automated)
L1 Auto
Description

This recommendation verifies that Enterprise Root Certificates Are Trusted on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Enterprise Root Certificates Are Trusted. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Enterprise Root Certificates Are Trusted. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

5.1.2 Ensure Certificate Transparency Is Enforced (Automated)
L2 Auto
Description

This recommendation ensures that Certificate Transparency Is Enforced on the Mozilla Firefox browser. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Mozilla Firefox browser may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Certificate Transparency Is Enforced. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Certificate Transparency Is Enforced. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

5.1.3 Ensure Revocation Checking Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Revocation Checking Is Enabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Revocation Checking Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Revocation Checking Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

5.2 Authentication

▶
5.2.1 Ensure Master Password Is Enforced (Manual)
L2 Manual
Description

This recommendation ensures that Master Password Is Enforced on the Mozilla Firefox browser. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Mozilla Firefox browser may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Master Password Is Enforced. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Master Password Is Enforced. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

5.2.2 Ensure Autofill for Credentials Is Controlled (Automated)
L1 Auto
Description

This setting ensures that Autofill for Credentials Is Controlled on the Mozilla Firefox browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Mozilla Firefox browser is essential for defense in depth.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Autofill for Credentials Is Controlled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Autofill for Credentials Is Controlled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

5.2.3 Ensure NTLM Authentication Is Restricted (Automated)
L2 Auto
Description

This setting ensures that NTLM Authentication Is Restricted on the Mozilla Firefox browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Mozilla Firefox browser is essential for defense in depth.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that NTLM Authentication Is Restricted. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure NTLM Authentication Is Restricted. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

6 — Updates & Enterprise Policies

▶

6.1 Update Configuration

▶
6.1.1 Ensure Auto-Update Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Auto-Update Is Enabled on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Auto-Update Is Enabled. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Auto-Update Is Enabled. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

6.1.2 Ensure Update Channel Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Update Channel Is Configured on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Update Channel Is Configured. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Update Channel Is Configured. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

6.2 Enterprise Policies

▶
6.2.1 Ensure Enterprise Policies Are Applied via policies.json (Manual)
L1 Manual
Description

This recommendation verifies that Enterprise Policies Are Applied via policies.json on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Enterprise Policies Are Applied via policies.json. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Enterprise Policies Are Applied via policies.json. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

6.2.2 Ensure Default Browser Check Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Default Browser Check Is Configured on the Mozilla Firefox browser. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Mozilla Firefox browser vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Default Browser Check Is Configured. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Default Browser Check Is Configured. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

6.2.3 Ensure Sync Is Disabled or Managed (Automated)
L2 Auto
Description

This recommendation verifies that Sync Is Disabled or Managed on the Mozilla Firefox browser. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.

Rationale

Running unnecessary components on the Mozilla Firefox browser increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that Sync Is Disabled or Managed. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure Sync Is Disabled or Managed. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).

6.2.4 Ensure about:config Access Is Restricted (Automated)
L2 Auto
Description

This setting ensures that about:config Access Is Restricted on the Mozilla Firefox browser. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Mozilla Firefox browser is essential for defense in depth.

Audit

Verify via Mozilla Firefox enterprise browser policy or Group Policy that about:config Access Is Restricted. Navigate to edge://policy (Edge) or about:policies (Firefox) and confirm the relevant policy is set.

Remediation

Configure Mozilla Firefox enterprise browser policy to ensure about:config Access Is Restricted. Deploy via Group Policy, Intune, or the managed policies file (policies.json / registry).