2.7.1 (L1) Ensure 'Cross-origin HTTP Authentication prompts' is set to 'Disabled'

Information

This setting controls whether third-party sub-content can open a HTTP Basic Auth dialog and is typically disabled.

The recommended state for this setting is: Disabled (0)

This setting is typically disabled to help combat phishing attempts.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\HTTP authentication\Cross-origin HTTP Authentication prompts

Impact:

None - This is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/23110

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Windows

Control ID: 41cffcad8a9dc5f3f4da94fc8608fd47487968e64a9488cd4353f8378a2006ff