2.30 Ensure 'Enable Renderer App Container' Is Enabled

Information

This setting controls the ability for Google Chrome to allow the Render App Container sandbox to be used while navigating to certain sites. It can be configured to either:

Disabled (0): Disable the Renderer App Container sandbox

Enabled (1): Enable the Renderer App Container sandbox

If the value for RendererAppContainerEnabled is not changed from the default, it will behave as if it is enabled.

Rationale:

Disabling this policy would weaken the sandbox that Google Chrome uses for the renderer process, and will have a detrimental effect on the security and stability of the browser. This policy needs to be enabled to maintain security and stability.

Impact:

This would only impact users if there is third-party software that must run inside renderer processes.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Enable Renderer App Container

Default Value:

Unset (Enabled)

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-8, CSCv7|4.8

Plugin: Windows

Control ID: 2da312a2e530a3df22d4bae229faf29bee4f5d8c1fd67f83d9ec0d051045cb05