4.2.8 Ensure 'Block Window Management permission on these sites' Is Configured

Information

This setting can automatically deny access to the window management permissions for specific sites. It can be configured to either:

If the value for WindowManagementBlockedForUrls is not changed from the default, it will follow the configuration of DefaultWindowManagementSetting.

Rationale:

Specifying URLs that do not have access to the window management permissions limits data for sites that have access to data on the clipboard, and allows for more sites to have access.

Impact:

Enforcing this recommendation can cause visited sites to not display as intended.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled and set Show to the blocked URLs:

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Content settings\Block Window Management permission on these sites

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3

Plugin: Windows

Control ID: 9f7c2e24bf97a98183e910b6ae114e049d407f117d6ce0081d93eeb33bf0690f