7.5 Set 'MK Protocol Security Restriction' to 'Enabled'

Information



The MK Protocol Security Restriction policy setting reduces attack surface area by
preventing the MK protocol. Resources hosted on the MK protocol will fail. If you enable
this policy setting, the MK Protocol is prevented for File Explorer and Internet Explorer,
and resources hosted on the MK protocol will fail. If you disable this policy setting,
applications can use the MK protocol API. Resources hosted on the MK protocol will work
for the File Explorer and Internet Explorer processes. If you do not configure this policy
setting, the MK Protocol is prevented for File Explorer and Internet Explorer, and resources
hosted on the MK protocol will fail. The recommended state for this setting is- Enabled.

*Rationale*

Because the MK protocol is not widely used, it should be blocked wherever it is not needed.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Security Features\MK Protocol Security Restriction\Internet Explorer
Processes

Default Value-Enabled

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CSCv6|3.1

Plugin: Windows

Control ID: e0f87aad4d68d55c89fdd518b94789bb4a351199f7176ed1efb2bec0c138e06d