1.4 Set 'Prevent bypassing SmartScreen Filter warnings about files that are not commonly downloaded from the Internet' to 'Enabled'

Information




This policy setting determines whether the user can bypass warnings from SmartScreen
Filter. SmartScreen Filter warns the user about executable files that Internet Explorer users
do not commonly download from the Internet.
If you enable this policy setting, SmartScreen Filter warnings block the user.
If you disable or do not configure this policy setting, the user can bypass SmartScreen Filter
warnings. The recommended state for this setting is- Enabled.

*Rationale*

The SmartScreen Filter prevents users from navigating to and downloading from sites
known to host malicious content, including Phishing or malicious software attacks.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Prevent bypassing SmartScreen Filter warnings about files that are not
commonly downloaded from the Internet

Impact-If you enable this policy setting, the user is not permitted to navigate to sites identified as
unsafe by the SmartScreen Filter. If you disable this policy setting or do not configure it, the
user can ignore SmartScreen Filter warnings and navigate to unsafe sites.

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(3)

Plugin: Windows

Control ID: d5e6ff58acdf8f306656cf4c06d49beb01cbd1f2ec754f292de51357600a43bc