3.2 Configure 'Prevent Deleting Cookies'

Information



This policy setting is used to prevent users from deleting cookies. This feature is available
in the Delete Browsing History dialog box. If you enable this policy setting, cookies will be
preserved when the user clicks Delete. If you disable this policy setting, cookies will be
deleted when the user clicks Delete. If you do not configure this policy setting, the user will
be able to choose whether to delete or preserve cookies when the user clicks Delete. If the
'Turn off Delete Browsing History functionality' policy is enabled, this policy is enabled by
default. Configure this setting in a manner that is consistent with security and operational
requirements of your organization.

*Rationale*

If a user is suspected of visiting unauthorized website the information stored in the data
cookies could be useful in verifying where he or she went online.

Solution


To establish the recommended configuration via Group Policy, set the following UI path to
Not Configured.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Delete Browsing History\Prevent Deleting Cookies

Impact-If you enable this policy setting, users will not be able to delete cookies. If you disable or do
not configure this policy setting, users will be able to delete cookies.

Default Value-Disabled

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Windows

Control ID: 68503709f0fd9cd21d92742f1fb5590418bcc1b92999f2c56cec803ceecc7a83