8.13 Set 'Security Zones: Use only machine settings' to 'Enabled'

Information



This policy setting affects how security zone changes apply to different users. If you enable
this policy setting, changes that one user makes to a security zone will apply to all users of
that computer. If this policy setting is disabled or not configured, users of the same
computer are allowed to establish their own security zone settings. The recommended
state for this setting is- Enabled.

*Rationale*

Users who change their Internet Explorer security settings could enable the execution of
dangerous types of code from the Internet and Web sites that were listed in the Restricted
Sites zone in the browser.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Security Zones- Use only machine settings

Impact-Users will not be able to configure security settings for Internet Explorer zones.

Default Value-Disabled
9 Additional Settings

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-5

Plugin: Windows

Control ID: a25180f23f71efe316c488f65781e03a8506aeeaf2c77e0a49909724066cd3ed