8.1.3 Set 'Protected Mode' to 'Enabled:Enable'

Information



Protected mode protects Internet Explorer from exploited vulnerabilities by reducing the
locations Internet Explorer can write to in the registry and the file system. If you enable
this policy setting, Protected Mode will be turned on. Users will not be able to turn off
protected mode. If you disable this policy setting, Protected Mode will be turned off. It will
revert to Internet Explorer 6 behavior that allows for Internet Explorer to write to the
registry and the file system. Users will not be able to turn on protected mode. If you do not
configure this policy, users will be able to turn on or off protected mode. The recommended
state for this setting is- Enabled-Enable.

*Rationale*

Protected mode protects Internet Explorer from exploited vulnerabilities by reducing the
locations Internet Explorer can write to in the registry and the file system.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Internet Zone\Turn on Protected ModeThen set the Protected Mode option to Enable.


Impact-If you enable this policy setting, Protected Mode will be turned on. Users will not be able to
turn off protected mode. If you disable this policy setting, Protected Mode will be turned
off. It will revert to Internet Explorer 6 behavior that allows for Internet Explorer to write
to the registry and the file system. Users will not be able to turn on protected mode. If you
do not configure this policy, users will be able to turn on or off protected mode.

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-3, CSCv6|3.1

Plugin: Windows

Control ID: 733b2ba4530f6a554c2f7c0172f0e32c1c3e59db4862c0a8aa4c41efa1e8d949