8.5.3 Set 'Don't run antimalware programs against ActiveX controls' to 'Enabled:Disabled'

Information



This policy setting determines whether Internet Explorer runs antimalware programs
against ActiveX controls, to check if they're safe to load on pages.If you enable this policy setting, Internet Explorer won't check with your anti-malware
program to see if it's safe to create an instance of the ActiveX control.If you disable this policy setting, Internet Explorer always checks with your anti-malware
program to see if it's safe to create an instance of the ActiveX control.If you don't configure this policy setting, Internet Explorer always checks with your anti-
malware program to see if it's safe to create an instance of the ActiveX control. Users can
turn this behavior on or off, using Internet Explorer Security settings.

*Rationale*

Scanning ActiveX controls for malware will reduce risk associated with malicious ActiveX
controls.

Solution


To establish the recommended configuration via Group Policy, set the following UI path to
Enabled-Disabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Trusted Sites Zone

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(1)

Plugin: Windows

Control ID: 74d0e2f788cb8a0f5a5a08aac95212c6e627a6b0334bda603fdcd37ab8b67014