2.3 Set 'Turn off ActiveX opt- in prompt' to 'Disabled'

Information

*Description*

This policy setting allows you to turn off the ActiveX opt-in prompt. The ActiveX opt-in
prevents Web sites from loading any COM object without prior approval. If a page attempts
to load a COM object that Internet Explorer has not used before, an Information bar will
appear asking the user for approval. If you enable this policy setting, the ActiveX opt-in
prompt will not appear. Internet Explorer does not ask the user for permission to load a
control, and will load the ActiveX if it passes all other internal security checks. If you
disable or do not configure this policy setting, the ActiveX opt-In prompt will appear. The
recommended state for this setting is- Disabled.

*Rationale*

If the user were to enable this setting the ActiveX opt-in prompt would be disabled and
malicious ActiveX controls could be executed without the user's knowledge.

Solution

To implement the recommended configuration state, set the following Group Policy setting
to Disabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Turn off ActiveX opt-in prompt

Impact-Enabling this setting would allow the possibility of malicious ActiveX controls to be
executed without the user's knowledge.

See Also

https://workbench.cisecurity.org/files/1516

Item Details

Audit Name: CIS IE 9 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|3.1

Plugin: Windows

Control ID: 77f451b77e8a24f4781c1ec1edabf510ab18195eec8f59f22b09cda802d5ca5d