6.1 Set 'Disable Browser Geolocation' to 'Enabled'

Information

*Description*

This policy setting allows you to disable browser geolocation support. This will prevent
websites from requesting location data about the user.
If you enable this policy setting, browser geolocation support will be turned off.
If you disable this policy setting, browser geolocation support will be turned on.
If you do not configure this setting, browser geolocation support can be turned on or off in
Internet Options on the Privacy tab. The recommended state for this setting is- Enabled.

*Rationale*

This setting has a small impact on user privacy because users may unknowingly allow their
browser to share location data with web sites that they visit. The value of enabling this
setting is diminished due to the fact that malicious web sites can learn a great deal about
the location of a user merely by analyzing their IP address.

Solution

To implement the recommended configuration state, set the following Group Policy setting
to Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Disable Browser Geolocation

Impact-If you enable this policy setting, browser geolocation support will be turned off. If you
disable this policy setting, browser geolocation support will be turned on. If you do not
configure this setting, browser geolocation support can be turned on or off in Internet
Options on the Privacy tab.

See Also

https://workbench.cisecurity.org/files/1516

Item Details

Audit Name: CIS IE 9 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|3.1

Plugin: Windows

Control ID: 902c31332cb08393ed2954ca6f848d1c962a4f2f840b44000f53abdafe248242