2.1 Set 'Disable Per- User Installation of ActiveX Controls' to 'Enabled'

Information

*Description*

This policy setting allows you to disable the per-user installation of ActiveX controls. This
policy only affects ActiveX controls that can be installed on a per-user basis. If you enable
this policy setting, ActiveX controls cannot be installed on a per-user basis. If you disable or
do not configure this policy setting, ActiveX controls can be installed on a per-user basis.
Configure this setting in a manner that is consistent with the security and operational
requirements of your organization. The recommended state for this setting is- Enabled.

*Rationale*

Per-user installation of ActiveX controls is a convenient feature that many organizations
may want to leverage. One benefit is that even if the user installs a control that includes a
malicious payload its impact will be limited to the privileges of the user who installed it.
Nevertheless, restricting the installation of ActiveX controls to administrators and using the
ActiveX Installer Service or some other centralized software deployment tool is a more
effective method for avoiding malware.

Solution

To establish the recommended configuration via Group Policy, set the following UI path
to Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Prevent per-user installation of ActiveX controls

Impact-If you enable this policy setting, ActiveX controls cannot be installed on a per-user basis.
If you disable or do not configure this policy setting, ActiveX controls can be installed on a
per-user basis.

See Also

https://workbench.cisecurity.org/files/1516

Item Details

Audit Name: CIS IE 9 v1.0.0

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18

Plugin: Windows

Control ID: d21bc01236a9782cdc3fa8fb86aeb259bfa0bfc2bd34ed442ad42b65459877a7