8.1.4 Set 'Allow installation of desktop items' to 'Enabled:Disable'

Information

*Description*

This policy setting allows you to manage whether users can install Active Desktop items
from this zone. The recommended state for this setting is- Enabled-Disable.

*Rationale*

Active Desktop items could contain links to unauthorized websites or other undesirable
content, it is prudent to prevent users from installing desktop items from this security
zone.

Solution

To implement the recommended configuration state, set the following Group Policy setting
to Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Internet Zone\Allow installation of
desktop items\Allow installation of desktop items

Then set the Allow installation of desktop items option to Disable.

Impact-The settings for this option are- Enabled, users can install desktop items from this zone
automatically. Prompt, users are queried to choose whether to install desktop items from
this zone. Disabled, users are prevented from installing desktop items from this zone. If you
do not configure this policy setting, users are prevented from installing desktop items from
this zone.

See Also

https://workbench.cisecurity.org/files/1516

Item Details

Audit Name: CIS IE 9 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(4)

Plugin: Windows

Control ID: 37a501145610301bbbf0661711259c8da600f81e5b0c58831c2a8185b4f395a3