1.63 Ensure 'Configure whether form data and HTTP headers will be sent when entering or exiting Internet Explorer mode' is set to 'Enabled: Do not send form data or headers'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This policy setting configures navigations that switch between Internet Explorer mode and Microsoft Edge will include form data. IE Mode in Microsoft Edge allows organizations that still need Internet Explorer 11, (which is not supported) for backward compatibility with existing websites.

Available policy options:

IncludeNone (0) = Do not send form data or headers

IncludeFormDataOnly (1) = Send form data only

IncludeHeadersOnly (2) = Send additional headers only

IncludeFormDataAndHeaders (3) = Send form data and additional headers

The recommended state for this setting is: Enabled: Do not send form data or headers.

Rationale:

Allowing autofill data to be imported could potentially allow sensitive data, such as personally identifiable information (PII) to be exposed. Storage of sensitive data should be handled with care and not stored within the browser.

Impact:

When entering or exiting IE mode, form data and headers will not be shared between Internet Explorer mode and Microsoft Edge and vise versa.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Do not send form data or headers:

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Configure whether form data and HTTP headers will be sent when entering or exiting Internet Explorer mode

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from: Download Microsoft Edge for Business - Microsoft.

Default Value:

Disabled. (Microsoft Edge will use the new behavior of including form data in navigations that change modes.)

See Also

https://workbench.cisecurity.org/files/4094