1.3.9 Ensure 'Default geolocation setting' is set to 'Enabled: Don't allow any site to track users physical location'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This policy setting controls whether a users' physical location can be tracked by websites.

The recommended state for this setting is: Enabled: Don't allow any site to track users' physical location.

Rationale:

Geolocation should not be shared with websites to ensure protection of the users privacy regarding location. Additionally location information could lead to clues regarding the users network infrastructure surrounding the device they are utilizing.

Impact:

Location information will not be shared with websites in Microsoft Edge. This could have an affect on websites that utilize this information for customized content.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Don't allow any site to track users' physical location:

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Content settings\Default geolocation setting

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from Microsoft here.

Default Value:

Enabled. (Ask whenever a site wants to track users physical location.)

See Also

https://workbench.cisecurity.org/files/4094