1.14.1 Ensure 'Enable startup boost' is set to 'Disabled'

Information

This policy setting allows Microsoft Edge processes to start at OS sign-in and restart in background after the last browser window is closed.

If Microsoft Edge is running in background mode, the browser might not close when the last window is closed, and the browser won't be restarted in background when the window closes. See the BackgroundModeEnabled (Continue running background apps after Microsoft Edge closes) policy for information about what happens after configuring Microsoft Edge background mode behavior.

Note: The startup boost policy may initially be configured off or on by the user; the user can configure its behavior in edge://settings/system.

The recommended state for this setting is: Disabled.

Rationale:

Allowing processes from the browser to run in the background could allow a malicious script or code to continue running once the browser windows has been closed.

Impact:

Users will experience normal browser start-up times which may seem slow in comparison to Startup boost.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Performance\Enable startup boost

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from: Download Microsoft Edge for Business - Microsoft.

Default Value:

Not configured. (Start boost may initially be off or on.)

See Also

https://workbench.cisecurity.org/benchmarks/11865

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-10, 800-53|CM-11, 800-53|SC-18, CSCv7|7.2

Plugin: Windows

Control ID: 995de4ecd4779e8839015f3adb31ceca1fd9f13564827f1f2c037ff36da518f3