1.3.10 Ensure 'Default geolocation setting' is set to 'Enabled: Don't allow any site to track users physical location'

Information

This policy setting controls whether a users' physical location can be tracked by websites.

The recommended state for this setting is: Enabled: Don't allow any site to track users' physical location.

Rationale:

Geolocation should not be shared with websites to ensure protection of the user's privacy regarding location. Additionally, location information could lead to clues regarding the user's network infrastructure surrounding the device they are utilizing.

Impact:

Location information will not be shared with websites in Microsoft Edge. This could have an effect on websites that utilize this information for customized content.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Don't allow any site to track users' physical location:

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Content settings\Default geolocation setting

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from: Download Microsoft Edge for Business - Microsoft.

Default Value:

Enabled. (Ask whenever a site wants to track users physical location.)

See Also

https://workbench.cisecurity.org/benchmarks/11865

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: c8347ba61c402067212811d21b00f36cdb88de89c71f4587876cc9b8bd5b3fcd