1.8.1 Ensure 'Enable the linked account feature' is set to 'Disabled'

Information

This policy setting determines if Microsoft Edge can guide a user to the account management page where they can link a Microsoft Account (MSA) to an Azure Active Directory (Azure AD) account.

The recommended state for this setting is: Disabled.

Rationale:

Linking personal Microsoft Accounts to a company device could inadvertently lead to data being transferred from the environment to a personal device.

Impact:

Linked account information will not be shown on a flyout and when the Azure AD profile doesn't have a linked account it will not show the 'Add account' button.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Identity and sign-in\Enable the linked account feature

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from: Download Microsoft Edge for Business - Microsoft.

Default Value:

Enabled. (Linked account information will be shown on a flyout. When the Azure AD profile doesn't have a linked account, it will show 'Add account')

See Also

https://workbench.cisecurity.org/benchmarks/11865

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Windows

Control ID: 2a3b2485f2133ec333b582ecfe20a18b716e9adffb1d02082c6864126e020d58