1.57 Ensure 'Configure browser process code integrity guard setting' is set to 'Enabled: Enable code integrity guard enforcement in the browser process'

Information

This policy setting controls the use of code integrity guard in the browser process, which only allows Microsoft signed binaries to load.

The recommended state for this setting is Enabled: Enable code integrity guard enforcement in the browser process.

Rationale:

Code Integrity Guard ensures Microsoft's digital signature is present when loading binaries into a process. Binaries without Microsoft's digital signature are blocked to protect the system from unknown binaries and prevent the injection of untrustworthy binaries into a process.

Impact:

Binaries without Microsoft's digital signature are blocked from being loaded into a process.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Enable code integrity guard enforcement in the browser process:

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Configure browser process code integrity guard setting

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from: Download Microsoft Edge for Business - Microsoft.




Default Value:

Disabled. (Prevents the browser from enabling code integrity guard in the browser process.)

See Also

https://workbench.cisecurity.org/benchmarks/11865

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18

Plugin: Windows

Control ID: 302089b5ab914dc4902fb2017e161bafa9f4cc8dfdfd80bbd82227d98e1316ba