1.11.1 (L1) Ensure 'Enable the linked account feature' is set to 'Disabled'

Information

This policy setting determines if Microsoft Edge can guide a user to the account management page where they can link a Microsoft Account (MSA) to an Azure Active Directory (Azure AD) account.

The recommended state for this setting is: Disabled

Linking personal Microsoft Accounts to a company device could inadvertently lead to data being transferred from the environment to a personal device.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Identity and sign-in\Enable the linked account feature

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from:

Download Microsoft Edge for Business - Microsoft

.

Impact:

Linked account information will not be shown on a flyout and when the Azure AD profile doesn't have a linked account it will not show the 'Add account' button.

See Also

https://workbench.cisecurity.org/benchmarks/18501

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 02dafc4474ecd51423d42717c7bcb107499b3949a2cd1a913f5fb86db25f5c04