1.6.1 (L1) Ensure 'Enable insecure download warnings' is set to 'Enabled'

Information

This policy setting configures whether warnings are enabled when potentially dangerous content is downloaded over HTTP.

The recommended state for this setting is: Enabled.

Downloading files over HTTP is not secure, and is vulnerable to interception and modification. Enabling this policy setting helps users avoid potentially harmful content by flagging executables and archives from insecure sources.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Cast\Downloads\Enable insecure download warnings

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from: Download Microsoft Edge for Business - Microsoft https://www.microsoft.com/en-us/edge/business/download.

Impact:

When a user tries to download potentially dangerous content from an HTTP site, the user will receive a UI warning, such as 'Insecure download blocked.' The user will still have an option to proceed and download the item.

See Also

https://workbench.cisecurity.org/benchmarks/24354

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4

Plugin: Windows

Control ID: 18218783d124b851ce50b56f287e7947a764ae138a0d9a5e3db694a2d47bbb0f