1.87 (L1) Ensure 'Dynamic Code Settings' is set to 'Enabled: Prevent the browser process from creating dynamic code'

Information

This policy setting controls the Dynamic Code Settings for Microsoft Edge.

The recommended state for this setting is: Enabled: Prevent the browser process from creating dynamic code.

Leaving this policy in its default state decreases the security of Microsoft Edge by allowing potentially hostile Dynamic Code and third-party code to make changes to Microsoft Edge's behavior.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Prevent the browser process from creating dynamic code :

Computer Configuration\Administrative Templates\Microsoft Edge\Dynamic Code Settings

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from: Download Microsoft Edge for Business - Microsoft https://www.microsoft.com/en-us/edge/business/download.

Impact:

Compatibility issues may arise with third-party software (e.g. certain printer drivers) that must run in the browser process.

See Also

https://workbench.cisecurity.org/benchmarks/24354

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: 026f2ce6619f76916b16d52dfdd470b5ff8e67985835b82f7953f8d83ed55539