1.20.1 (L1) Ensure 'Specifies whether to block requests from public websites to devices on a user's local network' is set to 'Enabled'

Information

This policy setting configures whether Microsoft Edge will prevent websites from making requests to local network devices without explicit user permission.

The recommended state for this setting is: Enabled.

If you disable or don't configure this policy, Microsoft Edge handles these requests using the default behavior, which may include showing warnings in DevTools and allowing the request to proceed depending on the context. Blocking websites from making requests to local network devices without explicit user permission can prevent malicious websites from sending unauthorized commands to devices like routers, printers, or IoT gadgets on your network. Enabling this policy setting will also protect your local network from being probed by sites using such requests.

Note: This feature improves local network security by deprecating direct access to private IP addresses from public websites unless explicitly granted by the user. For more information about Local Network Access, see https://wicg.github.io/local-network-access/.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Network settings\Specifies whether to block requests from public websites to devices on a user's local network

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from: Download Microsoft Edge for Business - Microsoft https://www.microsoft.com/en-us/edge/business/download.

Impact:

Microsoft Edge will prevent websites from making requests to local network devices without explicit user permission. Web apps that rely on automatic access to local devices (e.g., for configuration or diagnostics) may stop working unless permission is explicitly granted.

See Also

https://workbench.cisecurity.org/benchmarks/24354

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(3), 800-53|SC-7(4), CSCv7|7.5

Plugin: Windows

Control ID: 1df4d68adfce1c55dee66d93619157ae3ed0dbe1b1372569bfde16f6d6453820