Information
This policy setting configures whether Microsoft Edge will allow web authentication requests on websites that have TLS certificates with errors (i.e. Websites considered not secure).
The recommended state for this setting is: Disabled.
A 'broken' TLS certificate cannot be validated by the browser or application due to it being misconfigured, expired, or invalid in some other way. This prevents a secure connection from being made. Allowing Web Authentication requests on sites with broken TLS certificates may lead to sensitive information being exposed.
Solution
To establish the recommended configuration via GP, set the following UI path to Disabled :
Computer Configuration\Administrative Templates\Microsoft Edge\Allow Web Authentication requests on sites with broken TLS certificates
Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from: Download Microsoft Edge for Business - Microsoft https://www.microsoft.com/en-us/edge/business/download.
Impact:
Web authentication requests on Websites that are considered not secure will be blocked.