1.13.1 (L1) Ensure 'Allow Basic authentication for HTTP' is set to 'Disabled'

Information

This policy setting determines if Basic authentication receives challenges over non-secure HTTP. Basic authentication is a non-secure authentication method that relies on sending the username and password to the server in plaintext.

The recommended state for this setting is: Disabled.

Note: This policy setting is ignored (and Basic is always forbidden) if the AuthSchemes (Supported authentication schemes) policy is set and does not include Basic.

Basic authentication is less robust than other authentication methods available because credentials including passwords are transmitted in plain text. An attacker who can capture these credentials in plain text can gain access to the system.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\HTTP authentication\Allow Basic authentication for HTTP

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from: Download Microsoft Edge for Business - Microsoft https://www.microsoft.com/en-us/edge/business/download.

Impact:

Non-secure HTTP requests from the Basic authentication scheme are blocked, and only secure HTTPS is allowed.

See Also

https://workbench.cisecurity.org/benchmarks/24354

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: Windows

Control ID: aa67c303606e925c67deaba5df14f1b3ee75af4061582f54373e627910ae9e90