1.90 (L1) Ensure 'Enable Application Bound Encryption' is set to 'Enabled'

Information

This policy setting configures whether encryption keys used for local data storage are bound to Microsoft Edge whenever possible.

The recommended state for this setting is: Enabled.

When this policy setting is disabled, it has a detrimental effect on Microsoft Edge's security by allowing unknown and potentially hostile apps the possibility to retrieve the encryption keys used to secure data.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Administrative Templates\Microsoft Edge\Enable Application Bound Encryption

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from: Download Microsoft Edge for Business - Microsoft https://www.microsoft.com/en-us/edge/business/download.

Impact:

Compatibility issues may arise, such as scenarios where other applications need legitimate access to Microsoft Edge data.

See Also

https://workbench.cisecurity.org/benchmarks/24354

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: 0e380f5aae9c7f998af778efb519e507f51a420cd5d5645816685686f71ca6ad