1.63 (L2) Ensure 'Block third party cookies' is set to 'Enabled'

Information

This policy controls whether web page elements from a domain other than that in the address bar can set cookies.

The recommended state for this setting is: Enabled.

Allowing third-party cookies could potentially allow tracking of your web activities by third-party entities which may expose information that could be used for an attack on the end-user.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Block third party cookies

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from: Download Microsoft Edge for Business - Microsoft https://www.microsoft.com/en-us/edge/business/download.

Impact:

Disabling third-party cookies could cause some websites to not function as expected (e.g., Microsoft 365 or Salesforce).

See Also

https://workbench.cisecurity.org/benchmarks/24354

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: b3e8dc9c5a72850e6027f617d6fbbcc3979eb6b1ba44b030d89320c3f2278cea