1.57 (L2) Ensure 'Allow users to proceed from the HTTPS warning page' is set to 'Disabled'

Information

This policy setting controls whether a user can proceed to a webpage when an invalid SSL certificate warning has occurred.

The recommended state for this setting is: Disabled.

Sites protected by SSL should always be recognized as valid in the web browser. Allowing a user to make the decision as to whether what appears to be an invalid certificate could open an organization up to users visiting a site that is otherwise not secure and/or malicious in nature.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Microsoft Edge\Allow users to proceed from the HTTPS warning page

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from: Download Microsoft Edge for Business - Microsoft https://www.microsoft.com/en-us/edge/business/download.

Impact:

Users will not be able to click past the invalid certificate error to view the website.

See Also

https://workbench.cisecurity.org/benchmarks/24354

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Windows

Control ID: 2c5bcd905a14592d1510a6740d7a7050ebeda7224a23400491963b15ac15e2b9