1.20.1 (L1) Ensure 'Specifies whether to block requests from public websites to devices on a user's local network' is set to 'Enabled'

Information

This policy setting configures whether Microsoft Edge will prevent websites from making requests to local network devices without explicit user permission.

The recommended state for this setting is: Enabled.

If you disable or don't configure this policy, Microsoft Edge handles these requests using the default behavior, which may include showing warnings in DevTools and allowing the request to proceed depending on the context. Blocking websites from making requests to local network devices without explicit user permission can prevent malicious websites from sending unauthorized commands to devices like routers, printers, or IoT gadgets on your network. Enabling this policy setting will also protect your local network from being probed by sites using such requests.

Note: This feature improves local network security by deprecating direct access to private IP addresses from public websites unless explicitly granted by the user. For more information about Local Network Access, see https://wicg.github.io/local-network-access/.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled :

Microsoft Edge\Network settings\Specifies whether to block requests from public websites to devices on a user's local network

Impact:

Microsoft Edge will prevent websites from making requests to local network devices without explicit user permission. Web apps that rely on automatic access to local devices (e.g., for configuration or diagnostics) may stop working unless permission is explicitly granted.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(3), 800-53|SC-7(4), CSCv7|7.5

Plugin: Windows

Control ID: d682561f2f74f82dd9bdf32901a960d9b6137a4bd99453404b3bbb2e07204115