1.34 (L1) Ensure 'Allow download restrictions' is set to 'Enabled: Block malicious downloads'

Information

This policy setting controls whether Microsoft Edge blocks certain types of downloads, and prevents users from bypassing security warnings, depending on the classification of Safe Browsing.

The recommended state for this setting is: Enabled: Block malicious downloads.

Note: These restrictions only apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, or to the 'Save as PDF' option from the printing options. For more information on Microsoft Defender SmartScreen, please visit Microsoft Defender SmartScreen Frequently Asked Questions https://go.microsoft.com/fwlink/?linkid=2094934.

Note #2: Microsoft Edge relies on Internet Explorer zones (Local Machine, Local Intranet, Trusted, Internet, Restricted) to determine which sites may bypass this policy setting. Please see Security Zones in Edge - text/plain https://textslashplain.com/2020/01/30/security-zones-in-edge/ for more information.

Downloads could contain malware that has the potential to exfiltrate sensitive data or encrypt critical systems for ransom.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled: Block malicious downloads :

Microsoft Edge\Allow download restrictions

Note: The setting Allow download restrictions can appear twice in the settings picker. Be sure to choose the one that includes the setting value in the dropdown box as indicated above.

Impact:

Users will be prevented from downloading certain types of files and will not be able to bypass security warnings.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: 81af907433138f34061f337f7024a0869ec7f535a70b65cad96d8e9d4f8df9fd