1.31.3 (L1) Ensure 'Enable Microsoft Defender SmartScreen DNS requests' is set to 'Enabled'

Information

This policy setting configures DNS requests made by Microsoft Defender SmartScreen.

The recommended state for this setting is: Enabled.

Note: This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that are enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.

Whenever SmartScreen is enabled for Edge browser, SmartScreen tries to check if the website is a phishing/malicious URL and does a local DNS query. If the DNS server fails to resolve the website, Web Isolation will not be used to isolate those websites.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled :

Microsoft Edge\SmartScreen settings\Enable Microsoft Defender SmartScreen DNS requests

Impact:

DNS server might not resolve queries sent to external websites or the website may have no information stored on its local server or cache.

Warning: Disabling DNS requests will prevent Microsoft Defender SmartScreen from getting IP addresses, and potentially impact the IP-based protections provided.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: 474487285901ac4ee292f5bd7972fbb7d11f2c346551c663cc2302dded0a22c2