1.4.9 (L1) Ensure 'Default automatic downloads setting' is set to 'Enabled: Don't allow any website to perform automatic downloads'

Information

This policy setting controls whether websites can perform multiple downloads successively without user interaction.

The recommended state for this setting is: Enabled: Don't allow any website to perform automatic downloads.

Unintentional malicious content could be downloaded without user interaction if websites are allowed to perform automatic downloads.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled: Don't allow any website to perform automatic downloads :

Microsoft Edge\Content settings\Default automatic downloads setting

Impact:

Websites will not be able to perform automatic downloads.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-2c.

Plugin: Windows

Control ID: 47b2b0236ed313c5a9d1727f289642707b1fb9e2933926dc05e8e470df07a4af