1.31.6 (L1) Ensure 'Prevent bypassing of Microsoft Defender SmartScreen warnings about downloads' is set to 'Enabled'

Information

This policy setting controls whether users may override Microsoft Defender SmartScreen warnings regarding downloads that are unverified.

The recommended state for this setting is: Enabled.

Smartscreen checks downloads and verifies whether they are deemed safe or not. Only allowing verified downloads greatly reduces risk of a download containing a virus, spyware, or other unwanted software.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled :

Microsoft Edge\SmartScreen settings\Prevent bypassing of Microsoft Defender SmartScreen warnings about downloads

Impact:

Users will not be able to download software that has not been verified by SmartScreen.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: 4919b3601f9e4d2d59fe5e3f069ac6fee617973cf61e0149c595d5e8c7713cf3