1.52 (L1) Ensure 'Allow the audio sandbox to run' is set to 'Enabled'

Information

This policy setting controls whether audio processes in Microsoft Edge run in a sandbox.

The recommended state for this setting is: Enabled.

Note: Security software setups within your environment might interfere with the sandbox.

Having audio processes run in a sandbox ensures that if a website misuses audio processes that data may not be manipulated or exfiltrated from the system.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled :

Microsoft Edge\Allow the audio sandbox to run

Impact:

The audio process will not run in the sandbox and the WebRTC audio-processing module will run in the renderer process.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 8ba9397dd9d92bad0dbdc12b01483e2fe17fad28e9107b748ce836e1b84e12e6