1.69 (L1) Ensure 'Configure browser process code integrity guard setting' is set to 'Enabled: Enable code integrity guard enforcement in the browser process.'

Information

This policy setting controls the use of code integrity guard in the browser process, which only allows Microsoft signed binaries to load.

The recommended state for this setting is: Enabled: Enable code integrity guard enforcement in the browser process..

Code Integrity Guard ensures Microsoft's digital signature is present when loading binaries into a process. Binaries without Microsoft's digital signature are blocked to protect the system from unknown binaries and prevent the injection of untrustworthy binaries into a process.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled: Enable code integrity guard enforcement in the browser process. :

Microsoft Edge\Configure browser process code integrity guard setting

Impact:

Binaries without Microsoft's digital signature are blocked from being loaded into a process.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: 3aca45890d79c50b5a3c844dd26fad2b6c291f56dadd11ae60eadaaff28ffbad