1.120 (L1) Ensure 'Notify a user that a browser restart is recommended or required for pending updates' is set to 'Enabled: Required - Show a recurring prompt to the user indicating that a restart is required'

Information

This setting determines whether a notification to restart Microsoft Edge due to an update is recommended or required.

The recommended state for this setting is: Enabled: Required - Show a recurring prompt to the user indicating that a restart is required.

Note: If this setting is set as prescribed, the browser will automatically restart based on the RelaunchNotificationPeriod setting which is recommended to be 24 hours.

The end-user will receive a notification informing them that an update has been applied and that the browser must be restarted for the update to be completed. Once updates have been pushed by the organization it is pertinent that the update is applied as soon as possible. Enabling this notification will ensure that users restart their browser in a timely fashion.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled: Required - Show a recurring prompt to the user indicating that a restart is required :

Microsoft Edge\Notify a user that a browser restart is recommended or required for pending updates

Impact:

When updates are applied by an organization the end-user will receive a notification after 24 hours that they must restart the browser for updates to complete, after 24 hours the browser will be automatically restarted.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.5

Plugin: Windows

Control ID: 936f960ac060ba6b8299bff1b58ec3e9709a20eef269097d2ed390bcecff4bea