1.3.1 (L1) Ensure 'Allow users to manage installed CA certificates' is set to 'Enabled: Disallow users from managing certificates'

Information

This policy configures the level of access users have when managing CA certificates in Microsoft Edge.

The recommended state for this setting is: Enabled : Disallow users from managing certificates.

Configuring this policy to the recommended state prevents users from unknowingly installing certificates that grant excessive trust, such as root CAs from unverified sources. It also prevents system-trusted certificates from being tampered with by users.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled : Disallow users from managing certificates :

Microsoft Edge\Certificate management settings\Allow users to manage installed CA certificates

Impact:

Users will not be able to manage certificates.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Windows

Control ID: a5c451e1ceec000440a5eba8e1bfdcdc636497918beea568a73c8c8b70c74528