1.89 (L1) Ensure 'Enable Application Bound Encryption' is set to 'Enabled'

Information

This policy setting configures whether encryption keys used for local data storage are bound to Microsoft Edge whenever possible.

The recommended state for this setting is: Enabled.

When this policy setting is disabled, it has a detrimental effect on Microsoft Edge's security by allowing unknown and potentially hostile apps the possibility to retrieve the encryption keys used to secure data.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled :

Microsoft Edge\Enable Application Bound Encryption

Impact:

Compatibility issues may arise, such as scenarios where other applications need legitimate access to Microsoft Edge data.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: cbe40e2240305007be14fb0314580e7c8c582e6bbdd1d59e0e58fceb9578e610