Information
This policy setting configures whether Microsoft Edge will allow web authentication requests on websites that have TLS certificates with errors (i.e. Websites considered not secure).
The recommended state for this setting is: Disabled.
A 'broken' TLS certificate cannot be validated by the browser or application due to it being misconfigured, expired, or invalid in some other way. This prevents a secure connection from being made. Allowing Web Authentication requests on sites with broken TLS certificates may lead to sensitive information being exposed.
Solution
To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Disabled :
Microsoft Edge\Allow Web Authentication requests on sites with broken TLS certificates
Impact:
Web authentication requests on Websites that are considered not secure will be blocked.