1.85 (L1) Ensure 'DNS interception checks enabled' is set to 'Enabled'

Information

This policy setting determines whether a local switch is configured for DNS interception checks. These checks attempt to discover if the browser is behind a proxy that redirects unknown host names.

The recommended state for this setting is: Enabled.

Note: This detection might not be necessary in an enterprise environment where the network configuration is known. It can be disabled to avoid additional DNS and HTTP traffic on start-up and each DNS configuration change.

Disabling these checks could potentially allow DNS hijacking and poisoning.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled :

Microsoft Edge\DNS interception checks enabled

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-8, CSCv7|7.7

Plugin: Windows

Control ID: e0b174fb98c442b60cfee7f6a00336d646cdc8b416038110c278d79b6905e8bb