1.7.1 (L1) Ensure 'Configure Edge Website Typo Protection' is set to 'Enabled'

Information

This policy setting configures whether to turn on Edge TyposquattingChecker. The Edge TyposquattingChecker provides warning messages to help protect users from potential typo squatting sites. Typo squatting is a type of social engineering attack which targets internet users who incorrectly type a URL into their web browser rather than using a search engine. Typically, it involves tricking users into visiting malicious websites with URLs that are common misspellings of legitimate websites.

The recommended state for this setting is: Enabled.

The Edge TyposquattingChecker will provide a warning message and can help protect users from potential typo squatting by alerting the user to the potential of accessing a malicious site.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled :

Microsoft Edge\Typosquatting Checker settings\Configure Edge Website Typo Protection

Impact:

Users will see a warning message when attempting to access a site identified by Microsoft as a potential typosquatting site. Occasionally, legitimate sites may be mistakenly flagged as typosquatting.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: fc5c9c39521820a60c202efb1d2d4157c44912f63255eba9e50b928265710322