1.74 (L1) Ensure 'Configure the list of types that are excluded from synchronization' is set to 'Enabled'

Information

This policy setting allows you to specify data types that will be limited/excluded from uploading data to the Microsoft Edge synchronization service.

The recommended state for this setting is: Enabled with the following CASE SENSITIVE datatype passwords.

Note: In a High Security/Sensitive Data Environment (L2), this setting should also include the following options: settings, favorites, addressesAndMore, extensions and collections.

Storing and sharing information could potentially expose sensitive information including but not limited to user passwords and login information. Allowing this synchronization could also potentially allow an end user to pull corporate data that was synchronized into the cloud to a personal machine.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled with the following CASE SENSITIVE datatype passwords :

Microsoft Edge\Configure the list of types that are excluded from synchronization
- Add the word passwords to the dialog box, in all lower case.

Impact:

Password data will not be synchronized with the Azure AD Tenant.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 8aae248aa47c392848d83448e1bd4cc500b3a89cb77b5862aa6a19a40c99dff7