1.9.1 (L1) Ensure 'Configure users ability to override feature flags' is set to 'Enabled: Prevent users from overriding feature flags'

Information

This policy setting configures users' ability to override state of feature flags. Feature flags are settings a team can define that indicate whether a given set of features is visible in the user experience and/or invoked within the functionality.

The recommended state for this setting is: Enabled: Prevent users from overriding feature flags.

The ability to enter commands and override programs should be limited at the CLI to prevent unintentional system configuration alterations. Additionally, feature flags are not necessary for users, as they are typically used by Development teams.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled: Prevent users from overriding feature flags :

Microsoft Edge\Experimentation\Configure users ability to override feature flags

Impact:

It can be risky for experimental features to be allowed in an enterprise managed environment because this can introduce bugs and security holes into systems, making it easier for an attacker to gain access. It is generally preferred to only use production-ready features.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-10, 800-53|CM-11, 800-53|SC-18, CSCv7|7.2

Plugin: Windows

Control ID: 1ec51a46a3e6342607910e4942d8106eea1fa3f3b4191d8ecdb0f45caca998b0