1.57 (L2) Ensure 'Allow users to proceed from the HTTPS warning page' is set to 'Disabled'

Information

This policy setting controls whether a user can proceed to a webpage when an invalid SSL certificate warning has occurred.

The recommended state for this setting is: Disabled.

Sites protected by SSL should always be recognized as valid in the web browser. Allowing a user to make the decision as to whether what appears to be an invalid certificate could open an organization up to users visiting a site that is otherwise not secure and/or malicious in nature.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Disabled :

Microsoft Edge\Allow users to proceed from the HTTPS warning page

Impact:

Users will not be able to click past the invalid certificate error to view the website.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Windows

Control ID: 9f57083e8118e0d2c981c0a9e91f051f00fc4c0db384dadf459f64bd5a269e94