1.78 (L2) Ensure 'Control use of the Headless Mode' is set to 'Disabled'

Information

This policy setting controls whether users can launch Microsoft Edge in headless mode. A headless browser is a browser that is not configured with a Graphical User Interface (GUI) and is executed via command-line or using network communication.

The recommended state for this setting is: Disabled.

Although this feature can be very useful to developers, an attacker could programmatically scrape website content and install malicious scripts on devices running the browser's headless interface.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Disabled :

Microsoft Edge\Control use of the Headless Mode

Impact:

Users will not be able to access headless mode in Microsoft Edge.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 8c2b7fab99456f5ffbfa12f486de4c376e852f49e1a80354f725f3bd2f4e0fd1