1.63 (L2) Ensure 'Block third party cookies' is set to 'Enabled'

Information

This policy controls whether web page elements from a domain other than that in the address bar can set cookies.

The recommended state for this setting is: Enabled.

Allowing third-party cookies could potentially allow tracking of your web activities by third-party entities which may expose information that could be used for an attack on the end-user.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled :

Microsoft Edge\Block third party cookies

Impact:

Disabling third-party cookies could cause some websites to not function as expected (e.g., Microsoft 365 or Salesforce).

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: 5be78dc53ac7ed700fa46f55d64a756fb9f9a7a69ccaa9c060a8cc4c31aae857