1.65 (L2) Ensure 'Browser sign-in settings' is set to 'Enabled: Disable browser sign-in'

Information

This policy setting controls whether a user can sign into Microsoft Edge with an account to use services such as sync and single sign on.

The recommended state for this setting is: Enabled: Disable browser sign-in.

Note: To control the availability of sync, use the SyncDisabled (Disable synchronization of data using Microsoft sync services) policy.

Note #2: This setting works in conjunction with the NonRemovableProfileEnabled setting which will need to be set to Disabled because the setting NonRemovableProfileEnabled disables the creation of an automatically signed in browser profile.

Users will not be able to sign into Microsoft Edge with an account. Signing into Edge does not automatically sync users' data, to control the availability of sync, use the SyncDisabled (Disable synchronization of data using Microsoft sync services) policy.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled: Disable browser sign-in :

Microsoft Edge\Browser sign-in settings

Impact:

Users will not be able to sign into the Microsoft Edge browser.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 5ef1ad83f03b46cf974827d70d94a4d5659a64d0edd030bdcd695dd68b9603ab