1.13.3 (L2) Ensure 'Supported authentication schemes' is set to 'Enabled: ntlm, negotiate'

Information

This setting specifies what HTTP authentication methods are supported by Microsoft Edge.

The recommended setting is: Enabled: ntlm, negotiate.

Basic and Digest authentication do not provide sufficient security and can lead to submission of user's password in plaintext or minimal protection (Integrated Authentication is supported for negotiate and ntlm challenges only).

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled: ntlm, negotiate :

Microsoft Edge\HTTP authentication\Supported authentication schemes

Impact:

Any sites that utilize Basic or Digest Authentication will be impacted. Sites will need to be reconfigured to support a more secure form of authentication.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-17(2), 800-53|IA-5, 800-53|IA-5(1), 800-53|SC-8, 800-53|SC-8(1), CSCv7|14.4

Plugin: Windows

Control ID: 43bb8b8f17a98edb5efcc7086014bf02cdfcb8c59ee588439e2fe268222b793e