1.46 (L2) Ensure 'Allow or block audio capture' is set to 'Disabled'

Information

This policy setting configures whether the end-user is prompted for access to audio capture devices.

The recommended state for this setting is: Disabled.

Note: The AudioCaptureAllowedUrls setting will need to be configured along with this setting if this feature is needed for specific websites.

With the end-user having the ability to allow or deny audio capture for websites in Microsoft Edge, could open an organization up to a malicious site that may capture proprietary information through the browser. By limiting or disallowing this setting, it removes the end-user's discretion leaving it up to the organization as to the sites allowed to use this ability.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Disabled

Microsoft Edge\Allow or block audio capture

Impact:

Users will not be prompted by audio devices when using websites which may need this access, for example a web-based conferencing system. If there are sites which access will be allowed, this will need to be configured in the AudioCaptureAllowedUrls setting.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: e7422ded7ca0b77cc7a750af786655a85239e318dce8b51284932ce4cbca29e2