1.60 (L2) Ensure 'AutoLaunch Protocols Component Enabled' is set to 'Disabled'

Information

This policy setting controls the AutoLaunch Protocols Component. This component allows Microsoft to provide a list similar to the AutoLaunchProtocolsFromOrigins (Define a list of Protocols that can launch an external application from listed origins without prompting the user) policy, which allows certain external Protocols to launch without prompt or blocking certain Protocols (on specified origins).

The recommended state for this setting is: Disabled.

Allowing applications to AutoLaunch without prompting users for websites in Microsoft Edge could open an organization up to malicious sites that may capture proprietary information through the browser app.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Disabled :

Microsoft Edge\AutoLaunch Protocols Component Enabled

Impact:

Disabling this setting will prompt users whether to allow or deny Microsoft Edge to open certain links in their associated application, no protocols can launch without prompt.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-10, 800-53|CM-11, 800-53|SC-18, CSCv7|7.2

Plugin: Windows

Control ID: 61ccbd4f5360de1fec0e2a333b44ae15af54e6e0f34bbeb018172411e72f3202