EDGE-00-000036 - Download restrictions must be configured.

Information

This configures the type of downloads that Microsoft Edge completely blocks without allowing users to override the security decision.

Set 'BlockDangerousDownloads' to allow all downloads except those that carry Microsoft Defender SmartScreen warnings of known dangerous downloads or that have dangerous file type extensions.

Set 'BlockPotentiallyDangerousDownloads' to allow all downloads except those that carry Microsoft Defender SmartScreen warnings of potentially dangerous or unwanted downloads or that have dangerous file type extensions.

Set 'BlockAllDownloads' to block all downloads.

Set 'BlockMaliciousDownloads' to allow all downloads except those that carry Microsoft Defender SmartScreen warnings of known malicious downloads.

If this policy is not configured or the 'DefaultDownloadSecurity' option is not set, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.

Policy options mapping:

DefaultDownloadSecurity (0) = No special restrictions

BlockDangerousDownloads (1) = Block malicious downloads and dangerous file types

BlockPotentiallyDangerousDownloads (2) = Block potentially dangerous or unwanted downloads and dangerous file types

BlockAllDownloads (3) = Block all downloads

BlockMaliciousDownloads (4) = Block malicious downloads

Solution

Set the policy value for 'Computer Configuration/Administrative Templates/Microsoft Edge/Allow download restrictions' to 'Enabled' and select one of the following: 'BlockDangerousDownloads', 'Block potentially dangerous or unwanted downloads', 'BlockAllDownloads', or 'BlockMaliciousDownloads'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Edge_V2R3_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|III, CCI|CCI-000381, Rule-ID|SV-235752r1106675_rule, STIG-ID|EDGE-00-000036, Vuln-ID|V-235752

Plugin: Windows

Control ID: d59da37ea5e8d1bf5191a781bb05df2cab7d4044919b4c6bb13a9864d82cdac0