I - Mission Critical Public
Rules and Groups employed by this XCCDF Profile
-
SRG-APP-000073
Group -
Bypassing Microsoft Defender SmartScreen prompts for sites must be disabled.
This policy setting allows a decision to be made on whether users can override the Microsoft Defender SmartScreen warnings about potentially malicious websites. If this setting is enabled, users c...Rule Medium Severity -
SRG-APP-000073
Group -
Bypassing of Microsoft Defender SmartScreen warnings about downloads must be disabled.
This policy setting allows a decision to be made on whether users can override Microsoft Defender SmartScreen warnings about unverified downloads. If this setting is enabled, users cannot ignore M...Rule Medium Severity -
SRG-APP-000073
Group -
The list of domains for which Microsoft Defender SmartScreen will not trigger warnings must be allowlisted if used.
Configure the list of Microsoft Defender SmartScreen trusted domains. This means Microsoft Defender SmartScreen will not check for potentially malicious resources, such as phishing software and oth...Rule Low Severity -
SRG-APP-000080
Group -
InPrivate mode must be disabled.
This setting specifies whether the user can open pages in InPrivate mode in Microsoft Edge. If this policy is not configured or set it to "Enabled", users can open pages in InPrivate mode. Set th...Rule Medium Severity -
SRG-APP-000141
Group -
Background processing must be disabled.
Background processing allows Microsoft Edge processes to start at OS sign-in and keep running after the last browser window is closed. In this scenario, background apps and the current browsing ses...Rule Medium Severity -
SRG-APP-000141
Group -
The ability of sites to show pop-ups must be disabled.
Set whether websites can show pop-up windows. Pop-ups can be allowed on all websites ("AllowPopups") or blocked on all sites ("BlockPopups"). If this policy is configured, pop-up windows are block...Rule Medium Severity -
SRG-APP-000141
Group -
The default search provider must be set to use an encrypted connection.
Allows a list of list of up to 10 search engines to be configured, one of which must be marked as the default search engine. The encoding does not need to be specified. Starting in Microsoft Edge 8...Rule Medium Severity -
SRG-APP-000141
Group -
Data Synchronization must be disabled.
Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing. If this policy is not set or applied as recommended, users will be able to turn s...Rule Low Severity -
SRG-APP-000141
Group -
Network prediction must be disabled.
Enables network prediction and prevents users from changing this setting. This controls DNS prefetching, TCP and SSL pre-connection, and pre-rendering of web pages. If this policy is not configur...Rule Medium Severity -
SRG-APP-000141
Group -
Search suggestions must be disabled.
Enables web search suggestions in the Microsoft Edge Address Bar and Auto-Suggest List, and prevents users from changing this policy. If this policy is enabled, web search suggestions are used. I...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.