Skip to content

II - Mission Support Sensitive

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000080

    Group
  • Browser history must be saved.

    This setting disables deleting browser history and download history and prevents users from changing this setting.
    Rule Medium Severity
  • SRG-APP-000141

    Group
  • Edge development tools must be disabled.

    While the risk associated with browser development tools is more related to the proper design of a web application, a risk vector remains within the browser. The developer tools allow end users and...
    Rule Low Severity
  • SRG-APP-000141

    Group
  • Download restrictions must be configured.

    Configure the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision. Set "BlockDangerousDownloads" to allow all downloads except for those t...
    Rule Low Severity
  • SRG-APP-000378

    Group
  • URLs must be allowlisted for plugin use if used.

    Define a list of sites, based on URL patterns that can open pop-up windows.
    Rule Low Severity
  • SRG-APP-000141

    Group
  • Extensions installation must be blocklisted by default.

    List specific extensions that users cannot install in Microsoft Edge. When this policy is deployed, any extensions on this list that were previously installed will be disabled, and the user will no...
    Rule Medium Severity
  • SRG-APP-000386

    Group
  • Extensions that are approved for use must be allowlisted if used.

    By default, all extensions are allowed. However, if all extensions are blocked by setting the "ExtensionInstallBlockList" policy to "*," users can only install extensions defined in this policy.
    Rule Low Severity
  • SRG-APP-000400

    Group
  • The Password Manager must be disabled.

    Enable Microsoft Edge to save user passwords. If this policy is enabled, users can save their passwords in Microsoft Edge. The next time the user visits the site, Microsoft Edge will enter the pas...
    Rule Medium Severity
  • SRG-APP-000456

    Group
  • The version of Microsoft Edge running on the system must be a supported version.

    Security flaws with software applications are discovered daily. Vendors are constantly updating and patching their products to address newly discovered security vulnerabilities. Organizations (incl...
    Rule High Severity
  • SRG-APP-000141

    Group
  • Site isolation for every site must be enabled.

    The "SitePerProcess" policy can be used to prevent users from opting out of the default behavior of isolating all sites. The "IsolateOrigins" policy can be used to isolate additional, finer-grained...
    Rule Medium Severity
  • SRG-APP-000142

    Group
  • Supported authentication schemes must be configured.

    This setting specifies which HTTP authentication schemes are supported. The policy can be configured by using these values: "basic", "digest", "ntlm", and "negotiate". Separate multiple values wit...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules