1. Home
  2. Security Hardening
  3. DISA STIG Edge V1R4
  4. EDGE-00-000036 – Download restrictions must be configured.

EDGE-00-000036 – Download restrictions must be configured.

Details

Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.

Set ‘BlockDangerousDownloads’ to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings.

Set ‘BlockPotentiallyDangerousDownloads’ to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous or unwanted downloads.

Set ‘BlockAllDownloads’ to block all downloads.

If this policy is not configured or the ‘DefaultDownloadSecurity’ option set, downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.

Note that these restrictions apply to downloads from web page content, as well as the ‘download link…’ context menu option. These restrictions do not apply to saving or downloading the currently displayed page, nor do they apply to the ‘Save as PDF’ option from the printing options.

See https://go.microsoft.com/fwlink/?linkid=2094934 for more information on Microsoft Defender SmartScreen.

Policy options mapping:

– DefaultDownloadSecurity (0) = No special restrictions.

– BlockDangerousDownloads (1) = Block dangerous downloads.

– BlockPotentiallyDangerousDownloads (2) = Block potentially dangerous or unwanted downloads.

– BlockAllDownloads (3) = Block all downloads.

Solution

Set the policy value for ‘Computer Configuration/Administrative Templates/Microsoft Edge/Allow download restrictions’ to ‘Enabled’ and select ‘BlockDangerousDownloads’ or ‘Block potentially dangerous or unwanted downloads’.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles