1. Home
  2. Security Hardening
  3. CIS Microsoft Edge L2 V1.0.0
  4. Ensure ‘Default Adobe Flash setting’ is set to ‘Enabled: Block the Adobe Flash plug-in’

Ensure ‘Default Adobe Flash setting’ is set to ‘Enabled: Block the Adobe Flash plug-in’

Details

This policy setting determines whether the use of Adobe Flash will be allowed for websites visited inside of Microsoft Edge.

The recommended setting is Enabled: Block the Adobe Flash plug-in

Rationale:

Adobe Flash has many known vulnerabilities which can expose a users machine to several attacks, furthermore Adobe Flash will be discontinued in the future.

Impact:

Websites using Adobe Flash will not operate as expected.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: Block the Adobe Flash plugin

Computer ConfigurationPoliciesAdministrative TemplatesMicrosoft EdgeContent settingsDefault Adobe Flash setting

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template MSEdge.admx/adml that can be downloaded from Microsoft here.

Default Value:

Not Configured – But the user can change this setting.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles