Check: EDGE-00-000005
Microsoft Edge STIG:
EDGE-00-000005
(in versions v1 r8 through v1 r1)
Title
InPrivate mode must be disabled. (Cat II impact)
Discussion
This setting specifies whether the user can open pages in InPrivate mode in Microsoft Edge. If this policy is not configured or set it to "Enabled", users can open pages in InPrivate mode. Set this policy to "Disabled" to stop users from using InPrivate mode. Set this policy to "Forced" to always use InPrivate mode. Policy options mapping: - Enabled (0) = InPrivate mode available - Disabled (1) = InPrivate mode disabled - Forced (2) = InPrivate mode forced
Check Content
The policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Configure InPrivate mode availability" must be set to "enabled" with the option value set to "InPrivate mode disabled". Use the Windows Registry Editor to navigate to the following key: HKLM\SOFTWARE\Policies\Microsoft\Edge If the value for "InPrivateModeAvailability" is not set to "REG_DWORD = 1", this is a finding.
Fix Text
Set the policy value for "Computer Configuration/Administrative Templates/Microsoft Edge/Configure InPrivate mode availability" to "enabled" and select "InPrivate mode disabled".
Additional Identifiers
Rule ID: SV-235723r879554_rule
Vulnerability ID: V-235723
Group Title: SRG-APP-000080
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000166 |
The information system protects against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation. |
Controls
Number | Title |
---|---|
AU-10 |
Non-Repudiation |