|
Policy object
|
Location
|
Recommended setting
|
Tested
|
|
Internet Explorer Processes (Zone Elevation Protection)
|
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Protection From Zone Elevation
|
Enabled
|
ok
|
|
Security Zones: Do not allow users to add/delete sites
|
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer
|
Enabled
|
ok
|
|
Security Zones: Do not allow users to change policies
|
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer
|
Enabled
|
ok
|
|
Prevent Ignoring Certificate Errors
|
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel
|
Enabled
|
ok
|
|
Internet Explorer Processes (Restrict ActiveX Install)
|
Computer Configuration\Administrative Templates\Windows Components \Internet Explorer\Security Features\Restrict ActiveX Install
|
Enabled
|
1
|
|
Allow Active Scripting
|
Computer Configuration\Administrative Templates\Windows Components \Internet Explorer\Internet Control Panel\Security Page\<zone>
|
Disabled in response to zero day attack
|
4
|
|
Internet Explorer Processes (Scripted Window Security Restrictions)
|
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Scripted Window Security Restrictions
|
Enabled
|
ok
|
|
ur non Protected Mode
|
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\<zone>
|
Enabled
|
ok
|
|
Empty Temporary Internet Files folder when browser is closed
|
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page
|
Enabled
|
ok
|
|
Disable AutoComplete for forms
|
User Configuration\Administrative Templates\Windows Components\ Internet Explorer
|
Enabled
|
ok
|
|
Turn on the auto-complete feature for user names and passwords on forms
|
User Configuration\Administrative Templates\Windows Components\ Internet Explorer
|
Disabled
|
ok
|
|
Logon Options
|
Computer Configuration\Administrative Templates\Windows Components\ Internet Explorer\Internet Control Panel\Security Page\Internet Zone
|
Enabled\Prompt for Username and Password
|
ok
|
|
Logon Options
|
Computer Configuration\Administrative Templates\Windows Components\ Internet Explorer\Internet Control Panel\Security Page\Intranet Zone
|
Enabled\Automatic Logon with Current Username and Password
|
ok
|
|
Logon Options
|
Computer Configuration\Administrative Templates\Windows Components\ Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone
|
Enabled\Anonymous Logon
|
ok
|
|
Logon Options
|
Computer Configuration\Administrative Templates\Windows Components\ Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone
|
Enabled\Automatic Logon only in Intranet Zone
|
ok
|
|
Turn off managing phishing filter
|
Computer Configuration\Administrative Templates\Windows Components\ Internet Explorer\
|
Enabled\Automatic
|
ok
|
|
Do not save encrypted pages to disk
|
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page
|
Enabled for environments with sensitive data on Web pages.
|
Ok
|
|
Disable Automatic Install of Internet Explorer components
|
Computer Configuration\Administrative Templates\Windows Components\ Internet Explorer
|
Enabled
|
ok
|
|
Disable Periodic Check for Internet Explorer software updates
|
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer
|
Enabled
|
ok
|
|
Disable software update shell notifications on program launch
|
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer
|
Enabled
|
ok
|
|
Turn off Crash Detection
|
Computer Configuration\Administrative Templates\Windows Components\ Internet Explorer
|
Enabled
|
ok
|
|
Internet Explorer Processes (Restrict File Download)
|
Computer Configuration\Administrative Templates\Windows Components \Internet Explorer\Security Features\ Restrict File Download
|
Enabled
|
ok
|
|
Allow File Downloads
|
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone
|
Disabled
|
ok
|
|
Deny all add-ons unless specifically allows in the add-on list
|
Computer Configuration\Administrative Templates\Windows Components\ Internet Explorer\Security Features\Add-on Management
|
Enabled
|
2
|
|
Add-on List
|
Computer Configuration\Administrative Templates\Windows Components\ Internet Explorer\Security Features\ Add-on Management
|
Enabled with add-ons listed
|
3
|
|
Internet Explorer Processes (Consistent MIME Handling)
|
Computer Configuration\Administrative Templates\Windows Components \Internet Explorer\Security Features\ Consistent MIME Handling
|
Enabled
|
ok
|
|
Internet Explorer Processes (MIME Sniffing)
|
Computer Configuration\Administrative Templates\Windows Components\ Internet Explorer\Security Features\ MIME Sniffing Safety Feature
|
Enabled
|
ok
|
|
Internet Explorer Processes\MK Protocol Security Restriction
|
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\MK Protocol Security Restriction
|
Enabled
|
ok
|
|
Internet Explorer Processes\Object Caching Protection
|
Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Object Caching Protection
|
Enabled
|
ok
|
|
Configure Outlook Express
|
User Configuration\Administrative Templates\Windows Components\ Internet Explorer
|
Enabled\Block attachments that could contain a virus
|
ok
|