ASD's Blueprint for Secure Cloud

ASD Edge hardening

This section describes the settings for device configuration policies within Microsoft Intune associated with systems built according to the guidance provided by ASD's Blueprint for Secure Cloud.

Estimated reading time: 12 minutes

Basics

ItemValue
NameASD Edge hardening
DescriptionNone
PlatformWindows 10 and later

Assignments

Included groups

ItemValue
GroupsAll devices

Excluded groups

ItemValue
GroupsNo groups selected

Scope tags

ItemValue
Scope tagsDefault

Configuration settings

Deployment and updates

ItemValue
Allow installationEnabled
- Install Policy (Device)Force Installs (Machine-Wide)
Allow users in the Windows Insider Program to be enrolled in Edge PreviewDisabled
Auto-update check period overrideEnabled
- Minutes between update checks (Device)60
Control updater’s communication with the Experimentation and Configuration ServiceEnabled
- Control updater’s communication with the Experimentation and Configuration Service (Device)Disable communication with the Experimentation and Configuration Service
Let users update on metered connectionsEnabled
- Let users update on metered connections (Device)Metered Updates Allowed
Notify a user that a browser restart is recommended or required for pending updatesEnabled
- Notify a user that a browser restart is recommended or required for pending updates (Device)Required - Show a recurring prompt to the user indicating that a restart is required
Relaunch browser quickly when the current version is outdatedEnabled
- Relaunch browser quickly when the current version is outdated (Device)7
Set the time period for update notificationsEnabled
- Set the time period for update notifications (Device)86400000
Target Channel overrideEnabled
- Target Channel (Device)Stable
Update policy overrideEnabled
- Policy (Device)Automatic silent updates only

Developer and debugging controls

ItemValue
Allow remote debuggingDisabled
Control the availability of developer mode on extensions pageEnabled
- Control the availability of developer mode on extensions page (Device)Do not allow the usage of developer mode on extensions page
Control where developer tools can be usedEnabled
- Control where developer tools can be used (Device)Don’t allow using the developer tools

Browser integrity protections

ItemValue
Allow import of data from other browsers on each Microsoft Edge launchDisabled
Allow importing of autofill form dataDisabled
Allow importing of CookiesDisabled
Allow importing of extensionsDisabled
Allow importing of payment infoDisabled
Allow importing of saved passwords1Disabled
Automatically import another browser’s data and settings at first runEnabled
- Automatically import another browser’s data and settings at first run (Device)Disables automatic import, and the import section of the first-run experience is skipped
Block access to a list of URLsEnabled
- Block access to a list of URLs (Device)edge://inspect, edge://net-export, edge://tracing
Configure users ability to override feature flagsEnabled
- Configure users ability to override feature flags (Device)Prevent users from overriding feature flags

Enhanced Security Mode

ItemValue
Allow users to bypass Enhanced Security ModeDisabled
Configure the list of domains for which enhance security mode will always be enforcedEnabled
- Configure the list of domains for which enhance security mode will always be enforced (Device)<high-risk-domains>
Configure the list of domains for which enhance security mode will not be enforcedEnabled
- Configure the list of domains for which enhance security mode will not be enforced (Device)<trusted-domains>
Enhance the security state in Microsoft EdgeEnabled
- Enhance the security state in Microsoft Edge (Device)Balanced mode

Microsoft Defender SmartScreen

ItemValue
Configure the list of domains for which Microsoft Defender SmartScreen won’t trigger warningsEnabled
- Configure the list of domains for which Microsoft Defender SmartScreen won’t trigger warnings (Device)<trusted-domains>
Enable Microsoft Defender SmartScreen DNS requestsEnabled
Force Microsoft Defender SmartScreen checks on downloads from trusted sourcesEnabled
Prevent bypassing Edge Website Typo Protection prompts for sitesEnabled
Scareware Blocker
ItemValue
Configure Edge Scareware blocker protection1Enabled
Configure Edge scareware blocker to block sites detected as potential tech scams1Enabled
Configure Edge Scareware blocker to share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreenEnabled
Download security
ItemValue
Allow download restrictionsEnabled
- Download restrictions (Device)Block potentially dangerous or unwanted downloads and dangerous file types
Enable insecure download warningsEnabled

Network and transport security

ItemValue
Control the mode of DNS-over-HTTPSEnabled
- Control the mode of DNS-over-HTTPS (Device)Disable DNS-over-HTTPS
Control use of insecure content exceptionsEnabled
- Control use of insecure content exceptions (Device)Don’t allow any site to load mixed content
Intranet Redirection BehaviorEnabled
- Intranet Redirection Behavior (Device)Disable DNS interception checks; allow did-you-mean “http://intranetsite/” infobars

Local Network Access restrictions

ItemValue
Allow sites to make network requests to local network endpoints.Enabled
- Allow sites to make network requests to local network endpoints. (Device)<allowed-origins>
Allow sites to make network requests to the local device.Enabled
- Allow sites to make network requests to the local device. (Device)<allowed-origins>
Block sites from making network requests to local network endpoints.Enabled
- Block sites from making network requests to local network endpoints. (Device)*
Block sites from making network requests to the local device.Enabled
- Block sites from making network requests to the local device. (Device)*

Extension policy

ItemValue
Allow specific extensions to be installedEnabled
- Allow specific extensions to be installed (Device)<approved-extension-ids>
Blocklist for extension install typesEnabled
- Blocklist for extension install types (Device)command_line, sideload
Blocks external extensions from being installedEnabled
Configure allowed extension typesEnabled
- Configure allowed extension types (Device)extension, theme
Configure extension management settingsEnabled
- Configure extension management settings (Device)<extension-settings.json>
Control Manifest v2 extension availabilityEnabled
- Control Manifest v2 extension availability (Device)Manifest v2 is enabled for forced extensions only
Control which extensions are installed silentlyEnabled
- Control which extensions are installed silently (Device)<mandatory-extension-id>;https://edge.microsoft.com/extensionwebstorebase/v1/crx

Profiles and profile sign-in

ItemValue
Browser sign-in settingsEnabled
- Browser sign-in settings (Device)Enable browser sign-in
Configure whether a user always has a default profile automatically signed in with their work or school accountEnabled
Enable implicit sign-inEnabled
Enable sign-in to Microsoft Edge using non-Microsoft accountsDisabled
Restrict which accounts can be used to sign in to Microsoft EdgeEnabled
- Restrict which accounts can be used to sign in to Microsoft Edge (Device).*@<organisation.gov.au>$

Enterprise sync

ItemValue
Configure the list of types that are excluded from synchronizationEnabled
- Configure the list of types that are excluded from synchronization (Device)passwords, autofill, payments, history, openTabs, extensions

Guest mode and InPrivate browsing

ItemValue
Enable guest modeDisabled
Specify extensions users must allow in order to navigate using InPrivate modeEnabled
- Specify extensions users must allow in order to navigate using InPrivate mode (Device)<extension-ids>

Session persistence and exit behaviour

ItemValue
Browsing Data Lifetime SettingsEnabled
- Browsing Data Lifetime Settings (Device)<browsing-data-lifetime.json>
Clear cached images and files when Microsoft Edge closes1Disabled
Continue running background apps after Microsoft Edge closes1Disabled
Enable startup boostDisabled

Edge password manager and passkeys

Where a dedicated enterprise password management solution is deployed:

ItemValue
Allow users to be alerted if their passwords are found to be unsafeDisabled
Allow users to get a strong password suggestion whenever they are creating an account onlineDisabled
Enable AutoFill for addressesDisabled
Enable AutoFill for payment instrumentsDisabled
Enable exporting saved passwords from Password ManagerDisabled
Enable saving passkeys to the password managerDisabled
Enable saving passwords to the password managerDisabled

Where the Edge password manager is permitted:

ItemValue
Allow users to be alerted if their passwords are found to be unsafeEnabled
Allow users to get a strong password suggestion whenever they are creating an account online1Enabled
Configure the list of domains for which the password manager UI (Save and Fill) will be disabledEnabled
- Configure the list of domains for which the password manager UI (Save and Fill) will be disabled (Device)<privileged-portal-domains>
Configures a setting that asks users to enter their device password while using password autofillEnabled
- Configures a setting that asks users to enter their device password while using password autofill (Device)With device password
Enable AutoFill for addresses1Enabled
Enable AutoFill for payment instrumentsDisabled
Enable exporting saved passwords from Password ManagerDisabled
Enable saving passkeys to the password managerDisabled
Enable saving passwords to the password manager1Enabled

User experience and compatibility

ItemValue
Action to take on Microsoft Edge startupEnabled
- Action to take on Microsoft Edge startup (Device)Open a list of URLs
Block third party cookiesEnabled
Block tracking of users’ web-browsing activity1Enabled
- Block tracking of users’ web-browsing activity (Device)Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)
Configure Internet Explorer integrationEnabled
- Configure Internet Explorer integration (Device)Internet Explorer mode
Configure the Enterprise Mode Cloud Site ListEnabled
- Configure the Enterprise Mode Cloud Site List (Device)<site-list-guid>
Configure the home page URLEnabled
- Configure the home page URL (Device)https://<intranet>
Default search provider nameEnabled
- Default search provider name (Device)<search-provider-name>
Default search provider search URLEnabled
- Default search provider search URL (Device)<search-provider-url>
Enable clipboard suggestions in the address barDisabled
Enable Microsoft Bing trending suggestions in the address barDisabled
Enable search suggestionsDisabled
Enable the default search providerEnabled
Restrict exposure of local IP address by WebRTCEnabled
- Restrict exposure of local IP address by WebRTC (Device)Allow public interface over http default route. This doesn’t expose the local IP address
Set the new tab page as the home pageDisabled
Sites to open when the browser startsEnabled
- Sites to open when the browser starts (Device)https://<intranet>

The Edge sidebar

ItemValue
Enable open in sidebarDisabled
Enable sidebar customizeDisabled
Show Hubs SidebarDisabled

Feature minimisation and interface reduction

ItemValue
Ads setting for sites with intrusive ads1Enabled
- Ads setting for sites with intrusive ads (Device)Block ads on sites with intrusive ads
Allow feature recommendations and browser assistance notifications from Microsoft EdgeDisabled
Allow Microsoft content on the new tab pageDisabled
Allow websites to query for available payment methodsDisabled
Choose whether users can receive customized background images and text, suggestions, notifications, and tips for Microsoft servicesDisabled
Configure if the ads transparency feature is enabledDisabled
Configure the background types allowed for the new tab page layoutEnabled
- Configure the background types allowed for the new tab page layout (Device)Disable all background image types
Enable Google CastDisabled
Enable tab organization suggestionsDisabled
Enable upload files from mobile in Microsoft Edge desktopDisabled
Enable WorkspacesDisabled
Enables default browser settings campaignsDisabled
Enables Microsoft Edge mini menuDisabled
Hide App Launcher on Microsoft Edge new tab pageDisabled
Hide the default top sites from the new tab pageEnabled
Shopping in Microsoft Edge EnabledDisabled
Show Microsoft Rewards experiencesDisabled
Visual search enabledDisabled
Browser-native AI features
ItemValue
Allow pages to use the built-in AI APIs.Disabled
Automatically open Copilot side pane with contextual insights for links opened from OutlookDisabled
Compose is enabled for writing on the webDisabled
Control access to AI-enhanced search in HistoryDisabled
Control Copilot access to Microsoft Edge page content, browsing history, and video transcript for Entra account user profiles when using Copilot in the Microsoft Edge sidepaneDisabled
Control Copilot access to page context for Microsoft Entra ID profilesDisabled
Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbarEnabled
Controls the availability of browsing with Copilot in Microsoft Edge.1Disabled
Enable Copilot address bar suggestionsDisabled
Enable the Copilot new tab page1Disabled
Enables DALL-E themes generationDisabled
Settings for GenAI local foundational modelEnabled
- Settings for GenAI local foundational model (Device)Do not download model

Diagnostic data and telemetry

ItemValue
Allow features to download assets from the Asset Delivery ServiceDisabled
Allow personalization of ads, search and news by sending browsing history to MicrosoftDisabled
Allow user feedbackDisabled
Control communication with the Experimentation and Configuration ServiceEnabled
- Control communication with the Experimentation and Configuration Service (Device)Disable communication with the Experimentation and Configuration Service
Edge 3P SERP Telemetry EnabledDisabled
Enable resolution of navigation errors using a web serviceDisabled
Enable Windows to search local Microsoft Edge browsing dataDisabled
Send required and optional diagnostic data about browser usageEnabled
- Send required and optional diagnostic data about browser usage (Device)Off (Not recommended)
Suggest similar pages when a webpage can’t be foundDisabled
URL reporting in Edge diagnostic data enabledDisabled

Edge WebView2

ItemValue
Control communication with the Experimentation and Configuration ServiceEnabled
- Control communication with the Experimentation and Configuration Service (Device)Disable communication with the Experimentation and Configuration Service
Update policy overrideEnabled
- Update policy override (Device)Always allow updates

1: The setting matches the default (not configured) but removes the ability of a user to change it.

Security and governance

Design

Configuration

References

Do you have a suggestion on how the above page could be improved? Get in touch! ASD's Blueprint for Secure Cloud is an open source project, and we would love to get your input. Submit an issue on our GitHub, or send us an email at [email protected]

Acknowledgement of Country icon

Acknowledgement of Country
We acknowledge the Traditional Owners and Custodians of Country throughout Australia and their continuing connections to land, sea and communities. We pay our respects to them, their cultures and their Elders; past, present and emerging. We also recognise Australia's First Peoples' enduring contribution to Australia's national security.

Authorised by the Australian Government, Canberra