Implementation guidance for Australian Essential Eight controls in Microsoft environments - ISM controls with PSPF mappings
| Property | Value |
|---|---|
| ISM Control | ISM-1485 |
| Revision | 1 |
| Updated | Sep-21 |
| Guideline | Not provided |
| Section | User application hardening |
| Topic | Hardening user application configurations |
| Essential Eight | ML1, ML2, ML3 |
| PSPF Levels | NC, OS, P, S, TS |
Enable Edge policy to block intrusive ads using the Intune security baseline by configuring Ads setting for sites with intrusive ads to Enabled, reducing exposure to potentially malicious advertising and supporting browser hardening. 1
The built-in Edge AdsSettingForIntrusiveAdsSites policy blocks only intrusive ad formats defined by the IAB standard (e.g., large pop-ups, auto-play video overlays, ads that obscure content). It does not block all web advertisements. For Maturity Level 3 or where a stricter interpretation of “does not process web advertisements” is required, this must be supplemented with a policy-deployed ad-blocking extension or enterprise DNS filtering at the network layer.2
Not provided in source documentation.
[!NOTE] The Ads setting for sites with intrusive ads policy will be enabled using the Intune security baseline to block intrusive ads in Microsoft Edge. This will be aligned with the control’s intent to prevent web advertisements from being processed by browsers.
AdsSettingForIntrusiveAdsSites).1).PopupsAllowed = Blocked)SmartScreenEnabled) = Enabled[!NOTE] The
AdsSettingForIntrusiveAdsSitespolicy blocks only intrusive ad formats as defined by the IAB Better Ads Standards. It does not prevent all web advertisements from loading. For environments requiring a stricter interpretation of this control, supplement with a policy-deployed ad-blocking extension (see below).
For ML3 or audit-strict environments where all advertisements must be prevented: