Implementation guidance for Australian Essential Eight controls in Microsoft environments - ISM controls with PSPF mappings
| Property | Value |
|---|---|
| ISM Control | ISM-1585 |
| Revision | 2 |
| Updated | Mar-23 |
| Guideline | Not provided |
| Section | User application hardening |
| Topic | Hardening user application configurations |
| Essential Eight | ML1, ML2, ML3 |
| PSPF Levels | NC, OS, P, S, TS |
Enforce browser security settings via Intune so users cannot modify them, preventing changes that could weaken browser security1. This approach maintains consistent, enterprise-wide protections and reduces exposure to phishing, tracking and data leakage risks2.
[!NOTE] The Intune configuration profiles will enforce the browser security settings so users cannot modify them. This will implement the guidance to prevent changes to web browser configurations via Intune.
Use a Settings Catalog profile for most policies (available as MDM CSPs) and supplement with an Administrative Templates profile for Enhanced Security Mode settings not yet available in the catalog.45
| # | Policy name | Category | Recommended value | Available in Settings Catalog |
|---|---|---|---|---|
| 1 | ConfigureMicrosoftDefenderSmartScreen |
SmartScreen | Enabled | Yes |
| 2 | PreventSmartScreenPromptOverride |
SmartScreen | Enabled | Yes |
| 3 | PreventSmartScreenPromptOverrideForFiles |
SmartScreen | Enabled | Yes |
| 4 | SmartScreenBlockPotentiallyUnwantedApps |
SmartScreen | Enabled | Yes |
| 5 | SecurityZones_DoNotAllowAddDeleteSites |
Security Zones | Enabled | Yes |
| 6 | SecurityZones_DoNotAllowPolicyChanges |
Security Zones | Enabled | Yes |
| 7 | SecurityZones_UseOnlyMachineSettings |
Security Zones | Enabled | Yes |
| 8 | EnableSiteIsolationForEverySite |
Site Isolation | Enabled | Yes |
| 9 | MinimumTLSVersion |
TLS/SSL | TLS 1.2 | Yes |
| 10 | PasswordManagerEnabled |
Passwords | Disabled | Yes |
| 11 | PasswordExportEnabled |
Passwords | Disabled | Yes |
| 12 | ConfigureDoNotTrack |
Privacy | Enabled | Yes |
| 13 | AllowInPrivateBrowsing |
Privacy | Disabled | Yes |
| 14 | DeveloperToolsAvailability |
UI control | 1 — Do not allow | Yes |
| 15 | URLBlocklist |
UI control | edge://settings/*, edge://flags/* |
Yes |
| 16 | AllowExtensions |
Extensions | Disabled | Yes |
| 17 | EnhancedSecurityMode |
Enhanced Security | Enabled | ADMX only |
| 18 | EnhancedSecurityModeAllowUserBypass |
Enhanced Security | Disabled | ADMX only |
| ASD’s Blueprint for Secure Cloud describes endpoint management design decisions for Intune, including browser configuration deployment [ASD Blueprint: Endpoint management | ASD’s Blueprint for Secure Cloud](https://blueprint.asd.gov.au/design/platform/client/) |