| Where Can I Use This? | What Do I Need? |
Anti-exploitation controls enable you to reduce the potential attack
surface of the browser. These controls effectively limit usage of browser components
that are complex and are occasionally found to contain vulnerabilities. While the
latest version of the browser would never include known vulnerabilities, disabling
unnecessary components limits the potential exposure between when a vulnerability is
found and the time it is fixed.
You should be aware that by disabling these components, you may impact some
web page functionality. To minimize the impact on end-users, a non-intrusive dialog
will be displayed if a capability is canceled. You need to be aware of these dialogs
and the corresponding events in case users report issues with web pages. For
example, disabling WebGL may impact functionality of an online maps website. When
the users complain, you can identify the issue by looking for corresponding events
and dialogs when users browse to these sites.
When a web page is affected by a disabled component, an abbreviated message
is shown. The message will pop up again every 2 hours if you revisit the website.
The system will also generate a log event.
The Configure Protected Browsing options contains the following controls: