STIGQter STIGQter: STIG Summary: Microsoft Windows 11 Security Technical Implementation Guide Version: 2 Release: 8 Benchmark Date: 01 Jul 2026:

Internet Explorer must be disabled for Windows 11.

DISA Rule

SV-256893r958552_rule

Vulnerability Number

V-256893

Group Title

SRG-OS-000185-GPOS-00079

Rule Version

WN11-CC-000391

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

For Windows 11 semi-annual channel, remove or disable the IE11 application.

To disable IE11 as a standalone browser:

Set the policy value for "Computer Configuration/Administrative Templates/Windows Components/Internet Explorer/Disable Internet Explorer 11 as a standalone browser" to "Enabled" with the option value set to "Never".

Check Contents

Determine if IE11 is installed or enabled on Windows 11 semi-annual channel.

If IE11 is installed or not disabled on Windows 11 semi-annual channel, this is a finding.

If IE11 is installed on an unsupported operating system and is enabled or installed, this is a finding.

For more information, visit: https://learn.microsoft.com/en-us/lifecycle/faq/internet-explorer-microsoft-edge#what-is-the-lifecycle-policy-for-internet-explorer-

Vulnerability Number

V-256893

Documentable

False

Rule Version

WN11-CC-000391

Severity Override Guidance

Determine if IE11 is installed or enabled on Windows 11 semi-annual channel.

If IE11 is installed or not disabled on Windows 11 semi-annual channel, this is a finding.

If IE11 is installed on an unsupported operating system and is enabled or installed, this is a finding.

For more information, visit: https://learn.microsoft.com/en-us/lifecycle/faq/internet-explorer-microsoft-edge#what-is-the-lifecycle-policy-for-internet-explorer-

Check Content Reference

M

Target Key

5471