Microsoft Edge: Changes to local IP address detection for proxy auto-config (PAC) scripts
🚨 The Signal: Microsoft Edge updated how it detects local IP addresses for proxy auto-config (PAC) scripts, aligning with Chromium defaults. Administrators can now override these defaults, which is critical for network routing and security policy enforcement.
The Impact
Network and security teams are affected, with a risk of misrouted traffic or bypassed security controls if not configured correctly.
- Network Administrators: May need to update PAC script configurations to ensure correct routing.
- Security Teams: Risk of misrouted traffic bypassing security controls if policies are not applied.
- End Users: Potential for network connectivity issues if proxy settings are not correctly managed.
- Compliance Officers: Need to verify network configurations align with ISM and PSPF requirements.
The Action
- Review existing PAC script configurations and network routing requirements.
- Evaluate the impact of the new default IPv4 and IPv6 probe destinations.
- If necessary, deploy PacMyIpAddressIPv4ProbeAddress policy via Group Policy or Intune.
- If necessary, deploy PacMyIpAddressIPv6ProbeAddress policy via Group Policy or Intune.
- Test network connectivity and proxy functionality for affected user groups.
Domain: Other · Impact: high · Workload: M365 Apps · Essential Eight: User Application Hardening · ISM: ISM-1412, ISM-1485, ISM-1486, ISM-1542, ISM-1585, ISM-1667, ISM-1668, ISM-1669, ISM-1670, ISM-1823, ISM-1824, ISM-1859, ISM-1860