7732d84e-90be-4734-bae5-e3c6d3be7568
It's best practice to configure Internet Explorer to enforce the verification of signatures for downloaded files, and to disallow running or installing files when an invalid signature is detected. This identifies the publisher of signed software and verifies it hasn't been modified or tampered with.
https://www.stigviewer.com/stig/microsoft_internet_explorer_11/2018-06-08/finding/V-46625
This setting can be enabled via GPO.
Stig IE: https://www.stigviewer.com/stig/microsoft_internet_explorer_11/2018-06-08/finding/V-46625