2018-05-14 10:44:43 -07:00

80 KiB
Raw Blame History

title, description, ms.author, ms.topic, ms.prod, ms.technology, author, ms.date
title description ms.author ms.topic ms.prod ms.technology author ms.date
Policy CSP - Browser Policy CSP - Browser maricia article w10 windows MariciaAlforque 05/14/2018

Policy CSP - Browser


Browser policies

Browser/AllowAddressBarDropdown
Browser/AllowAutofill
Browser/AllowBrowser
Browser/AllowConfigurationUpdateForBooksLibrary
Browser/AllowCookies
Browser/AllowDeveloperTools
Browser/AllowDoNotTrack
Browser/AllowExtensions
Browser/AllowFlash
Browser/AllowFlashClickToRun
Browser/AllowInPrivate
Browser/AllowMicrosoftCompatibilityList
Browser/AllowPasswordManager
Browser/AllowPopups
Browser/AllowSearchEngineCustomization
Browser/AllowSearchSuggestionsinAddressBar
Browser/AllowSmartScreen
Browser/AlwaysEnableBooksLibrary
Browser/ClearBrowsingDataOnExit
Browser/ConfigureAdditionalSearchEngines
Browser/DisableLockdownOfStartPages
Browser/EnableExtendedBooksTelemetry
Browser/EnterpriseModeSiteList
Browser/EnterpriseSiteListServiceUrl
Browser/FirstRunURL
Browser/HomePages
Browser/LockdownFavorites
Browser/PreventAccessToAboutFlagsInMicrosoftEdge
Browser/PreventFirstRunPage
Browser/PreventLiveTileDataCollection
Browser/PreventSmartScreenPromptOverride
Browser/PreventSmartScreenPromptOverrideForFiles
Browser/PreventTabPreloading
Browser/PreventUsingLocalHostIPAddressForWebRTC
Browser/ProvisionFavorites
Browser/SendIntranetTraffictoInternetExplorer
Browser/SetDefaultSearchEngine
Browser/ShowMessageWhenOpeningSitesInInternetExplorer
Browser/SyncFavoritesBetweenIEAndMicrosoftEdge
Browser/UseSharedFolderForBooks

Browser/AllowAddressBarDropdown

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark2 check mark2 check mark2 check mark2 cross mark cross mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Added in Windows 10, version 1703. Specifies whether to allow the address bar drop-down functionality in Microsoft Edge. If you want to minimize network connections from Microsoft Edge to Microsoft services, we recommend disabling this functionality. 

Note

 Disabling this setting turns off the address bar drop-down functionality. Because search suggestions are shown in the drop-down list, this setting takes precedence over the Browser/AllowSearchSuggestionsinAddressBar setting.

Most restricted value is 0.

ADMX Info:

  • GP English name: Allow Address bar drop-down list suggestions
  • GP name: AllowAddressBarDropdown
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 Not allowed. Address bar drop-down is disabled, which also disables the user-defined setting, "Show search and site suggestions as I type." 
  • 1 (default) Allowed. Address bar drop-down is enabled.

Browser/AllowAutofill

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark check mark check mark check mark cross mark cross mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Specifies whether autofill on websites is allowed.

Most restricted value is 0.

ADMX Info:

  • GP English name: Configure Autofill
  • GP name: AllowAutofill
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 Not allowed.
  • 1 (default) Allowed.

To verify AllowAutofill is set to 0 (not allowed):

  1. Open Microsoft Edge.
  2. In the upper-right corner of the browser, click .
  3. Click Settings in the drop down list, and select View Advanced Settings.
  4. Verify the setting Save form entries is greyed out.

Browser/AllowBrowser

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark cross mark cross mark cross mark cross mark check mark check mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Note

 This policy is only enforced in Windows 10 Mobile and not supported in Windows 10 for desktop. For desktop devices, use the AppLocker CSP instead.

Specifies whether the browser is allowed on the device.

Most restricted value is 0.

When this policy is set to 0 (not allowed), the Microsoft Edge for Windows 10 Mobile tile will appear greyed out, and clicking on the tile will display a message indicating theat Internet browsing has been disabled by your administrator.

The following list shows the supported values:

  • 0 Not allowed.
  • 1 (default) Allowed.

Browser/AllowConfigurationUpdateForBooksLibrary

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark4 check mark4 check mark4 check mark4 cross mark cross mark

Scope:

[!div class = "checklist"]

  • User
  • Device

This policy setting lets you decide whether Microsoft Edge can automatically update the configuration data for the Books Library.

The following list shows the supported values:

  • 0 - Disable. Microsoft Edge cannot retrieve a configuration
  • 1 - Enable (default). Microsoft Edge can retrieve a configuration for Books Library

Browser/AllowCookies

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark check mark check mark check mark check mark check mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Specifies whether cookies are allowed.

Most restricted value is 0.

ADMX Info:

  • GP English name: Configure cookies
  • GP name: Cookies
  • GP element: CookiesListBox
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 Block all cookies
  • 1 Block only third party cookies
  • 2 - Allow cookies

To verify AllowCookies is set to 0 (not allowed):

  1. Open Microsoft Edge or Microsoft Edge for Windows 10 Mobile.
  2. In the upper-right corner of the browser, click .
  3. Click Settings in the drop down list, and select View Advanced Settings.
  4. Verify the setting Cookies is greyed out.

Browser/AllowDeveloperTools

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark check mark check mark check mark cross mark cross mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Note

 This policy is only enforced in Windows 10 for desktop and not supported in Windows 10 Mobile.

Specifies whether employees can use F12 Developer Tools on Microsoft Edge. Turning this setting on, or not configuring it, lets employees use F12 Developer Tools. Turning this setting off stops employees from using F12 Developer Tools.

Most restricted value is 0.

ADMX Info:

  • GP English name: Allow Developer Tools
  • GP name: AllowDeveloperTools
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 Not allowed.
  • 1 (default) Allowed.

Browser/AllowDoNotTrack

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark check mark check mark check mark check mark check mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Specifies whether Do Not Track headers are allowed.

Most restricted value is 1.

ADMX Info:

  • GP English name: Configure Do Not Track
  • GP name: AllowDoNotTrack
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 (default) Not allowed.
  • 1 Allowed.

To verify AllowDoNotTrack is set to 0 (not allowed):

  1. Open Microsoft Edge or Microsoft Edge for Windows 10 Mobile.
  2. In the upper-right corner of the browser, click .
  3. Click Settings in the drop down list, and select View Advanced Settings.
  4. Verify the setting Send Do Not Track requests is greyed out.

Browser/AllowExtensions

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark1 check mark1 check mark1 check mark1 cross mark cross mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Added in Windows 10, version 1607. Specifies whether Microsoft Edge extensions are allowed.

ADMX Info:

  • GP English name: Allow Extensions
  • GP name: AllowExtensions
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 Not allowed.
  • 1 (default) Allowed.

Browser/AllowFlash

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark check mark check mark check mark cross mark cross mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Added in Windows 10. Specifies whether Adobe Flash can run in Microsoft Edge.

ADMX Info:

  • GP English name: Allow Adobe Flash
  • GP name: AllowFlash
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 Not allowed.
  • 1 (default) Allowed.

Browser/AllowFlashClickToRun

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark2 check mark2 check mark2 check mark2 cross mark cross mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Added in Windows 10, version 1703. Specifies whether users must take an action, such as clicking the content or a Click-to-Run button, before seeing content in Adobe Flash.

ADMX Info:

  • GP English name: Configure the Adobe Flash Click-to-Run setting
  • GP name: AllowFlashClickToRun
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 Adobe Flash content is automatically loaded and run by Microsoft Edge.
  • 1 (default) Users must click the content, click a Click-to-Run button, or have the site appear on an auto-allow list before Microsoft Edge loads and runs Adobe Flash content.

Browser/AllowInPrivate

Home Pro Business Enterprise Education Mobile Mobile Enterprise
check mark check mark check mark check mark check mark check mark check mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Specifies whether InPrivate browsing is allowed on corporate networks.

Most restricted value is 0.

ADMX Info:

  • GP English name: Allow InPrivate browsing
  • GP name: AllowInPrivate
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 Not allowed.
  • 1 (default) Allowed.

Browser/AllowMicrosoftCompatibilityList

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark2 check mark2 check mark2 check mark2 check mark2 check mark2

Scope:

[!div class = "checklist"]

  • User
  • Device

Added in Windows 10, version 1703. Specifies whether to use the Microsoft compatibility list in Microsoft Edge. The Microsoft compatibility list is a Microsoft-provided list that enables sites with known compatibility issues to display properly. By default, the Microsoft compatibility list is enabled and can be viewed by visiting "about:compat".

If you enable or dont configure this setting, Microsoft Edge periodically downloads the latest version of the compatibility list from Microsoft, applying the updates during browser navigation. Visiting any site on the compatibility list prompts the employee to use Internet Explorer 11 (or enables/disables certain browser features on mobile), where the site is automatically rendered as though its run in the version of Internet Explorer necessary for it to display properly. If you disable this setting, the compatibility list isnt used during browser navigation.

Most restricted value is 0.

ADMX Info:

  • GP English name: Allow Microsoft Compatibility List
  • GP name: AllowCVList
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 Not enabled.
  • 1 (default) Enabled.

Browser/AllowPasswordManager

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark check mark check mark check mark check mark check mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Specifies whether saving and managing passwords locally on the device is allowed.

Most restricted value is 0.

ADMX Info:

  • GP English name: Configure Password Manager
  • GP name: AllowPasswordManager
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 Not allowed.
  • 1 (default) Allowed.

To verify AllowPasswordManager is set to 0 (not allowed):

  1. Open Microsoft Edge or Microsoft Edge for Windows 10 Mobile.
  2. In the upper-right corner of the browser, click .
  3. Click Settings in the drop down list, and select View Advanced Settings.
  4. Verify the settings Offer to save password and Manage my saved passwords are greyed out.

Browser/AllowPopups

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark check mark check mark check mark cross mark cross mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Specifies whether pop-up blocker is allowed or enabled.

Most restricted value is 1.

ADMX Info:

  • GP English name: Configure Pop-up Blocker
  • GP name: AllowPopups
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 (default) Pop-up blocker is not allowed. It means that pop-up browser windows are allowed.
  • 1 Pop-up blocker is allowed or enabled. It means that pop-up browser windows are blocked.

To verify AllowPopups is set to 0 (not allowed):

  1. Open Microsoft Edge.
  2. In the upper-right corner of the browser, click .
  3. Click Settings in the drop down list, and select View Advanced Settings.
  4. Verify the setting Block pop-ups is greyed out.

Browser/AllowSearchEngineCustomization

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark2 check mark2 check mark2 check mark2 check mark2 check mark2

Scope:

[!div class = "checklist"]

  • User
  • Device

Added in Windows 10, version 1703. Allows search engine customization for MDM-enrolled devices. Users can change their default search engine.     If this setting is turned on or not configured, users can add new search engines and change the default used in the address bar from within Microsoft Edge settings. If this setting is disabled, users will be unable to add search engines or change the default used in the address bar. This policy applies only on domain-joined machines or when the device is MDM-enrolled. For more information, see Microsoft browser extension policy (aka.ms/browserpolicy). 

Most restricted value is 0.

ADMX Info:

  • GP English name: Allow search engine customization
  • GP name: AllowSearchEngineCustomization
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 Not allowed.
  • 1 (default) Allowed.

Browser/AllowSearchSuggestionsinAddressBar

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark check mark check mark check mark check mark check mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Specifies whether search suggestions are allowed in the address bar.

Most restricted value is 0.

ADMX Info:

  • GP English name: Configure search suggestions in Address bar
  • GP name: AllowSearchSuggestionsinAddressBar
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 Not allowed.
  • 1 (default) Allowed.

Browser/AllowSmartScreen

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark check mark check mark check mark check mark check mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Specifies whether Windows Defender SmartScreen is allowed.

Most restricted value is 1.

ADMX Info:

  • GP English name: Configure Windows Defender SmartScreen
  • GP name: AllowSmartScreen
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 Not allowed.
  • 1 (default) Allowed.

To verify AllowSmartScreen is set to 0 (not allowed):

  1. Open Microsoft Edge or Microsoft Edge for Windows 10 Mobile.
  2. In the upper-right corner of the browser, click .
  3. Click Settings in the drop down list, and select View Advanced Settings.
  4. Verify the setting Help protect me from malicious sites and download with SmartScreen Filter is greyed out.

Browser/AlwaysEnableBooksLibrary

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark4 check mark4 check mark4 check mark4 cross mark cross mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Added in Windows 10, next majot update. Always show the Books Library in Microsoft Edge

ADMX Info:

  • GP English name: Always show the Books Library in Microsoft Edge
  • GP name: AlwaysEnableBooksLibrary
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 (default) - Disable. Use default visibility of the Books Library. The Library will be only visible in countries or regions where its available.
  • 1 - Enable. Always show the Books Library, regardless of countries or region of activation.

Browser/ClearBrowsingDataOnExit

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark2 check mark2 check mark2 check mark2 check mark2 check mark2

Scope:

[!div class = "checklist"]

  • User
  • Device

Added in Windows 10, version 1703. Specifies whether to clear browsing data on exiting Microsoft Edge.

Most restricted value is 1.

ADMX Info:

  • GP English name: Allow clearing browsing data on exit
  • GP name: AllowClearingBrowsingDataOnExit
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 (default) Browsing data is not cleared on exit. The type of browsing data to clear can be configured by the employee in the Clear browsing data options under Settings.
  • 1 Browsing data is cleared on exit.

To verify that browsing data is cleared on exit (ClearBrowsingDataOnExit is set to 1):

  1. Open Microsoft Edge and browse to websites.
  2. Close the Microsoft Edge window.
  3. Open Microsoft Edge and start typing the same URL in address bar. Verify that it does not auto-complete from history.

Browser/ConfigureAdditionalSearchEngines

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark2 check mark2 check mark2 check mark2 check mark2 check mark2

Scope:

[!div class = "checklist"]

  • User
  • Device

Added in Windows 10, version 1703. Allows you to add up to 5 additional search engines for MDM-enrolled devices.    If this policy is enabled, you can add up to 5 additional search engines for your employees. For each additional search engine you want to add, specify a link to the OpenSearch XML file that contains, at a minimum, the short name and the URL template (HTTPS) of the search engine. For more information about creating the OpenSearch XML file, see Search provider discovery. Employees cannot remove these search engines, but they can set any one as the default. This setting does not affect the default search engine. 

If this setting is not configured, the search engines used are the ones that are specified in the App settings. If this setting is disabled, the search engines you added will be deleted from your employee's machine.  

Important

Due to Protected Settings (aka.ms/browserpolicy), this setting will apply only on domain-joined machines or when the device is MDM-enrolled. 

Most restricted value is 0.

ADMX Info:

  • GP English name: Configure additional search engines
  • GP name: ConfigureAdditionalSearchEngines
  • GP element: ConfigureAdditionalSearchEngines_Prompt
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 (default) Additional search engines are not allowed.
  • 1 Additional search engines are allowed.

Browser/DisableLockdownOfStartPages

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark2 check mark2 check mark2 check mark2 cross mark cross mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Added in Windows 10, version 1703. Boolean value that specifies whether the lockdown on the Start pages is disabled. This policy works with the Browser/HomePages policy, which locks down the Start pages that the users cannot modify. You can use the DisableLockdownOfStartPages policy to allow users to modify the Start pages when the Browser/HomePages policy is in effect.    

Note

 This policy has no effect when the Browser/HomePages policy is not configured.    [!IMPORTANT] This setting can be used only with domain-joined or MDM-enrolled devices. For more information, see the Microsoft browser extension policy (aka.ms/browserpolicy).

Most restricted value is 0.

ADMX Info:

  • GP English name: Disable lockdown of Start pages
  • GP name: DisableLockdownOfStartPages
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 (default) Enable lockdown of the Start pages according to the settings specified in the Browser/HomePages policy. Users cannot change the Start pages. 
  • 1 Disable lockdown of the Start pages and allow users to modify them.

Browser/EnableExtendedBooksTelemetry

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark4 check mark4 check mark4 check mark4 cross mark cross mark

Scope:

[!div class = "checklist"]

  • User
  • Device

This policy setting lets you decide how much data to send to Microsoft about the book you're reading from the Books tab in Microsoft Edge.

If you enable this setting, Microsoft Edge sends additional diagnostic data, on top of the basic diagnostic data, from the Books tab. If you disable or don't configure this setting, Microsoft Edge only sends basic diagnostic data, depending on your device configuration.

ADMX Info:

  • GP English name: Allow extended telemetry for the Books tab
  • GP name: EnableExtendedBooksTelemetry
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 (default) - Disable. No additional diagnostic data.
  • 1 - Enable. Additional diagnostic data for schools.

Browser/EnterpriseModeSiteList

Home Pro Business Enterprise Education Mobile Mobile Enterprise
check mark check mark check mark check mark check mark cross mark cross mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Note

 This policy is only enforced in Windows 10 for desktop and not supported in Windows 10 Mobile.

  Allows the user to specify an URL of an enterprise site list.

ADMX Info:

  • GP English name: Configure the Enterprise Mode Site List
  • GP name: EnterpriseModeSiteList
  • GP element: EnterSiteListPrompt
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • Not configured. The device checks for updates from Microsoft Update.
  • Set to a URL location of the enterprise site list.

Browser/EnterpriseSiteListServiceUrl

Home Pro Business Enterprise Education Mobile Mobile Enterprise
check mark check mark check mark check mark check mark check mark check mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Important

This policy (introduced in Windows 10, version 1507) was deprecated in Windows 10, version 1511 by Browser/EnterpriseModeSiteList.


Browser/FirstRunURL

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark cross mark cross mark cross mark cross mark check mark check mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Note

 This policy is only enforced in Windows 10 Mobile and not supported in Windows 10 for desktop.

Specifies the URL that Microsoft Edge for Windows 10 Mobile. will use when it is opened the first time.

The data type is a string.

The default value is an empty string. Otherwise, the string should contain the URL of the webpage users will see the first time Microsoft Edge is run. For example, “contoso.com”.


Browser/HomePages

Home Pro Business Enterprise Education Mobile Mobile Enterprise
check mark check mark check mark check mark check mark cross mark cross mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Note

 This policy is only available for Windows 10 for desktop and not supported in Windows 10 Mobile.

Specifies your Start pages for MDM-enrolled devices. Turning this setting on lets you configure one or more corporate Start pages. If this setting is turned on, you must also include URLs to the pages, separating multiple pages by using the XML-escaped characters < and >. For example, "<support.contoso.com><support.microsoft.com>"

Starting in Windows 10, version 1607, this policy will be enforced so that the Start pages specified by this policy cannot be changed by the users.

Starting in Windows 10, version 1703, if you dont want to send traffic to Microsoft, you can use the "<about:blank>" value, which is honored for both domain- and non-domain-joined machines, when its the only configured URL. 

Note

 Turning this setting off, or not configuring it, sets your default Start pages to the webpages specified in App settings.

ADMX Info:

  • GP English name: Configure Start pages
  • GP name: HomePages
  • GP element: HomePagesPrompt
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

Browser/LockdownFavorites

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark3 check mark3 check mark3 check mark3 check mark3 check mark3

Scope:

[!div class = "checklist"]

  • User
  • Device

Added in Windows 10, version 1709. This policy setting lets you decide whether employees can add, import, sort, or edit the Favorites list on Microsoft Edge.

If you enable this setting, employees won't be able to add, import, or change anything in the Favorites list. Also as part of this, Save a Favorite, Import settings, and the context menu items (such as, Create a new folder) are all turned off.

Important

Don't enable both this setting and the Keep favorites in sync between Internet Explorer and Microsoft Edge setting. Enabling both settings stops employees from syncing their favorites between Internet Explorer and Microsoft Edge.

If you disable or don't configure this setting (default), employees can add, import and make changes to the Favorites list.

Data type is integer.

ADMX Info:

  • GP English name: Prevent changes to Favorites on Microsoft Edge
  • GP name: LockdownFavorites
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 - Disabled. Do not lockdown Favorites.
  • 1 - Enabled. Lockdown Favorites.

Browser/PreventAccessToAboutFlagsInMicrosoftEdge

Home Pro Business Enterprise Education Mobile Mobile Enterprise
check mark check mark check mark check mark check mark cross mark cross mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Specifies whether users can access the about:flags page, which is used to change developer settings and to enable experimental features.

ADMX Info:

  • GP English name: Prevent access to the about:flags page in Microsoft Edge
  • GP name: PreventAccessToAboutFlagsInMicrosoftEdge
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 (default) Users can access the about:flags page in Microsoft Edge.
  • 1 Users can't access the about:flags page in Microsoft Edge.

Browser/PreventFirstRunPage

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark2 check mark2 check mark2 check mark2 check mark2 check mark2

Scope:

[!div class = "checklist"]

  • User
  • Device

Added in Windows 10, version 1703. Specifies whether to enable or disable the First Run webpage. On the first explicit user-launch of Microsoft Edge, a First Run webpage hosted on Microsoft.com opens automatically via a FWLINK. This policy allows enterprises (such as those enrolled in a zero-emissions configuration) to prevent this page from opening.

Most restricted value is 1.

ADMX Info:

  • GP English name: Prevent the First Run webpage from opening on Microsoft Edge
  • GP name: PreventFirstRunPage
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 (default) Employees see the First Run webpage.
  • 1 Employees don't see the First Run webpage.

Browser/PreventLiveTileDataCollection

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark2 check mark2 check mark2 check mark2 check mark2 check mark2

Scope:

[!div class = "checklist"]

  • User
  • Device

Added in Windows 10, version 1703. Specifies whether Microsoft can collect information to create a Live Tile when pinning a site to Start from Microsoft Edge.

Most restricted value is 1.

ADMX Info:

  • GP English name: Prevent Microsoft Edge from gathering Live Tile information when pinning a site to Start
  • GP name: PreventLiveTileDataCollection
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 (default) Microsoft servers will be contacted if a site is pinned to Start from Microsoft Edge.
  • 1 Microsoft servers will not be contacted if a site is pinned to Start from Microsoft Edge.

Browser/PreventSmartScreenPromptOverride

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark check mark check mark check mark check mark check mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Specifies whether users can override the Windows Defender SmartScreen Filter warnings about potentially malicious websites.

Turning this setting on stops users from ignoring the Windows Defender SmartScreen Filter warnings and blocks them from going to the site. Turning this setting off, or not configuring it, lets users ignore the Windows Defender SmartScreen Filter warnings about potentially malicious websites and to continue to the site.

ADMX Info:

  • GP English name: Prevent bypassing Windows Defender SmartScreen prompts for sites
  • GP name: PreventSmartScreenPromptOverride
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 (default) Off.
  • 1 On.

Browser/PreventSmartScreenPromptOverrideForFiles

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark check mark check mark check mark check mark check mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Specifies whether users can override the Windows Defender SmartScreen Filter warnings about downloading unverified files. Turning this setting on stops users from ignoring the Windows Defender SmartScreen Filter warnings and blocks them from downloading unverified files. Turning this setting off, or not configuring it, lets users ignore the Windows Defender SmartScreen Filter warnings about unverified files and lets them continue the download process.

ADMX Info:

  • GP English name: Prevent bypassing Windows Defender SmartScreen prompts for files
  • GP name: PreventSmartScreenPromptOverrideForFiles
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 (default) Off.
  • 1 On.

Browser/PreventTabPreloading

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark4 check mark4 check mark4 check mark4

Scope:

[!div class = "checklist"]

  • User
  • Device

Added in Windows 10, version 1803. This is only a placeholder. Do not use in production code.

ADMX Info:

  • GP English name: Prevent Microsoft Edge from starting and loading the Start and New Tab page at Windows startup and each time Microsoft Edge is closed
  • GP name: PreventTabPreloading
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 (default) Allow pre-launch and preload.
  • 1 Prevent pre-launch and preload.

Browser/PreventUsingLocalHostIPAddressForWebRTC

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark check mark check mark check mark cross mark cross mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Note

 This policy is only enforced in Windows 10 for desktop and not supported in Windows 10 Mobile.

Specifies whether a user's localhost IP address is displayed while making phone calls using the WebRTC protocol. Turning this setting on hides an users localhost IP address while making phone calls using WebRTC. Turning this setting off, or not configuring it, shows an users localhost IP address while making phone calls using WebRTC.

ADMX Info:

  • GP English name: Prevent using Localhost IP address for WebRTC
  • GP name: HideLocalHostIPAddress
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 (default) The localhost IP address is shown.
  • 1 The localhost IP address is hidden.

Browser/ProvisionFavorites

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark3 check mark3 check mark3 check mark3 check mark3 check mark3

Scope:

[!div class = "checklist"]

  • User
  • Device

Added in Windows 10, version 1709. This policy setting allows you to configure a default set of favorites, which will appear for employees. Employees cannot modify, sort, move, export or delete these provisioned favorites. Specify the URL which points to the file that has all the data for provisioning favorites (in html format). You can export a set of favorites from Edge and use that html file for provisioning user machines.   URL can be specified as:

  • HTTP location: "SiteList"="http://localhost:8080/URLs.html"
  • Local network: "SiteList"="\network\shares\URLs.html"
  • Local file: "SiteList"="file:///c:\Users\\Documents\URLs.html"

Important

Don't enable both this setting and the Keep favorites in sync between Internet Explorer and Microsoft Edge setting. Enabling both settings stops employees from syncing their favorites between Internet Explorer and Microsoft Edge.

If you disable or don't configure this setting, employees will see the favorites they set in the Hub and Favorites Bar.

Data type is string.

ADMX Info:

  • GP English name: Provision Favorites
  • GP name: ConfiguredFavorites
  • GP element: ConfiguredFavoritesPrompt
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

Browser/SendIntranetTraffictoInternetExplorer

Home Pro Business Enterprise Education Mobile Mobile Enterprise
check mark check mark check mark check mark check mark cross mark cross mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Note

 This policy is only enforced in Windows 10 for desktop and not supported in Windows 10 Mobile.

Specifies whether to send intranet traffic over to Internet Explorer.

Most restricted value is 0.

ADMX Info:

  • GP English name: Send all intranet sites to Internet Explorer 11
  • GP name: SendIntranetTraffictoInternetExplorer
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 (default) Intranet traffic is sent to Internet Explorer.
  • 1 Intranet traffic is sent to Microsoft Edge.

Browser/SetDefaultSearchEngine

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark2 check mark2 check mark2 check mark2 check mark2 check mark2

Scope:

[!div class = "checklist"]

  • User
  • Device

Added in Windows 10, version 1703. Allows you configure the default search engine for your employees. By default, your employees can change the default search engine at any time. If you want to prevent your employees from changing the default search engine that you set, you can do so by configuring the AllowSearchEngineCustomization policy.

You must specify a link to the OpenSearch XML file that contains, at a minimum, the short name and the URL template (HTTPS) of the search engine. For more information about creating the OpenSearch XML file, see Search provider discovery. If you want your employees to use the Microsoft Edge factory settings for the default search engine for their market, set the string EDGEDEFAULT; otherwise, if you want your employees to use Bing as the default search engine, set the string EDGEBING.    If this setting is not configured, the default search engine is set to the one specified in App settings and can be changed by your employees. If this setting is disabled, the policy-set search engine will be removed, and, if it is the current default, the default will be set back to the factory Microsoft Edge search engine for the market.     

Important

 This setting can be used only with domain-joined or MDM-enrolled devices. For more information, see the Microsoft browser extension policy (aka.ms/browserpolicy).

Most restricted value is 0.

ADMX Info:

  • GP English name: Set default search engine
  • GP name: SetDefaultSearchEngine
  • GP element: SetDefaultSearchEngine_Prompt
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 (default) - The default search engine is set to the one specified in App settings.
  • 1 - Allows you to configure the default search engine for your employees.

Browser/ShowMessageWhenOpeningSitesInInternetExplorer

Home Pro Business Enterprise Education Mobile Mobile Enterprise
check mark check mark check mark check mark check mark cross mark cross mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Note

 This policy is only enforced in Windows 10 for desktop and not supported in Windows 10 Mobile.

Added in Windows 10, version 1607. Specifies whether users should see a full interstitial page in Microsoft Edge when opening sites that are configured to open in Internet Explorer using the Enterprise Site List.

Most restricted value is 0.

ADMX Info:

  • GP English name: Show message when opening sites in Internet Explorer
  • GP name: ShowMessageWhenOpeningSitesInInternetExplorer
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 (default) Interstitial pages are not shown.
  • 1 Interstitial pages are shown.

Browser/SyncFavoritesBetweenIEAndMicrosoftEdge

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark2 check mark2 check mark2 check mark2 cross mark cross mark

Scope:

[!div class = "checklist"]

  • User
  • Device

Added in Windows 10, version 1703. Specifies whether favorites are kept in sync between Internet Explorer and Microsoft Edge. Changes to favorites in one browser are reflected in the other, including: additions, deletions, modifications, and ordering.

Note

 This policy is only enforced in Windows 10 for desktop and not supported in Windows 10 Mobile.

Enabling this setting stops Microsoft Edge favorites from syncing between connected Windows 10 devices.

ADMX Info:

  • GP English name: Keep favorites in sync between Internet Explorer and Microsoft Edge
  • GP name: SyncFavoritesBetweenIEAndMicrosoftEdge
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 (default) Synchronization is off.
  • 1 Synchronization is on.

To verify that favorites are in synchronized between Internet Explorer and Microsoft Edge:

  1. Open Internet Explorer and add some favorites.
  2. Open Microsoft Edge, then select Hub > Favorites.
  3. Verify that the favorites added to Internet Explorer show up in the favorites list in Microsoft Edge.

Browser/UseSharedFolderForBooks

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark4 check mark4 check mark4 check mark4 cross mark cross mark

Scope:

[!div class = "checklist"]

  • User
  • Device

This setting specifies whether organizations should use a folder shared across users to store books from the Books Library.

ADMX Info:

  • GP English name: Allow a shared Books folder
  • GP name: UseSharedFolderForBooks
  • GP path: Windows Components/Microsoft Edge
  • GP ADMX file name: MicrosoftEdge.admx

The following list shows the supported values:

  • 0 - No shared folder.
  • 1 - Use a shared folder.

Footnote:

  • 1 - Added in Windows 10, version 1607.
  • 2 - Added in Windows 10, version 1703.
  • 3 - Added in Windows 10, version 1709.
  • 4 - Added in Windows 10, version 1803.

Browser policies that can be set using Exchange Active Sync (EAS)

Browser policies supported by Windows Holographic for Business

Browser policies supported by IoT Core

Browser policies supported by Microsoft Surface Hub