Microsoft Edge
AdsSettingForIntrusiveAdsSites Ads setting for sites with intrusive ads
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AdsSettingForIntrusiveAdsSites
- Supported on
- Microsoft Edge version 78, Windows 7 or later
- Template
- msedge.admx
1Allow ads on all sites2Block ads on sites with intrusive ads. (Default value)Controls whether ads are blocked on sites with intrusive ads. Policy options mapping: * AllowAds (1) = Allow ads on all sites * BlockAds (2) = Block ads on sites with intrusive ads. (Default value) Use the preceding information when configuring this policy.
InPrivateModeUrlAllowlist Allow access to a list of URLs in InPrivate mode.
If this policy is configured and 'InPrivateModeUrlBlocklist' is not configured, only the URLs specified in this allowlist can be opened in InPrivate mode. If this policy is not configured, no exceptions are applied to 'InPrivateModeUrlBlocklist' or 'InPrivateModeAvailability'.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\InPrivateModeUrlAllowlist
- Supported on
- Microsoft Edge version 147, Windows 7 or later
- Template
- msedge.admx
This policy allows administrators to specify a list of URL patterns that are permitted to open in InPrivate mode. It can be used to create exceptions for URL patterns defined in 'InPrivateModeUrlBlocklist' (Block access to a list of URLs in InPrivate mode.). See how to format a URL pattern (https://go.microsoft.com/fwlink/?linkid=2095322). If both this policy and 'InPrivateModeUrlBlocklist' are configured, the allowlist takes precedence. URLs that match a pattern on this allowlist are allowed. URLs that match the blocklist but not this allowlist are blocked. URLs that match neither list fall back to 'URLBlocklist' (Block access to a list of URLs) and 'URLAllowlist' (Define a list of allowed URLs). If this policy is configured and 'InPrivateModeUrlBlocklist' is not configured, only the URLs specified in this allowlist can be opened in InPrivate mode. All other URLs are blocked. If 'InPrivateModeAvailability' (Configure InPrivate mode availability) is set to disallow (value 1) but this policy is configured, InPrivate mode is available only for URLs that match the allowlist. If this policy is not configured, no exceptions are applied to 'InPrivateModeUrlBlocklist' or 'InPrivateModeAvailability'. This policy applies only to InPrivate mode. To allow URLs across all browsing modes and profiles, use the 'URLAllowlist' policy. This policy supports up to 1000 entries. Example value: example.com https://ssl.server.com hosting.com/bad_path https://server:8080/path .exact.hostname.com file://* custom_scheme:* *
SensorsAllowedForUrls Allow access to sensors on specific sites
If you don't configure this policy, the global default value from the 'DefaultSensorsSetting' (Default sensors setting) policy (if set) or the user's personal configuration is used for all sites.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\SensorsAllowedForUrls
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
Define a list of sites, based on URL patterns, that can access and use sensors such as motion and light sensors. If you don't configure this policy, the global default value from the 'DefaultSensorsSetting' (Default sensors setting) policy (if set) or the user's personal configuration is used for all sites. For URL patterns that don't match this policy, the following order of precedence is used: The 'SensorsBlockedForUrls' (Block access to sensors on specific sites) policy (if there's a match), the 'DefaultSensorsSetting' policy (if set), or the user's personal settings. The URL patterns defined in this policy can't conflict with those configured in the 'SensorsBlockedForUrls' policy. You can't allow and block a URL. For detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Example value: https://www.contoso.com [*.]contoso.edu
EnterpriseModeSiteListManagerAllowed Allow access to the Enterprise Mode Site List Manager tool
If you disable or don't configure this policy, users can't see the Enterprise Mode Site List Manager nav button and can't use it.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EnterpriseModeSiteListManagerAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
Allows you to set whether Enterprise Mode Site List Manager is available to users. If you enable this policy, users can see the Enterprise Mode Site List Manager nav button on edge://compat page, navigate to the tool, and use it. If you disable or don't configure this policy, users can't see the Enterprise Mode Site List Manager nav button and can't use it.
EnableSha1ForLocalAnchors Allow certificates signed using SHA-1 when issued by local trust anchors (obsolete)
If you disable or don't configure this policy, or if the SHA-1 certificate chains to a publicly trusted certificate root, then Microsoft Edge won't allow certificates signed by SHA-1.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EnableSha1ForLocalAnchors
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 85-91, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 91. If you enable this policy, Microsoft Edge allows connections secured by SHA-1 signed certificates so long as the certificate chains to a locally installed root certificate and is otherwise valid. This policy depends on the operating system (OS) certificate verification stack allowing SHA-1 signatures. If an OS update changes the OS handling of SHA-1 certificates, this policy might no longer have effect. Further, this policy is intended as a temporary workaround to give enterprises more time to move away from SHA-1. This policy will be removed in Microsoft Edge 92 releasing in mid 2021. If you disable or don't configure this policy, or if the SHA-1 certificate chains to a publicly trusted certificate root, then Microsoft Edge won't allow certificates signed by SHA-1. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.
ClipboardAllowedForUrls Allow clipboard use on specific sites
Leaving the policy unset means 'DefaultClipboardSetting' (Default clipboard site permission) applies for all sites if it's set.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ClipboardAllowedForUrls
- Supported on
- Microsoft Edge version 109, Windows 7 or later
- Template
- msedge.admx
Configure the list of URL patterns that specify which sites can use the clipboard site permission. Setting the policy lets you create a list of URL patterns that specify which sites can use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users can still paste using keyboard shortcuts because this isn't controlled by the clipboard site permission. Leaving the policy unset means 'DefaultClipboardSetting' (Default clipboard site permission) applies for all sites if it's set. If it isn't set, the user's personal setting applies. For more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
DefaultSearchProviderContextMenuAccessAllowed Allow default search provider context menu search access
If you enable or don't configure this policy, the context menu item for your default search provider and sidebar search is available.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultSearchProviderContextMenuAccessAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 85, Windows 7 or later
- Template
- msedge.admx
Enables the use of a default search provider on the context menu. If you disable this policy, the search context menu item that relies on your default search provider and sidebar search isn't available. If you enable or don't configure this policy, the context menu item for your default search provider and sidebar search is available. The policy value is only applied when the 'DefaultSearchProviderEnabled' (Enable the default search provider) policy is enabled, and isn't applicable otherwise.
AdditionalDnsQueryTypesEnabled Allow DNS queries for more DNS record types
If this policy is unset or set to Enabled, more record types such as HTTPS (DNS type 65) may be queried in addition to A (DNS type 1) and AAAA (DNS type 28).
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AdditionalDnsQueryTypesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 140, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Microsoft Edge can query more DNS record types when making insecure (non-Secure DNS) requests. If this policy is unset or set to Enabled, more record types such as HTTPS (DNS type 65) may be queried in addition to A (DNS type 1) and AAAA (DNS type 28). If this policy is set to Disabled, Microsoft Edge will only query A and AAAA record types for insecure DNS requests. This setting doesn't affect DNS queries made via Secure DNS, which may always use more record types. Note: This is a temporary policy and is planned for removal in a future version of Microsoft Edge. After removal, Microsoft Edge will always be able to query more DNS types during insecure requests.
DownloadRestrictions Allow download restrictions
If you don't configure this policy or set the 'DefaultDownloadSecurity' option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DownloadRestrictions
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
0No special restrictions1Block malicious downloads and dangerous file types2Block potentially dangerous or unwanted downloads and dangerous file types3Block all downloads4Block malicious downloadsConfigures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision. Set 'BlockDangerousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of known dangerous downloads or that have dangerous file type extensions. Set 'BlockPotentiallyDangerousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous or unwanted downloads or that have dangerous file type extensions. Set 'BlockAllDownloads' to block all downloads. Set 'BlockMaliciousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of known malicious downloads. If you don't configure this policy or set the 'DefaultDownloadSecurity' option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results. Note that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options. See https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen. Policy options mapping: * DefaultDownloadSecurity (0) = No special restrictions * BlockDangerousDownloads (1) = Block malicious downloads and dangerous file types * BlockPotentiallyDangerousDownloads (2) = Block potentially dangerous or unwanted downloads and dangerous file types * BlockAllDownloads (3) = Block all downloads * BlockMaliciousDownloads (4) = Block malicious downloads Use the preceding information when configuring this policy.
ShowRecommendationsEnabled Allow feature recommendations and browser assistance notifications from Microsoft Edge
If you enable or don't configure this setting, users receive recommendations or notifications from Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ShowRecommendationsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 89, Windows 7 or later
- Template
- msedge.admx
This setting controls the in-browser assistance notifications that are intended to help users get the most out of Microsoft Edge. This is done by recommending features and by helping them use browser features. These notifications take the form of dialog boxes, flyouts, coach marks and banners in the browser. An example of an assistance notification would be when a user has many tabs opened in the browser. In this instance, Microsoft Edge may prompt the user to try out the vertical tabs feature which is designed to give better browser tab management. Disabling this policy stops this message from appearing again even if the user has too many tabs open. Any features that have been disabled by a management policy aren't suggested to users. If you enable or don't configure this setting, users receive recommendations or notifications from Microsoft Edge. If you disable this setting, users won't receive any recommendations or notifications from Microsoft Edge.
EdgeAssetDeliveryServiceEnabled Allow features to download assets from the Asset Delivery Service
If you enable or don't configure this policy, features can download assets from the Asset Delivery Service.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeAssetDeliveryServiceEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 101, Windows 7 or later
- Template
- msedge.admx
The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients. These assets can be config files or Machine Learning models that power the features that use this service. If you enable or don't configure this policy, features can download assets from the Asset Delivery Service. If you disable this policy, features won't be able to download assets needed for them to run correctly.
FileOrDirectoryPickerWithoutGestureAllowedForOrigins Allow file or directory picker APIs to be called without prior user gesture
If you disable or don't configure this policy, all origins will require a prior user gesture to call these APIs.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\FileOrDirectoryPickerWithoutGestureAllowedForOrigins
- Supported on
- Microsoft Edge version 123, Windows 7 or later
- Template
- msedge.admx
For security reasons, the showOpenFilePicker(), showSaveFilePicker(), and showDirectoryPicker() web APIs require a prior user gesture ("transient activation") to be called; else, they fail. If you enable this policy, admins can specify origins on which these APIs can be called without prior user gesture. For detailed information on valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy. If you disable or don't configure this policy, all origins will require a prior user gesture to call these APIs. Example value: https://www.example.com [*.]example.edu
AllowFileSelectionDialogs Allow file selection dialogs
If you enable or don't configure this policy, users can open file selection dialogs as normal.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AllowFileSelectionDialogs
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allow access to local files by letting Microsoft Edge display file selection dialogs. If you enable or don't configure this policy, users can open file selection dialogs as normal. If you disable this policy, whenever the user performs an action that triggers a file selection dialog (like importing favorites, uploading files, or saving links), a message is displayed instead, and the system interprets the action as a Cancel selection in the file selection dialog.
TabFreezingEnabled Allow freezing of background tabs (obsolete)
If you enable or don't configure this policy, tabs that are in the background for at least 5 minutes might be frozen.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- TabFreezingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 79-86, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 86. This policy doesn't work, use 'SleepingTabsEnabled' (Configure sleeping tabs) instead. Controls whether Microsoft Edge can freeze tabs that are in the background for at least 5 minutes. Tab freezing reduces CPU, battery, and memory usage. Microsoft Edge uses heuristics to avoid freezing tabs that do useful work in the background, such as display notifications, play sound, and stream video. If you enable or don't configure this policy, tabs that are in the background for at least 5 minutes might be frozen. If you disable this policy, no tabs are frozen.
FullscreenAllowed Allow full screen mode
If you enable this policy or don't configure it, the user, apps, and extensions with appropriate permissions can enter full screen mode.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- FullscreenAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Set the availability of full screen mode - all Microsoft Edge UI is hidden and only web content is visible. If you enable this policy or don't configure it, the user, apps, and extensions with appropriate permissions can enter full screen mode. If you disable this policy, users, apps, and extensions can't enter full screen mode. Opening Microsoft Edge in kiosk mode using the command line is unavailable when full screen mode is disabled.
MediaRouterCastAllowAllIPs Allow Google Cast to connect to Cast devices on all IP addresses
If you don't configure this policy, Google Cast connects to Cast devices on RFC1918/RFC4193 private addresses only, unless you enable the CastAllowAllIPs feature.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- MediaRouterCastAllowAllIPs
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enable this policy to let Google Cast connect to Cast devices on all IP addresses, not just RFC1918/RFC4193 private addresses. Disable this policy to restrict Google Cast to Cast devices on RFC1918/RFC4193 private addresses. If you don't configure this policy, Google Cast connects to Cast devices on RFC1918/RFC4193 private addresses only, unless you enable the CastAllowAllIPs feature. If the 'EnableMediaRouter' (Enable Google Cast) policy is disabled, then this policy has no effect.
HttpsOnlyMode Allow HTTPS-Only Mode to be enabled
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- HttpsOnlyMode
- Supported on
- Microsoft Edge version 140, Windows 7 or later
- Template
- msedge.admx
Don't restrict users' HTTPS-Only Mode settingDisable HTTPS-Only ModeForce enable HTTPS-Only Mode in Strict modeForce enable HTTPS-Only Mode in Balanced ModeThis policy controls whether users can enable HTTPS-Only Mode (Always Use Secure Connections) in Settings. HTTPS-Only Mode attempts to upgrade all navigation to HTTPS. If this setting isn't set or is set to Allowed, users are able to enable HTTPS-Only Mode. If this setting is set to Disallowed, HTTPS-Only Mode will be disabled. If this setting is set to Force Enabled, HTTPS-Only Mode is enabled in Strict mode. If this setting is set to Force Balance Enabled, HTTPS-Only Mode is enabled in Balanced mode. The settings Force Enabled and Force Enabled can be recommended to users. HTTPS-Only Mode will be set to Strict or Balanced initially, but users are allowed to change it. If you set this policy to a value that isn't supported by the version of Microsoft Edge that receives the policy, Microsoft Edge defaults to the Allowed setting. The separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature. Policy options mapping: * allowed (allowed) = Don't restrict users' HTTPS-Only Mode setting * disallowed (disallowed) = Disable HTTPS-Only Mode * force_enabled (force_enabled) = Force enable HTTPS-Only Mode in Strict mode * force_balanced_enabled (force_balanced_enabled) = Force enable HTTPS-Only Mode in Balanced Mode Use the preceding information when configuring this policy. Example value: disallowed
ImportOnEachLaunch Allow import of data from other browsers on each Microsoft Edge launch
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ImportOnEachLaunch
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 104, Windows 7 or later
- Template
- msedge.admx
If you enable this policy, users will see a prompt to import their browsing data from other browsers on each Microsoft Edge launch. If you disable this policy, users will never see a prompt to import their browsing data from other browsers on each Microsoft Edge launch. If the policy is left unconfigured, users can activate this feature from a Microsoft Edge prompt or from the Settings page. Note: A similar policy named 'AutoImportAtFirstRun' (Automatically import another browser's data and settings at first run) exists. This policy should be used if you want to import supported data from other browsers only once while setting up your device.
ImportAutofillFormData Allow importing of autofill form data
If you don't configure this policy, autofill data is imported at first run, and users can choose whether to import this data manually during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ImportAutofillFormData
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows users to import autofill form data from another browser into Microsoft Edge. If you enable this policy, the option to manually import autofill data is automatically selected. If you disable this policy, autofill form data isn't imported at first run, and users can't import it manually. If you don't configure this policy, autofill data is imported at first run, and users can choose whether to import this data manually during later browsing sessions. You can set this policy as a recommendation. This means that Microsoft Edge imports autofill data on first run, but users can select or clear autofill data option during manual import. Note: This policy currently manages import from Google Chrome (on Windows 7, 8, and 10 and on macOS) and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.
ImportBrowserSettings Allow importing of browser settings
If you don't configure this policy, browser settings are imported at first run, and users can choose whether to import them manually during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ImportBrowserSettings
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 78, Windows 7 or later
- Template
- msedge.admx
Allows users to import browser settings from another browser into Microsoft Edge. If you enable this policy, the **Browser settings** check box is automatically selected in the **Import browser data** dialog box. If you disable this policy, browser settings aren't imported at first run, and users can't import them manually. If you don't configure this policy, browser settings are imported at first run, and users can choose whether to import them manually during later browsing sessions. You can also set this policy as a recommendation. This option means that Microsoft Edge imports the settings on first run, but users can select or clear the **browser settings** option during manual import. **Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).
ImportHistory Allow importing of browsing history
If you don't configure this policy, browsing history data is imported at first run, and users can choose whether to import it manually during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ImportHistory
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows users to import their browsing history from another browser into Microsoft Edge. If you enable this policy, the Browsing history check box is automatically selected in the Import browser data dialog box. If you disable this policy, browsing history data isn't imported at first run, and users can't import this data manually. If you don't configure this policy, browsing history data is imported at first run, and users can choose whether to import it manually during later browsing sessions. You can also set this policy as a recommendation. This means that Microsoft Edge imports browsing history on first run, but users can select or clear the **history** option during manual import. Note: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (macOS) browsers.
ImportCookies Allow importing of Cookies
If you don't configure this policy, Cookies are imported on first run.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ImportCookies
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 81, Windows 7 or later
- Template
- msedge.admx
Allows users to import Cookies from another browser into Microsoft Edge. If you disable this policy, Cookies aren't imported on first run. If you don't configure this policy, Cookies are imported on first run. You can also set this policy as a recommendation. This means that Microsoft Edge imports Cookies on first run. Note: This policy currently manages Google Chrome import (on Windows 7, 8, and 10 and on macOS).
ImportExtensions Allow importing of extensions
If you don't configure this policy, extensions are imported at first run, and users can choose whether to import them manually during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ImportExtensions
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 81, Windows 7 or later
- Template
- msedge.admx
Allows users to import extensions from another browser into Microsoft Edge. If you enable this policy, the **Extensions** check box is automatically selected in the **Import browser data** dialog box. If you disable this policy, extensions aren't imported at first run, and users can't import them manually. If you don't configure this policy, extensions are imported at first run, and users can choose whether to import them manually during later browsing sessions. You can also set this policy as a recommendation. This means that Microsoft Edge imports extensions on first run, but users can select or clear the **extensions** option during manual import. **Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).
ImportFavorites Allow importing of favorites
If you don't configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ImportFavorites
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows users to import favorites from another browser into Microsoft Edge. If you enable this policy, the Favorites check box is automatically selected in the Import browser data dialog box. If you disable this policy, favorites aren't imported at first run, and users can't import them manually. If you don't configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions. You can also set this policy as a recommendation. This means that Microsoft Edge imports favorites on first run, but users can select or clear the **favorites** option during manual import. Note: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (on macOS) browsers.
ImportHomepage Allow importing of home page settings
If you don't configure this policy, the home page setting is imported at first run, and users can choose whether to import this data manually during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ImportHomepage
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows users to import their home page setting from another browser into Microsoft Edge. If you enable this policy, the option to manually import the home page setting is automatically selected. If you disable this policy, the home page setting isn't imported at first run, and users can't import it manually. If you don't configure this policy, the home page setting is imported at first run, and users can choose whether to import this data manually during later browsing sessions. You can set this policy as a recommendation. This option means that Microsoft Edge imports the home page setting on first run, but users can select or clear the **home page** option during manual import. **Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).
ImportOpenTabs Allow importing of open tabs
If you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ImportOpenTabs
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 79, Windows 7 or later
- Template
- msedge.admx
Allows users to import open and pinned tabs from another browser into Microsoft Edge. If you enable this policy, the **Open tabs** check box is automatically selected in the **Import browser data** dialog box. If you disable this policy, open tabs aren't imported at first run, and users can't import them manually. If you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions. You can also set this policy as a recommendation. This means that Microsoft Edge imports open tabs on first run, but users can select or clear the **Open tabs** option during manual import. **Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).
ImportPaymentInfo Allow importing of payment info
If you don't configure this policy, payment info is imported at first run, and users can choose whether to import it manually during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ImportPaymentInfo
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows users to import payment info from another browser into Microsoft Edge. If you enable this policy, the **payment info** check box is automatically selected in the **Import browser data** dialog box. If you disable this policy, payment info isn't imported at first run, and users can't import it manually. If you don't configure this policy, payment info is imported at first run, and users can choose whether to import it manually during later browsing sessions. You can also set this policy as a recommendation. This option means that Microsoft Edge imports payment info on first run, but users can select or clear the **payment info** option during manual import. **Note:** This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).
ImportSavedPasswords Allow importing of saved passwords
If you don't configure this policy, no passwords are imported at first run, and users can choose whether to import them manually during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ImportSavedPasswords
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows users to import saved passwords from another browser into Microsoft Edge. If you enable this policy, the option to manually import saved passwords is automatically selected. If you disable this policy, saved passwords aren't imported on first run, and users can't import them manually. If you don't configure this policy, no passwords are imported at first run, and users can choose whether to import them manually during later browsing sessions. You can set this policy as a recommendation. This means that Microsoft Edge imports passwords on first run, but users can select or clear the **passwords** option during manual import. Note: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.
ImportSearchEngine Allow importing of search engine settings
If you don't configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ImportSearchEngine
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows users to import search engine settings from another browser into Microsoft Edge. If you enable, this policy, the option to import search engine settings is automatically selected. If you disable this policy, search engine settings aren't imported at first run, and users can't import them manually. If you don't configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions. You can set this policy as a recommendation. This option means that Microsoft Edge imports search engine settings on first run, but users can select or clear the **search engine** option during manual import. **Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).
ImportShortcuts Allow importing of shortcuts
If you don't configure this policy, Shortcuts are imported on first run.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ImportShortcuts
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 81, Windows 7 or later
- Template
- msedge.admx
Allows users to import Shortcuts from another browser into Microsoft Edge. If you disable this policy, Shortcuts aren't imported on first run. If you don't configure this policy, Shortcuts are imported on first run. You can also set this policy as a recommendation. This means that Microsoft Edge imports Shortcuts on first run. Note: This policy currently manages import from Google Chrome (on Windows 7, 8, and 10 and on macOS).
ImportStartupPageSettings Allow importing of startup page settings
If you don't configure this policy, startup settings are imported at first run, and users can choose whether to import this data manually by selecting browser settings option during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ImportStartupPageSettings
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 91, Windows 7 or later
- Template
- msedge.admx
Allows users to import Startup settings from another browser into Microsoft Edge. If you enable this policy, the Startup settings are always imported. If you disable this policy, startup settings aren't imported at first run or at manual import. If you don't configure this policy, startup settings are imported at first run, and users can choose whether to import this data manually by selecting browser settings option during later browsing sessions. You can set this policy as a recommendation. This means that Microsoft Edge will import startup settings on first run, but users can select or clear **browser settings** option during manual import. **Note**: This policy currently manages importing from Microsoft Edge Legacy and Google Chrome (on Windows 7, 8, and 10) browsers.
InternetExplorerIntegrationTestingAllowed Allow Internet Explorer mode testing (obsolete)
If you disable or don't configure this policy, users can't see the options 'Open in Internet Explorer mode' and 'Open in Edge mode' under "More tools" menu.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerIntegrationTestingAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 86-94, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 94. This policy is obsolete because it has been superseded by an improved feature. It doesn't work in Microsoft Edge after version 94. To allow users to open applications in Internet Explorer mode, use the 'InternetExplorerIntegrationReloadInIEModeAllowed' (Allow unconfigured sites to be reloaded in Internet Explorer mode) policy instead. Alternatively, users can still use the --ie-mode-test flag. This policy allows users to test applications in Internet Explorer mode by opening an Internet Explorer mode tab in Microsoft Edge. Users can do so from within the "More tools" menu by selecting 'Open sites in Internet Explorer mode'. Additionally, users can test their applications in a modern browser without removing applications from the site list using the option 'Open sites in Edge mode'. This setting works in conjunction with 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) which is set to 'IEMode'. If you enable this policy, the option 'Open sites in Internet Explorer mode' is visible under "More tools". Users can view their sites in Internet Explorer mode on this tab. Another option 'Open sites in Edge mode' is also visible under "More tools" to help testing sites in a modern browser without removing them from the site list. If the 'InternetExplorerIntegrationReloadInIEModeAllowed' policy is enabled, it takes precedence and these options will not be visible under "More tools". If you disable or don't configure this policy, users can't see the options 'Open in Internet Explorer mode' and 'Open in Edge mode' under "More tools" menu. However, users can configure these options with the --ie-mode-test flag.
InternetExplorerIntegrationLocalFileAllowed Allow launching of local files in Internet Explorer mode
If this policy is set to "true", or don't configure it, the user is allowed to use the --ie-mode-file-url command line argument for launching local files in Internet Explorer mode.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerIntegrationLocalFileAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 88, Windows 7 or later
- Template
- msedge.admx
This policy controls the availability of the --ie-mode-file-url command line argument used to launch Microsoft Edge with a local file specified on the command line into Internet Explorer mode. This setting works in conjunction with 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) (which is set to 'IEMode'). If this policy is set to "true", or don't configure it, the user is allowed to use the --ie-mode-file-url command line argument for launching local files in Internet Explorer mode. If this policy is set to "false", the user isn't allowed to use the --ie-mode-file-url command line argument for launching local files in Internet Explorer mode. For more information about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210.
WebRtcAllowLegacyTLSProtocols Allow legacy TLS/DTLS downgrade in WebRTC (obsolete)
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebRtcAllowLegacyTLSProtocols
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 88-120, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 120. If you enable this policy, WebRTC peer connections can downgrade to obsolete versions of the TLS/DTLS (DTLS 1.0, TLS 1.0 and TLS 1.1) protocols. If you disable or don't set this policy, these TLS/DTLS versions are disabled. This policy was removed in Microsoft Edge 121 and is ignored if set.
InternetExplorerIntegrationLocalMhtFileAllowed Allow local MHTML files to open automatically in Internet Explorer mode
This setting works when 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode' and 'InternetExplorerIntegrationLocalFileAllowed' (Allow launching of local files in Internet Explorer mode) is enabled or not configured. If you enable or don't configure this policy, local mht or mhtml files launch in Microsoft Edge or Internet Explorer mode.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerIntegrationLocalMhtFileAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 107, Windows 7 or later
- Template
- msedge.admx
This policy controls whether local mht or mhtml files launched from the command line open automatically in Internet Explorer mode based on the file content without specifying the --ie-mode-file-url command line. This setting works when 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode' and 'InternetExplorerIntegrationLocalFileAllowed' (Allow launching of local files in Internet Explorer mode) is enabled or not configured. If you enable or don't configure this policy, local mht or mhtml files launch in Microsoft Edge or Internet Explorer mode. Then, you can view these files in the best way. If you disable this policy, local mht or mhtml files launch in Microsoft Edge. If you use the --ie-mode-file-url command line argument for launching local mht or mhtml files, it takes precedence over how you configured this policy. To learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210
EnterpriseHardwarePlatformAPIEnabled Allow managed extensions to use the Enterprise Hardware Platform API
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EnterpriseHardwarePlatformAPIEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 78, Windows 7 or later
- Template
- msedge.admx
When this policy is set to enabled, extensions installed by enterprise policy are allowed to use the Enterprise Hardware Platform API. When this policy is set to disabled or isn't set, no extensions are allowed to use the Enterprise Hardware Platform API. This policy also applies to component extensions.
AutoplayAllowed Allow media autoplay for websites
If you don't configure this policy, Microsoft Edge uses the current media autoplay setting, and users can change their autoplay settings.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AutoplayAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 78, Windows 7 or later
- Template
- msedge.admx
This policy controls media autoplay behavior for websites. If you don't configure this policy, Microsoft Edge uses the current media autoplay setting, and users can change their autoplay settings. If you enable this policy, media autoplay is set to "Allow". All websites can autoplay media, and users can't override this setting. If you disable this policy, media autoplay is set to "Limit" in Microsoft Edge version 148 and later. Autoplay is limited to webpages with high media engagement or active WebRTC streams, and users can't override this setting. In versions 92 through 145, disabling this policy also set autoplay to "Limit". In versions 146 and 147, disabling this policy set autoplay to "Block". Tabs must be closed and reopened for this policy to take effect.
AutoplayAllowlist Allow media autoplay on specific sites
If you don't configure this policy, the global default value from the 'AutoplayAllowed' (Allow media autoplay for websites) policy (if set) or the user's personal configuration is used for all sites.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\AutoplayAllowlist
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
Define a list of sites, based on URL patterns, that are allowed to autoplay media. If you don't configure this policy, the global default value from the 'AutoplayAllowed' (Allow media autoplay for websites) policy (if set) or the user's personal configuration is used for all sites. For detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Note: * is not an accepted value for this policy. Example value: https://www.contoso.com [*.]contoso.edu
SandboxExternalProtocolBlocked Allow Microsoft Edge to block navigations to external protocols in a sandboxed iframe
If you enable or don't configure this policy, Microsoft Edge blocks those navigations.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SandboxExternalProtocolBlocked
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 99, Windows 7 or later
- Template
- msedge.admx
Microsoft Edge blocks navigations to external protocols inside a sandboxed iframe. If you enable or don't configure this policy, Microsoft Edge blocks those navigations. If you disable this policy, Microsoft Edge doesn't block those navigations. This policy can be used by administrators who need more time to update their internal website affected by this new restriction. This Enterprise policy is temporary; it's intended to be removed after Microsoft Edge version 117.
AudioCaptureAllowed Allow or block audio capture
If you enable this policy or don't configure it (the default setting), the user is prompted for audio capture access except from the URLs in the 'AudioCaptureAllowedUrls' list.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AudioCaptureAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows you to set whether a user is prompted to grant a website access to their audio capture device. This policy applies to all URLs except for the ones configured in the 'AudioCaptureAllowedUrls' (Sites that can access audio capture devices without requesting permission) list. If you enable this policy or don't configure it (the default setting), the user is prompted for audio capture access except from the URLs in the 'AudioCaptureAllowedUrls' list. These listed URLs are granted access without prompting. If you disable this policy, the user isn't prompted, and audio capture is accessible only to the URLs configured in 'AudioCaptureAllowedUrls'. This policy affects all types of audio inputs, not only the built-in microphone.
VideoCaptureAllowed Allow or block video capture
If enabled or not configured (default), the user is asked about video capture access for all sites except sites with URLs configured in the 'VideoCaptureAllowedUrls' (Sites that can access video capture devices without requesting permission) policy list, which is granted without prompting.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- VideoCaptureAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Control whether sites can capture video. If enabled or not configured (default), the user is asked about video capture access for all sites except sites with URLs configured in the 'VideoCaptureAllowedUrls' (Sites that can access video capture devices without requesting permission) policy list, which is granted without prompting. If you disable this policy, the user isn't prompted, and video capture is only available to URLs configured in 'VideoCaptureAllowedUrls' policy. This policy affects all types of video inputs, not only the built-in camera.
ScreenCaptureAllowed Allow or deny screen capture
If you enable this policy, or don't configure this policy, a webpage uses screen-share APIs (for example, getDisplayMedia() or the Desktop Capture extension API) for a screen capture.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ScreenCaptureAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 83, Windows 7 or later
- Template
- msedge.admx
If you enable this policy, or don't configure this policy, a webpage uses screen-share APIs (for example, getDisplayMedia() or the Desktop Capture extension API) for a screen capture. If you disable this policy, calls to screen-share APIs fail. For example, if you're using a web-based online meeting, video or screen sharing won't work. However, this policy isn't considered. (and a site will be allowed to use screen-share APIs) if the site matches an origin pattern in any of the following policies: 'ScreenCaptureAllowedByOrigins' (Allow Desktop, Window, and Tab capture by these origins), 'WindowCaptureAllowedByOrigins' (Allow Window and Tab capture by these origins), 'TabCaptureAllowedByOrigins' (Allow Tab capture by these origins), 'SameOriginTabCaptureAllowedByOrigins' (Allow Same Origin Tab capture by these origins).
AllowSyncXHRInPageDismissal Allow pages to send synchronous XHR requests during page dismissal (obsolete)
If you disable this policy or don't configure this policy, pages aren't allowed to send synchronous XHR requests during page dismissal.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AllowSyncXHRInPageDismissal
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 79-99, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 99. This policy is obsolete because it was only intended to be a short-term mechanism to give enterprises more time to update their web content if and when it was found to be incompatible with the change to disallow synchronous XHR requests during page dismissal. It doesn't work in Microsoft Edge after version 99. This policy lets you specify that a page can send synchronous XHR requests during page dismissal. If you enable this policy, pages can send synchronous XHR requests during page dismissal. If you disable this policy or don't configure this policy, pages aren't allowed to send synchronous XHR requests during page dismissal.
BuiltInAIAPIsEnabled Allow pages to use the built-in AI APIs.
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- BuiltInAIAPIsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 138, Windows 7 or later
- Template
- msedge.admx
Use this policy to control whether websites can access the built-in AI APIs, including the LanguageModel API, Summarization API, Writer API, and Rewriter API. Enable this policy to allow pages to use the APIs. If you don’t configure this policy, the APIs are still allowed. Disable this policy to block access to the APIs. The APIs will return an error when used. For more information, see https://github.com/webmachinelearning/writing-assistance-apis/blob/main/README.md.
AllowBackForwardCacheForCacheControlNoStorePageEnabled Allow pages with Cache-Control: no-store header to enter back/forward cache
If you enable or don't configure this policy, the page with Cache-Control: no-store header is restored from back/forward cache unless the cache eviction is triggered (for example, when there's HTTP-only cookie change to the site).
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AllowBackForwardCacheForCacheControlNoStorePageEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 123, Windows 7 or later
- Template
- msedge.admx
This policy controls whether a page with Cache-Control: no-store header can be stored in back/forward cache. The website setting in this header may not expect the page to be restored from back/forward cache since some sensitive information could still be displayed after the restoration even if it's no longer accessible. If you enable or don't configure this policy, the page with Cache-Control: no-store header is restored from back/forward cache unless the cache eviction is triggered (for example, when there's HTTP-only cookie change to the site). If you disable this policy, the page with Cache-Control: no-store header isn't stored in back/forward cache.
PersonalizationReportingEnabled Allow personalization of ads, Microsoft Edge, search, news and other Microsoft services by sending browsing history, favorites and collections, usage and other browsing data to Microsoft
If this policy is enabled or not configured, Microsoft Edge defaults to the user's preference.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PersonalizationReportingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 80, Windows 7 or later
- Template
- msedge.admx
This policy prevents Microsoft from collecting a user's Microsoft Edge browsing history, favorites and collections, usage, and other browsing data to be used for personalizing advertising, search, news, Microsoft Edge, and other Microsoft services. This setting isn't available for child accounts or enterprise accounts. If you disable this policy, users can't change or override the setting. If this policy is enabled or not configured, Microsoft Edge defaults to the user's preference.
PinningWizardAllowed Allow Pin to taskbar wizard
If you enable this policy or don't configure it, users can call the Pin to taskbar wizard from the Settings and More menu.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PinningWizardAllowed
- Enabled / Disabled
- 1 / 0
- Stated default
- The Pin to taskbar wizard feature is enabled by default and accessible to the user through the Settings and more menu.
- Supported on
- Microsoft Edge version 80, Windows 7 or later
- Template
- msedge.admx
Microsoft Edge uses the Pin to taskbar wizard to help users pin suggested sites to the taskbar. The Pin to taskbar wizard feature is enabled by default and accessible to the user through the Settings and more menu. If you enable this policy or don't configure it, users can call the Pin to taskbar wizard from the Settings and More menu. The wizard can also be called via a protocol launch. If you disable this policy, the Pin to taskbar wizard is disabled in the menu and cannot be called via a protocol launch. User settings to enable or disable the Pin to taskbar wizard aren't available.
BrowserNetworkTimeQueriesEnabled Allow queries to a Browser Network Time service
If you enable this policy or don't configure it, Microsoft Edge occasionally sends queries to a browser network time service.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- BrowserNetworkTimeQueriesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Prevents Microsoft Edge from occasionally sending queries to a browser network time service to retrieve an accurate timestamp. If you disable this policy, Microsoft Edge stops sending queries to a browser network time service. If you enable this policy or don't configure it, Microsoft Edge occasionally sends queries to a browser network time service.
QuicAllowed Allow QUIC protocol
If you enable this policy or don't configure it, the QUIC protocol is allowed.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- QuicAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows use of the QUIC protocol in Microsoft Edge. If you enable this policy or don't configure it, the QUIC protocol is allowed. If you disable this policy, the QUIC protocol is blocked. QUIC is a transport layer network protocol that can improve performance of web applications that currently use TCP.
RemoteDebuggingAllowed Allow remote debugging
If you enable or don't configure this policy, users can use remote debugging by specifying --remote-debug-port and --remote-debugging-pipe command line switches.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RemoteDebuggingAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
Controls whether users can use remote debugging. If you enable or don't configure this policy, users can use remote debugging by specifying --remote-debug-port and --remote-debugging-pipe command line switches. If you disable this policy, users aren't allowed to use remote debugging.
InternetExplorerModeEnableSavePageAs Allow Save page as in Internet Explorer mode
If you disable or don't configure this policy, users can't select the "Save page as" option in "More tools".
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerModeEnableSavePageAs
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 101, Windows 7 or later
- Template
- msedge.admx
This policy enables 'Save page as' functionality in Internet Explorer mode. Users can use this option to save the current page in the browser. When a user reopens a saved page, it's loaded in the default browser. If you enable this policy, the "Save page as" option is clickable in "More tools". If you disable or don't configure this policy, users can't select the "Save page as" option in "More tools". Note: To make the "Ctrl+S" shortcut work, users must enable the Internet Explorer policy, namely 'Enable extended hot key in Internet Explorer mode'. To learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210
ScreenCaptureWithoutGestureAllowedForOrigins Allow screen capture without prior user gesture
If this policy isn't configured, all origins require a prior user gesture to call this API.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ScreenCaptureWithoutGestureAllowedForOrigins
- Supported on
- Microsoft Edge version 123, Windows 7 or later
- Template
- msedge.admx
For security reasons, the getDisplayMedia() web API requires a prior user gesture ("transient activation") to be called or the API fails. When this policy is configured, admins can specify origins on which this API can be called without prior user gesture. For detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Note: * isn't an accepted value for this policy. If this policy isn't configured, all origins require a prior user gesture to call this API. Example value: https://www.example.com [*.]example.edu
ServiceWorkerToControlSrcdocIframeEnabled Allow ServiceWorker to control srcdoc iframes
By default (if left unset) or when set to Enabled, Microsoft Edge makes srcdoc iframes with "allow-same-origin" sandbox attributes to be under ServiceWorker control.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ServiceWorkerToControlSrcdocIframeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 134, Windows 7 or later
- Template
- msedge.admx
https://github.com/w3c/ServiceWorker/issues/765 asks srcdoc iframe with the "allow-same-origin" sandbox attribute to be under ServiceWorker control. By default (if left unset) or when set to Enabled, Microsoft Edge makes srcdoc iframes with "allow-same-origin" sandbox attributes to be under ServiceWorker control. Setting the policy to Disabled prevents ServiceWorker control over srcdoc iframes. This policy is temporary and planned for deprecation in 2026.
ServiceWorkerAutoPreloadEnabled Allow ServiceWorker to dispatch navigation requests without waiting for its startup
If you enable or don't configure this policy, Microsoft Edge can initiate the main resource network request concurrently with the Service Worker bootstrap process.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ServiceWorkerAutoPreloadEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 140, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Microsoft Edge enables the ServiceWorkerAutoPreload feature. If you enable or don't configure this policy, Microsoft Edge can initiate the main resource network request concurrently with the Service Worker bootstrap process. This can improve performance in scenarios where the Service Worker isn't already running. If you disable this policy, Microsoft Edge will wait to dispatch the navigation request until after the Service Worker starts. This is a temporary policy and is removed in version 154 of Microsoft Edge. For more information on the feature, see https://github.com/WICG/service-worker-auto-preload.
ShareBrowsingHistoryWithCopilotSearchAllowed Allow sharing tenant-approved browsing history with Microsoft 365 Copilot Search
If you enable or don't configure this policy, browsing history will be shared with Microsoft 365 Copilot Search by default, and users can turn off sharing using the toggle in Microsoft Edge settings.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ShareBrowsingHistoryWithCopilotSearchAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 143, Windows 7 or later
- Template
- msedge.admx
This policy controls whether browsing history in Microsoft Edge is shared with Microsoft 365 Copilot Search to provide more relevant search results. Only tenant-approved, work-related sites are shared. This feature is available only to users who are signed in to Microsoft Edge with an Entra ID account and have an eligible Microsoft 365 Copilot license. If you enable or don't configure this policy, browsing history will be shared with Microsoft 365 Copilot Search by default, and users can turn off sharing using the toggle in Microsoft Edge settings. If you disable this policy, browsing history won't be shared with Microsoft 365 Copilot Search. Learn more about how Copilot uses data and consent at https://go.microsoft.com/fwlink/?linkid=2333202
MSAWebSiteSSOUsingThisProfileAllowed Allow single sign-on for Microsoft personal sites using this profile
If you enable this policy or don't configure it, users can use the Settings option to ensure non-MSA profiles are able to use single sign-on for Microsoft sites using MSA credentials present on the machine provided only a single MSA account exists on the machine.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- MSAWebSiteSSOUsingThisProfileAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
'Allow single sign-on for Microsoft personal sites using this profile' option allows non-MSA profiles to be able to use single sign-on for Microsoft sites using MSA credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-MSA profiles only. If you disable this policy, non-MSA profiles can't use single sign-on for Microsoft sites using MSA credentials present on the machine. If you enable this policy or don't configure it, users can use the Settings option to ensure non-MSA profiles are able to use single sign-on for Microsoft sites using MSA credentials present on the machine provided only a single MSA account exists on the machine.
InternetExplorerModeTabInEdgeModeAllowed Allow sites configured for Internet Explorer mode to open in Microsoft Edge
If you disable or don't configure this policy, users can't see the option 'Open in Microsoft Edge' under the "More tools" menu.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerModeTabInEdgeModeAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 97, Windows 7 or later
- Template
- msedge.admx
This policy lets sites configured to open in Internet Explorer mode to be opened by Microsoft Edge for testing on a modern browser without removing them from the site list. Users can configure this setting in the "More tools" menu by selecting 'Open sites in Microsoft Edge'. If you enable this policy, the option to 'Open sites in Microsoft Edge' is visible under "More tools". Users use this option to test IE mode sites on a modern browser. If you disable or don't configure this policy, users can't see the option 'Open in Microsoft Edge' under the "More tools" menu. However, users can access this menu option with the --ie-mode-test flag.
AllowSocketPoolSizeRandomizationForProxies Allow socket pool size randomization for proxies
If you enable this policy or don't configure it, Microsoft Edge enables socket pool size randomization for proxy connections.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AllowSocketPoolSizeRandomizationForProxies
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 150, Windows 7 or later
- Template
- msedge.admx
Controls whether Microsoft Edge randomizes socket pool sizes for proxy connections. Socket pool size randomization is a security mechanism that helps prevent attackers from using deterministic connection limits to infer cross-site information. For example, if the configured proxy socket pool limit is 128, Microsoft Edge can randomly set the effective limit between 128 and 256. This can allow up to twice as many proxy connections, though the expected increase is closer to 1.2x in practice. This policy affects the limits configured by the 'MaxConnectionsPerProxy' (Maximum number of concurrent connections to the proxy server for non-WebSocket requests) and 'MaxConnectionsPerProxyForWebSocket' (Maximum number of concurrent connections to the proxy server for WebSocket requests) policies. When this policy is enabled, the effective upper limit can be randomized up to 2x the values configured by those policies. If you enable this policy or don't configure it, Microsoft Edge enables socket pool size randomization for proxy connections. If you disable this policy, Microsoft Edge disables socket pool size randomization for proxy connections. The values configured by 'MaxConnectionsPerProxy' and 'MaxConnectionsPerProxyForWebSocket' are used as the upper limits without randomization.
EnableUnsafeSwiftShader Allow software WebGL fallback using SwiftShader
If you disable or don't configure this policy, WebGL context creation can fail on systems without hardware acceleration.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EnableUnsafeSwiftShader
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 139, Windows 7 or later
- Template
- msedge.admx
Microsoft Security BaselineEnableUnsafeSwiftShader = 0
Controls whether SwiftShader is used as a fallback for WebGL when hardware GPU acceleration isn't available. When enabled, Microsoft Edge uses SwiftShader to support WebGL on systems without GPU acceleration, such as headless environments or virtual machines. Starting in Microsoft Edge version 144, SwiftShader is deprecated due to security concerns. As a result, WebGL context creation fails in scenarios where SwiftShader is used. Enabling this policy allows organizations to temporarily defer the deprecation and continue using SwiftShader. If you disable or don't configure this policy, WebGL context creation can fail on systems without hardware acceleration. This could cause web content relying on WebGL to function incorrectly if it doesn't handle context creation failures. Note: This policy is temporary and scheduled for removal in a future release. Microsoft doesn't guarantee the security of environments where this policy is enabled.
EdgeSidebarAppUrlHostAllowList Allow specific apps to be opened in Microsoft Edge sidebar
If you don't configure this policy, a user can open any app in sidebar except the urls listed in 'EdgeSidebarAppUrlHostBlockList'.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\EdgeSidebarAppUrlHostAllowList
- Stated default
- By default, all apps are allowed.
- Supported on
- Microsoft Edge version 131, Windows 7 or later
- Template
- msedge.admx
Define a list of sites, based on URL patterns, that aren't subject to the 'EdgeSidebarAppUrlHostBlockList' (Control which apps cannot be opened in Microsoft Edge sidebar). If you don't configure this policy, a user can open any app in sidebar except the urls listed in 'EdgeSidebarAppUrlHostBlockList'. If you configure this policy, the apps listed in the allow list could be opened in sidebar even if they are listed in the block list. By default, all apps are allowed. However, if you prohibited apps by policy, you can use the list of allowed apps to change that policy. For detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2281313. Example value: https://www.contoso.com [*.]contoso.edu
PrefetchWithServiceWorkerEnabled Allow SpeculationRules prefetch for ServiceWorker-controlled URLs
If this policy is enabled or not configured, that default behavior is used.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PrefetchWithServiceWorkerEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- With Microsoft Edge version 138, prefetch requests to ServiceWorker-controlled URLs are allowed by default when the PrefetchServiceWorker feature is enabled.
- Supported on
- Microsoft Edge version 138, Windows 7 or later
- Template
- msedge.admx
Controls whether SpeculationRules prefetch requests are allowed for ServiceWorker-controlled URLs. With Microsoft Edge version 138, prefetch requests to ServiceWorker-controlled URLs are allowed by default when the PrefetchServiceWorker feature is enabled. If this policy is enabled or not configured, that default behavior is used. To restore the legacy behavior from versions before 138, where prefetch requests to ServiceWorker-controlled URLs were blocked, set this policy to disabled. This policy is intended to be temporary and will be removed in the future.
LocalProvidersEnabled Allow suggestions from local providers
If you don't configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- LocalProvidersEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 83, Windows 7 or later
- Template
- msedge.admx
Allow suggestions from suggestion providers on the device (local providers), for example, Favorites and Browsing History, in Microsoft Edge's Address Bar and Auto-Suggest List. If you enable this policy, suggestions from local providers are used. If you disable this policy, suggestions from local providers are never used. Local history and local favorites suggestions won't appear. If you don't configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle. Some features may not be available if a policy to disable this feature has been applied. For example, Browsing History suggestions will not be available if you enable the 'SavingBrowserHistoryDisabled' (Disable saving browser history) policy. This policy requires a browser restart to finish applying.
AllowSurfGame Allow surf game
If you enable or don't configure this policy, users can play the surf game.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AllowSurfGame
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 83, Windows 7 or later
- Template
- msedge.admx
If you disable this policy, users won't be able to play the surf game when the device is offline or if the user navigates to edge://surf. If you enable or don't configure this policy, users can play the surf game.
AudioProcessHighPriorityEnabled Allow the audio process to run with priority above normal on Windows
If you don't configure this policy, the default configuration for the audio process is used.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AudioProcessHighPriorityEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 96, Windows 7 or later
- Template
- msedge.admx
This policy controls the priority of the audio process on Windows. If you enable this policy, the audio process runs with above normal priority. If you disable this policy, the audio process runs with normal priority. If you don't configure this policy, the default configuration for the audio process is used. This policy is intended as a temporary measure to give enterprises the ability to run audio with higher priority to address certain performance issues with audio capture. This policy will be removed in the future.
AudioSandboxEnabled Allow the audio sandbox to run
If you don't configure this policy, the default configuration for the audio sandbox is used, which might differ based on the platform.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AudioSandboxEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 81, Windows 7 or later
- Template
- msedge.admx
This policy controls the audio process sandbox. If you enable this policy, the audio process runs sandboxed. If you disable this policy, the audio process runs unsandboxed and the WebRTC audio-processing module will run in the renderer process. This leaves users open to security risks related to running the audio subsystem unsandboxed. If you don't configure this policy, the default configuration for the audio sandbox is used, which might differ based on the platform. This policy is intended to give enterprises flexibility to disable the audio sandbox if they use security software setups that interfere with the sandbox.
SearchbarIsEnabledOnStartup Allow the Search bar at Windows startup
If you don't configure the policy: The Search bar doesn't start at Windows startup for all profiles.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SearchbarIsEnabledOnStartup
- Enabled / Disabled
- 1 / 0
- Stated default
- If you enable: The Search bar starts running at Windows startup by default.
- Supported on
- Microsoft Edge version 117, Windows 7 or later
- Template
- msedge.admx
Allows the Search bar to start running at Windows startup. If you enable: The Search bar starts running at Windows startup by default. If the Search bar is disabled via 'SearchbarAllowed' (Enable the Search bar) policy, this policy doesn't start the Search bar on Windows startup. If you disable this policy: The Search bar doesn't start at Windows startup for all profiles. The option to start the search bar at Windows startup is disabled and toggled off in search bar settings. If you don't configure the policy: The Search bar doesn't start at Windows startup for all profiles. The option to start the search bar at Windows startup is toggled off in search bar settings.
WebWidgetIsEnabledOnStartup Allow the Search bar at Windows startup (obsolete)
If you don't configure this policy, the Search bar doesn't start at Windows startup for all profiles.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebWidgetIsEnabledOnStartup
- Enabled / Disabled
- 1 / 0
- Stated default
- If you enable this policy, the Search bar starts running at Windows startup by default.
- Supported on
- Microsoft Edge version 88-119, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 119. This policy is obsolete due to the deprecation of the Web widget, which is now known as Edge search bar. Admins should use the 'SearchbarIsEnabledOnStartup' (Allow the Search bar at Windows startup) policy for Edge search bar instead. This policy allows the Search bar to start running at Windows startup. If you enable this policy, the Search bar starts running at Windows startup by default. If the Search bar is disabled via 'WebWidgetAllowed' (Enable the Search bar) policy, this policy doesn't start the Search bar on Windows startup. If you disable this policy, the Search bar doesn't start at Windows startup for all profiles. The option to start the Edge search bar at Windows startup is disabled and toggled off in Microsoft Edge settings. If you don't configure this policy, the Search bar doesn't start at Windows startup for all profiles. The option to start the Edge search bar at Windows startup is toggled off in Microsoft Edge settings.
SerialAskForUrls Allow the Serial API on specific sites
If not configured, Microsoft Edge uses the value from the DefaultSerialGuardSetting policy (if set), or the user's settings.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\SerialAskForUrls
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
Specifies URL patterns for sites that are allowed to request access to a serial port. If not configured, Microsoft Edge uses the value from the DefaultSerialGuardSetting policy (if set), or the user's settings. For unmatched sites, the following order applies: 1. 'SerialBlockedForUrls' (Block the Serial API on specific sites) (if matched). 2. DefaultSerialGuardSetting (if set). 3. User's settings. If URL patterns in this policy conflict with those in 'SerialBlockedForUrls', they're ignored. For detailed information about valid URL patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Example value: https://www.contoso.com [*.]contoso.edu
InternetExplorerIntegrationReloadInIEModeAllowed Allow unconfigured sites to be reloaded in Internet Explorer mode
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerIntegrationReloadInIEModeAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 92, Windows 7 or later
- Template
- msedge.admx
Microsoft Security BaselineInternetExplorerIntegrationReloadInIEModeAllowed = 0
This policy allows users to reload unconfigured sites (ones that aren't configured in the Enterprise Mode Site List) in Internet Explorer mode when browsing in Microsoft Edge, and a site requires Internet Explorer for compatibility. After a site is reloaded in Internet Explorer mode, "in-page" navigation stays in Internet Explorer mode (for example, a link, script, or form on the page, or a server-side redirect from another "in-page" navigation). Users can choose to exit from Internet Explorer mode, or Microsoft Edge automatically exits from Internet Explorer mode when a navigation that isn't "in-page" occurs (for example, using the address bar, the back button, or a favorite link). Users can also optionally tell Microsoft Edge to use Internet Explorer mode for the site in the future. This choice is remembered for a length of time managed by the 'InternetExplorerIntegrationLocalSiteListExpirationDays' (Specify the number of days that a site remains on the local IE mode site list) policy. If the 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) policy is set to 'IEMode', then sites explicitly configured by the 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy's site list to use Microsoft Edge aren't reloaded in Internet Explorer mode, and sites configured by the site list or by the 'SendIntranetToInternetExplorer' (Send all intranet sites to Internet Explorer) policy to use Internet Explorer mode can't exit from Internet Explorer mode. If you enable this policy, users are allowed to reload unconfigured sites in Internet Explorer mode. If you disable this policy, users aren't allowed to reload unconfigured sites in Internet Explorer mode. If you enable this policy, it takes precedence over how you configured the 'InternetExplorerIntegrationTestingAllowed' (Allow Internet Explorer mode testing) policy, and that policy is disabled. For more information about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210
UserFeedbackAllowed Allow user feedback
If you enable this policy or don't configure it, users can invoke Edge Feedback.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- UserFeedbackAllowed
- Enabled / Disabled
- 1 / 0
- Stated default
- Microsoft Edge uses the Edge Feedback feature (enabled by default) to allow users to send feedback, suggestions, or customer surveys and to report any issues with the browser. Also, by default, users can't disable (turn off) the Edge Feedback feature.
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Microsoft Edge uses the Edge Feedback feature (enabled by default) to allow users to send feedback, suggestions, or customer surveys and to report any issues with the browser. Also, by default, users can't disable (turn off) the Edge Feedback feature. Starting with Microsoft Edge 105, if the user is signed into Microsoft Edge with their work or school account, their feedback is associated with their account and organization. If you enable this policy or don't configure it, users can invoke Edge Feedback. If you disable this policy, users can't invoke Edge Feedback.
AllowGamesMenu Allow users to access the games menu (deprecated)
If you enable or don't configure this policy, users can access the games menu.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AllowGamesMenu
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 99, Windows 7 or later
- Template
- msedge.admx
DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. This policy is deprecated because it can be managed using the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy. If you enable or don't configure this policy, users can access the games menu. If you disable this policy, users won't be able to access the games menu.
MicrosoftOfficeMenuEnabled Allow users to access the Microsoft Office menu (deprecated)
If you enable or don't configure this policy, users can open the Microsoft Office menu.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- MicrosoftOfficeMenuEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 100, Windows 7 or later
- Template
- msedge.admx
DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. This policy is deprecated because the Microsoft Edge sidebar replaced it. Microsoft Office applications are now available in the sidebar, which are managed by HubsSidebarEnabled policy. When users can access the Microsoft Office menu, they can get access to Office applications such as Microsoft Word and Microsoft Excel. If you enable or don't configure this policy, users can open the Microsoft Office menu. If you disable this policy, users can't access the Microsoft Office menu.
OutlookHubMenuEnabled Allow users to access the Outlook menu (obsolete)
If you enable or don't configure this policy, users can access the Outlook menu.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- OutlookHubMenuEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 102-105, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 105. This policy doesn't work because the Outlook menu is now contained within the Edge Sidebar and can be managed using the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy. This policy is used to manage access to the Outlook menu from Microsoft Edge. If you enable or don't configure this policy, users can access the Outlook menu. If you disable this policy, users can't access the Outlook menu.
EnhanceSecurityModeAllowUserBypass Allow users to bypass Enhanced Security Mode
If you enable or don't configure this policy, Microsoft Edge allows users to bypass Enhanced Security Mode.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EnhanceSecurityModeAllowUserBypass
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 122, Windows 7 or later
- Template
- msedge.admx
Microsoft Edge lets users bypass Enhanced Security Mode on a site via Settings page or PageInfo flyout. This policy lets you configure whether users can bypass Enhanced Security Mode. If you disable this policy, Microsoft Edge can't allow users to bypass Enhanced Security Mode. If you enable or don't configure this policy, Microsoft Edge allows users to bypass Enhanced Security Mode. For detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895
FamilySafetySettingsEnabled Allow users to configure Family safety and Kids Mode
com/fwlink/?linkid=2146910) If you enable this policy or don't configure it, the family page in Settings is shown and Kids Mode is available.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- FamilySafetySettingsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 83, Windows 7 or later
- Template
- msedge.admx
This policy disables two family safety-related features in the browser. This hides the Family page inside Settings, and navigation to edge://settings/family is blocked. The family settings page describes what features are available with family groups with Microsoft Family Safety. Learn more about Family Safety here: (https://go.microsoft.com/fwlink/?linkid=2098432). Starting in Microsoft Edge version 90, this policy also disables Kids Mode, a kid-friendly browsing mode with custom themes and allow list browsing that requires the device password to exit. Learn more about Kids Mode here: (https://go.microsoft.com/fwlink/?linkid=2146910) If you enable this policy or don't configure it, the family page in Settings is shown and Kids Mode is available. If you disable this policy, the family page isn't shown, and Kids Mode is hidden.
SiteSafetyServicesEnabled Allow users to configure Site safety services (obsolete)
If you enable this policy or don't configure it, the top site info will be shown.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SiteSafetyServicesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 101-127, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 127. This policy is obsolete as the feature is being removed after Microsoft Edge version 127. This policy disables site safety services from showing top site info in the page info dialog. If you enable this policy or don't configure it, the top site info will be shown. If you disable this policy, the top site info won't be shown.
ClickOnceEnabled Allow users to open files using the ClickOnce protocol
If you don't configure this policy, users with Microsoft Edge versions before Microsoft Edge 87 can't open files using the ClickOnce protocol by default.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ClickOnceEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- If you don't configure this policy, users with Microsoft Edge versions before Microsoft Edge 87 can't open files using the ClickOnce protocol by default. Users with Microsoft Edge versions 87 and later can open files using the ClickOnce protocol by default but can disable the ClickOnce protocol with edge://flags/ page.
- Supported on
- Microsoft Edge version 78, Windows 7 or later
- Template
- msedge.admx
Allow users to open files using the ClickOnce protocol. The ClickOnce protocol allows websites to request that the browser open files from a specific URL using the ClickOnce file handler on the user's computer or device. If you enable this policy, users can open files using the ClickOnce protocol. This policy overrides the user's ClickOnce setting in the edge://flags/ page. If you disable this policy, users can't open files using the ClickOnce protocol. Instead, the file is saved to the file system using the browser. This policy overrides the user's ClickOnce setting in the edge://flags/ page. If you don't configure this policy, users with Microsoft Edge versions before Microsoft Edge 87 can't open files using the ClickOnce protocol by default. However, they can enable the use of the ClickOnce protocol with the edge://flags/ page. Users with Microsoft Edge versions 87 and later can open files using the ClickOnce protocol by default but can disable the ClickOnce protocol with edge://flags/ page. Disabling ClickOnce can prevent ClickOnce applications (.application files) from launching properly. For more information about ClickOnce, see https://go.microsoft.com/fwlink/?linkid=2103872 and https://go.microsoft.com/fwlink/?linkid=2099880.
DirectInvokeEnabled Allow users to open files using the DirectInvoke protocol
If you enable or don't configure this policy, users can open files using the DirectInvoke protocol.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DirectInvokeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 78, Windows 7 or later
- Template
- msedge.admx
Allow users to open files using the DirectInvoke protocol. The DirectInvoke protocol allows websites to request that the browser open files from a specific URL using a specific file handler on the user's computer or device. If you enable or don't configure this policy, users can open files using the DirectInvoke protocol. If you disable this policy, users can't open files using the DirectInvoke protocol. Instead, the file is saved to the file system. Note: Disabling DirectInvoke can prevent certain Microsoft SharePoint Online features from working as expected. For more information about DirectInvoke, see https://go.microsoft.com/fwlink/?linkid=2103872 and https://go.microsoft.com/fwlink/?linkid=2099871.
SSLErrorOverrideAllowed Allow users to proceed from the HTTPS warning page
If you enable or don't configure (default) this policy, users can click through these warning pages.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SSLErrorOverrideAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Microsoft Security BaselineSSLErrorOverrideAllowed = 0
Microsoft Edge shows a warning page when users visit sites that have SSL errors. If you enable or don't configure (default) this policy, users can click through these warning pages. If you disable this policy, users are blocked from clicking through any warning page.
SSLErrorOverrideAllowedForOrigins Allow users to proceed from the HTTPS warning page for specific origins
If you enable or don't configure the 'SSLErrorOverrideAllowed' (Allow users to proceed from the HTTPS warning page) policy, this policy does nothing. If you don't configure this policy, the 'SSLErrorOverrideAllowed' policy applies for all sites.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\SSLErrorOverrideAllowedForOrigins
- Supported on
- Microsoft Edge version 90, Windows 7 or later
- Template
- msedge.admx
Microsoft Edge shows a warning page when users visit sites that have SSL errors. If you enable or don't configure the 'SSLErrorOverrideAllowed' (Allow users to proceed from the HTTPS warning page) policy, this policy does nothing. If you disable the 'SSLErrorOverrideAllowed' policy, configuring this policy lets you configure a list of origin patterns for sites where users can continue to click through SSL error pages. Users can't click through SSL error pages on origins that are not on this list. If you don't configure this policy, the 'SSLErrorOverrideAllowed' policy applies for all sites. For detailed information about valid origin patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy. This policy only matches based on origin, so any path or query in the URL pattern is ignored. Example value: https://www.example.com [*.]example.edu
U2fSecurityKeyApiEnabled Allow using the deprecated U2F Security Key API (obsolete)
If you disable this policy or don't configure it, the U2F Security Key API is disabled by default and can only be used by sites that register for and use the U2FSecurityKeyAPI origin trial, which ended after Microsoft Edge version 103.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- U2fSecurityKeyApiEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 98-103, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 103. This policy is obsolete because it was intended to be a short-term mechanism to give enterprises more time to update their web content that's incompatible with the change to remove the U2F Security Key API. It doesn't work in Microsoft Edge after version 103. If you enable this policy, the deprecated U2F Security Key API can be used and the deprecation reminder prompt shown for U2F API requests is suppressed. If you disable this policy or don't configure it, the U2F Security Key API is disabled by default and can only be used by sites that register for and use the U2FSecurityKeyAPI origin trial, which ended after Microsoft Edge version 103.
AllowWebAuthnWithBrokenTlsCerts Allow Web Authentication requests on sites with broken TLS certificates.
If you disable or don't configure this policy, the default behavior of blocking such requests apply.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AllowWebAuthnWithBrokenTlsCerts
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 123, Windows 7 or later
- Template
- msedge.admx
If you enable this policy, Microsoft Edge allows Web Authentication requests on websites that have TLS certificates with errors (that is, websites considered not secure). If you disable or don't configure this policy, the default behavior of blocking such requests apply.
WebDriverOverridesIncompatiblePolicies Allow WebDriver to Override Incompatible Policies (obsolete)
If you disable or don't configure this policy, WebDriver isn't allowed to override incompatible policies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebDriverOverridesIncompatiblePolicies
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77-84, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 84. This policy doesn't work because WebDriver is now compatible with all existing policies. This policy allows users of the WebDriver feature to override policies that can interfere with its operation. Currently this policy disables 'SitePerProcess' (Enable site isolation for every site) and 'IsolateOrigins' (Enable site isolation for specific origins) policies. If you enable this policy, WebDriver can override incomaptible policies. If you disable or don't configure this policy, WebDriver isn't allowed to override incompatible policies.
PaymentMethodQueryEnabled Allow websites to query for available payment methods
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PaymentMethodQueryEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 80, Windows 7 or later
- Template
- msedge.admx
Allows you to set whether websites can check if the user has payment methods saved. If you disable this policy, websites that use PaymentRequest.canMakePayment or PaymentRequest.hasEnrolledInstrument API will be informed that no payment methods are available. If you enable this policy or don't set this policy, websites can check if the user has payment methods saved.
WebAuthenticationRemoteDesktopAllowedOrigins Allowed Origins for Proxied WebAuthn Requests from Remote Desktop Applications.
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\WebAuthenticationRemoteDesktopAllowedOrigins
- Supported on
- Microsoft Edge version 137, Windows 7 or later
- Template
- msedge.admx
This policy defines a list of allowed HTTPS origins for remote desktop client applications that initiate WebAuthn API requests from a browsing session on a remote host. Origins specified in this policy can request WebAuthn authentication for Relying Party IDs (RP IDs) they wouldn't typically be authorized to claim. Only HTTPS origins are supported. Wildcards aren't permitted. Entries that don't meet these requirements will be ignored. For more information about the WebAuthn Remote Desktop Support feature, see https://github.com/w3c/webauthn/wiki/Explainer:-Remote-Desktop-Support/a4e158c569f456c759d0ddd294a9015bd4d4eb9a. Example value: https://server:8080/
AllowPopupsDuringPageUnload Allows a page to show popups during its unloading (obsolete)
When the policy is set to disabled or unset, pages aren't allowed to show popups while they're being unloaded.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AllowPopupsDuringPageUnload
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 78-87, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 87. This policy allows an admin to specify that a page can show popups during its unloading. When the policy is set to enabled, pages are allowed to show popups while they're being unloaded. When the policy is set to disabled or unset, pages aren't allowed to show popups while they're being unloaded. This restriction is as per the spec: (https://html.spec.whatwg.org/#apis-for-creating-and-navigating-browsing-contexts-by-name). This policy was removed in Microsoft Edge 88 and is ignored if set.
NewBaseUrlInheritanceBehaviorAllowed Allows enabling the feature NewBaseUrlInheritanceBehavior (obsolete)
If you enable or don't configure this policy, it allows enabling NewBaseUrlInheritanceBehavior.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NewBaseUrlInheritanceBehaviorAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 123-135, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 135. NewBaseUrlInheritanceBehavior is a Microsoft Edge feature that causes about:blank and about:srcdoc frames to consistently inherit their base url values via snapshots of their initiator's base url. If you disable this policy, it prevents users or Microsoft Edge variations from enabling NewBaseUrlInheritanceBehavior, in case compatibility issues are discovered. If you enable or don't configure this policy, it allows enabling NewBaseUrlInheritanceBehavior. The policy became obsolete starting from Microsoft Edge version 136, but the NewBaseUrlInheritanceBehaviorAllowed feature was removed in Microsoft Edge version 123.
ThrottleNonVisibleCrossOriginIframesAllowed Allows enabling throttling of non-visible, cross-origin iframes (obsolete)
If you enable or don't configure this policy, users can opt in to throttling.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ThrottleNonVisibleCrossOriginIframesAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 116-123, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 123. Throttling of cross-origin frames that are display:none and nonvisible is a feature designed to make cross-process and same-process cross-origin frames consistent in their rendering behavior. For more information on cross-process vs. same-process throttling, see https://go.microsoft.com/fwlink/?linkid=2239564. This enterprise policy allows administrators to control whether their users can turn on the additional throttling or not. If you enable or don't configure this policy, users can opt in to throttling. If you disable this policy, users can't enable throttling.
AllowSystemNotifications Allows system notifications
If set to True or not set, Microsoft Edge is allowed to use system notifications.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AllowSystemNotifications
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 117, Windows 7 or later
- Template
- msedge.admx
Lets you use system notifications instead of Microsoft Edge's embedded Message Center on Windows and Linux. If set to True or not set, Microsoft Edge is allowed to use system notifications. If set to False, Microsoft Edge won't use system notifications. Microsoft Edge's embedded Message Center is used as a fallback.
AppCacheForceEnabled Allows the AppCache feature to be re-enabled, even if it's turned off by default (obsolete)
If you set this policy to true, the AppCache is enabled, even when AppCache in Microsoft Edge isn't available by default.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AppCacheForceEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 84-96, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 96. Support for AppCache and this policy was removed from Microsoft Edge starting in version 97. If you set this policy to true, the AppCache is enabled, even when AppCache in Microsoft Edge isn't available by default. If you set this policy to false, or don't set it, AppCache follows defaults of Microsoft Edge.
EditFavoritesEnabled Allows users to edit favorites
This is the default behavior if you don't configure the policy.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EditFavoritesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enable this policy to let users add, remove, and modify favorites. This is the default behavior if you don't configure the policy. Disable this policy to stop users from adding, removing, or modifying favorites. They can still use existing favorites.
LiveVideoTranslationEnabled Allows users to translate videos to different languages.
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- LiveVideoTranslationEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 141, Windows 7 or later
- Template
- msedge.admx
This policy configures the on-device real-time video translation feature in Microsoft Edge. With this feature, users can watch videos translated into their selected language in real time. When a user selects the Translate icon and chooses a source (video language) and target language (translated language), translation components are downloaded on first use (approximately 200 MB per language pair). These components can be updated periodically to improve performance and translation quality. Translation is performed locally on the user’s device and no data is sent outside of the device. The feature is available only for non-DRM videos, on supported high-end devices, with select language pairs, and in select regions. For more information, see https://www.microsoft.com/en-us/edge/features/real-time-video-translation. If you enable or don’t configure this policy, the on-device real-time video translation feature is enabled and users will see the Translate button when hovering over videos. If you disable this policy, the on-device real-time video translation feature is disabled and the Translate button is not shown.
AlwaysOpenPdfExternally Always open PDF files externally
If you don't configure this policy or disable it, Microsoft Edge opens PDF files (unless the user disables it).
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AlwaysOpenPdfExternally
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Disables the internal PDF viewer in Microsoft Edge. If you enable this policy Microsoft Edge treats PDF files as downloads and lets users open them with the default application. If Microsoft Edge is the default PDF reader, PDF files aren't downloaded and continue to open in Microsoft Edge. If you don't configure this policy or disable it, Microsoft Edge opens PDF files (unless the user disables it).
InternetExplorerIntegrationAlwaysUseOSCapture Always use the OS capture engine to avoid issues with capturing Internet Explorer mode tabs
If you disable or don't configure this policy, Microsoft Edge uses the Browser capture engine for browser windows in the same process.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerIntegrationAlwaysUseOSCapture
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 106, Windows 7 or later
- Template
- msedge.admx
Configure this policy to control whether Microsoft Edge will use the "OS capture engine" or the "Browser capture engine" when capturing browser windows in the same process using the screen-share APIs. You should configure this policy if you want to capture the contents of Internet Explorer mode tabs. However, enabling this policy may negatively impact performance when capturing browser windows in the same process. This policy only affects window capture, not tab capture. The contents of Internet Explorer mode tabs won't be captured when you choose to capture only a single tab, even if you configure this policy. If you enable this policy, Microsoft Edge always uses the OS capture engine for window capture. Internet Explorer mode tabs will have their contents captured. If you disable or don't configure this policy, Microsoft Edge uses the Browser capture engine for browser windows in the same process. Internet Explorer mode tabs in these windows won't have their contents captured. To learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2174004
PromptForDownloadLocation Ask where to save downloaded files
If you enable this policy, the user is asked where to save each file before downloading; if you don't configure it, files are saved automatically to the default location, without asking the user. If you don't configure this policy, the user can change this setting.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PromptForDownloadLocation
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Set whether to ask where to save a file before downloading it. If you enable this policy, the user is asked where to save each file before downloading; if you don't configure it, files are saved automatically to the default location, without asking the user. If you don't configure this policy, the user can change this setting.
AutoLaunchProtocolsComponentEnabled AutoLaunch Protocols Component Enabled
If you enable or don't configure this policy, the AutoLaunch Protocols component is enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AutoLaunchProtocolsComponentEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, this component is enabled.
- Supported on
- Microsoft Edge version 96, Windows 7 or later
- Template
- msedge.admx
Specifies whether the AutoLaunch Protocols component should be enabled. This component allows Microsoft to provide a list similar to that of the 'AutoLaunchProtocolsFromOrigins' (Define a list of protocols that can launch an external application from listed origins without prompting the user) policy, allowing certain external protocols to launch without prompt or blocking certain protocols (on specified origins). By default, this component is enabled. If you enable or don't configure this policy, the AutoLaunch Protocols component is enabled. If you disable this policy, the AutoLaunch Protocols component is disabled.
AutoImportAtFirstRun Automatically import another browser's data and settings at first run
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AutoImportAtFirstRun
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
0Automatically imports all supported datatypes and settings from the default browser1Automatically imports all supported datatypes and settings from Internet Explorer2Automatically imports all supported datatypes and settings from Google Chrome3Automatically imports all supported datatypes and settings from Safari4Disables automatic import, and the import section of the first-run experience is skipped5Automatically imports all supported datatypes and settings from Mozilla FirefoxIf you enable this policy, all supported datatypes and settings from the specified browser are silently and automatically imported at first run. During the First Run Experience, the import section is also skipped. The browser data from Microsoft Edge Legacy is always silently migrated at the first run, irrespective of the value of this policy. If you set this policy to 'FromDefaultBrowser' to FromDefaultBrowser, then the datatypes corresponding to the default browser on the managed device are imported. If the browser specified as the value of this policy isn't present in the managed device, Microsoft Edge simply skips the import without any notification to the user. If you set this policy to DisabledAutoImport, the import section of the first-run experience is skipped entirely, and Microsoft Edge doesn't import browser data and settings automatically. If you set this policy to FromInternetExplorer, the following datatypes are imported from Internet Explorer: 1. Favorites or bookmarks 2. Saved passwords 3. Search engines 4. Browsing history 5. Home page If you set this policy to FromGoogleChrome, the following datatypes are imported from Google Chrome: 1. Favorites 2. Saved passwords 3. Addresses and more 4. Payment info 5. Browsing history 6. Settings 7. Pinned and Open tabs 8. Extensions 9. Cookies Note: For more details on what is imported from Google Chrome, see https://go.microsoft.com/fwlink/?linkid=2120835 If you set this policy to FromSafari, user data is no longer imported into Microsoft Edge. This is because of the way in which Full Disk Access works on Mac. On macOS Mojave and above, it's no longer possible to have automated and unattended import of Safari data into Microsoft Edge. Starting with Microsoft Edge version 83, if you set this policy to 'FromMozillaFirefox', the following datatypes are imported from Mozilla Firefox: 1. Favorites or bookmarks 2. Saved passwords 3. Addresses and more 4. Browsing History If you want to restrict specific datatypes from getting imported onto the managed devices, use this policy with other policies such as 'ImportAutofillFormData' (Allow importing of autofill form data), 'ImportBrowserSettings' (Allow importing of browser settings), 'ImportFavorites' (Allow importing of favorites), and so on. Policy options mapping: * FromDefaultBrowser (0) = Automatically imports all supported datatypes and settings from the default browser * FromInternetExplorer (1) = Automatically imports all supported datatypes and settings from Internet Explorer * FromGoogleChrome (2) = Automatically imports all supported datatypes and settings from Google Chrome * FromSafari (3) = Automatically imports all supported datatypes and settings from Safari * DisabledAutoImport (4) = Disables automatic import, and the import section of the first-run experience is skipped * FromMozillaFirefox (5) = Automatically imports all supported datatypes and settings from Mozilla Firefox Use the preceding information when configuring this policy.
M365LinksAutoOpenCopilotEnabled Automatically open Copilot side pane with contextual insights for links opened from Outlook
If you enable this policy or don't configure it, the Copilot side pane opens automatically when users open eligible links from Outlook emails sent from the same tenant.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- M365LinksAutoOpenCopilotEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 148, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Microsoft Edge automatically opens the Microsoft Copilot side pane when users open eligible web links from Outlook emails sent from the same tenant. Starting in Microsoft Edge version 148, eligible links from Outlook emails sent from the same tenant can open with the Copilot side pane. Copilot can use the originating Outlook email as context to surface relevant insights and suggested next steps alongside the web content. If you enable this policy or don't configure it, the Copilot side pane opens automatically when users open eligible links from Outlook emails sent from the same tenant. If you disable this policy, the Copilot side pane doesn't open automatically for those links. This policy is not yet supported. When support becomes available, eligible links from Outlook emails sent from the same tenant can open with the Copilot side pane.
InternetExplorerIntegrationZoneIdentifierMhtFileAllowed Automatically open downloaded MHT or MHTML files from the web in Internet Explorer mode
If you disable or don't configure this policy, MHT or MHTML files that are downloaded from the web won't automatically open in Internet Explorer mode.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerIntegrationZoneIdentifierMhtFileAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 117, Windows 7 or later
- Template
- msedge.admx
Microsoft Security BaselineInternetExplorerIntegrationZoneIdentifierMhtFileAllowed = 0
This policy controls whether MHT or MHTML files that are downloaded from the web are automatically opened in Internet Explorer mode. If you enable this policy, the MHT or MHTML files that are downloaded from the web can be opened in both Microsoft Edge and Internet Explorer mode to provide the best user experience. If you disable or don't configure this policy, MHT or MHTML files that are downloaded from the web won't automatically open in Internet Explorer mode. To learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210
URLBlocklist Block access to a list of URLs
If you don't configure this policy, no URLs are blocked.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\URLBlocklist
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Defines a list of sites, based on URL patterns, that are blocked (your users can't load them). Format the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322. You can define exceptions in the 'URLAllowlist' (Define a list of allowed URLs) policy. These policies are limited to 1000 entries; subsequent entries are ignored. Blocking internal 'edge://*' and 'chrome-untrusted://*' URLs isn't recommended - this may lead to unexpected errors. This policy doesn't prevent the page from updating dynamically through JavaScript. For example, if you block 'contoso.com/abc', users can visit 'contoso.com' and select on a link to visit 'contoso.com/abc', as long as the page doesn't refresh. If you don't configure this policy, no URLs are blocked. This policy doesn't work as expected with file://* wildcards. Example value: contoso.com https://ssl.server.com hosting.com/bad_path https://server:8080/path .exact.hostname.com custom_scheme:* *
InPrivateModeUrlBlocklist Block access to a list of URLs in InPrivate mode.
If 'InPrivateModeUrlAllowlist' is configured and this policy is not configured, only URLs on the allowlist can be opened in InPrivate mode.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\InPrivateModeUrlBlocklist
- Supported on
- Microsoft Edge version 147, Windows 7 or later
- Template
- msedge.admx
This policy controls which URLs are blocked from loading in InPrivate mode in Microsoft Edge. Administrators can specify a list of URL patterns that are blocked when users browse in InPrivate mode. For information about the supported URL pattern format, see https://go.microsoft.com/fwlink/?linkid=2095322. If both 'InPrivateModeUrlBlocklist' (Block access to a list of URLs in InPrivate mode.) and 'InPrivateModeUrlAllowlist' (Allow access to a list of URLs in InPrivate mode.) are configured, the allowlist takes precedence. - URLs that match the allowlist are allowed. - URLs that match the blocklist but not the allowlist are blocked. - URLs that match neither list follow the behavior defined by the general 'URLBlocklist' (Block access to a list of URLs) and 'URLAllowlist' (Define a list of allowed URLs) policies. If 'InPrivateModeUrlAllowlist' is configured and this policy is not configured, only URLs on the allowlist can be opened in InPrivate mode. If 'InPrivateModeAvailability' (Configure InPrivate mode availability) is set to disallow (value 1) and 'InPrivateModeUrlAllowlist' is configured, InPrivate mode is available only for URLs that match the allowlist. This policy applies only to InPrivate mode. To block URLs across all browsing modes, use 'URLBlocklist'. This policy supports up to 1000 entries. Example value: example.com https://ssl.server.com hosting.com/bad_path https://server:8080/path .exact.hostname.com file://* custom_scheme:* *
CollectionsServicesAndExportsBlockList Block access to a specified list of services and export targets in Collections
If you don't configure this policy, no restrictions on the acceptable services and export targets are enforced.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\CollectionsServicesAndExportsBlockList
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
List specific services and export targets that users can't access in the Collections feature in Microsoft Edge. This includes displaying additional data from Bing and exporting collections to Microsoft products or external partners. If you enable this policy, services and export targets that match the given list are blocked. If you don't configure this policy, no restrictions on the acceptable services and export targets are enforced. Policy options mapping: * pinterest_suggestions (pinterest_suggestions) = Pinterest suggestions * collections_share (collections_share) = Sharing of Collections * local_pdf (local_pdf) = Save local PDFs in Collections to OneDrive * send_word (send_word) = Send collection to Microsoft Word * send_excel (send_excel) = Send collection to Microsoft Excel * send_onenote (send_onenote) = Send collection to Microsoft OneNote * send_pinterest (send_pinterest) = Send collection to Pinterest Use the preceding information when configuring this policy. Example value: collections_share local_pdf send_word send_excel send_onenote
SensorsBlockedForUrls Block access to sensors on specific sites
If you don't configure this policy, the global default value from the 'DefaultSensorsSetting' (Default sensors setting) policy (if set) or the user's personal configuration is used for all sites.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\SensorsBlockedForUrls
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
Define a list of sites, based on URL patterns, that can't access sensors such as motion and light sensors. If you don't configure this policy, the global default value from the 'DefaultSensorsSetting' (Default sensors setting) policy (if set) or the user's personal configuration is used for all sites. For URL patterns that don't match this policy, the following order of precedence is used: The 'SensorsAllowedForUrls' (Allow access to sensors on specific sites) policy (if there's a match), the 'DefaultSensorsSetting' policy (if set), or the user's personal settings. The URL patterns defined in this policy can't conflict with those configured in the 'SensorsAllowedForUrls' policy. You can't allow and block a URL. For detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Example value: https://www.contoso.com [*.]contoso.edu
BingAdsSuppression Block all ads on Bing search results
If you don't configure this policy, then the default experience has ads in the search results on bing.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- BingAdsSuppression
- Enabled / Disabled
- 1 / 0
- Stated default
- SafeSearch is set to 'Moderate' by default and can be changed by the user.
- Supported on
- Microsoft Edge version 83, Windows 7 or later
- Template
- msedge.admx
Enables an ad-free search experience on Bing.com If you enable this policy, then a user can search on bing.com and have an ad-free search experience. At the same time, the SafeSearch setting is set to 'Strict' and can't be changed by the user. If you don't configure this policy, then the default experience has ads in the search results on bing.com. SafeSearch is set to 'Moderate' by default and can be changed by the user. This policy is only available for K-12 SKUs that are identified as EDU tenants by Microsoft. Refer to https://go.microsoft.com/fwlink/?linkid=2119711 to learn more about this policy or if the following scenarios apply to you: * You have an EDU tenant, but the policy doesn't work. * You had your IP allowlisted for having an ad free search experience. * You were experiencing an ad-free search experience on Microsoft Edge Legacy and want to upgrade to the new version of Microsoft Edge.
ClipboardBlockedForUrls Block clipboard use on specific sites
Leaving the policy unset means 'DefaultClipboardSetting' (Default clipboard site permission) applies for all sites if it's set.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ClipboardBlockedForUrls
- Supported on
- Microsoft Edge version 109, Windows 7 or later
- Template
- msedge.admx
Configure the list of URL patterns that specify which sites can use the clipboard site permission. Setting the policy lets you create a list of URL patterns that specify sites that can't use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users can still paste using keyboard shortcuts because this isn't controlled by the clipboard site permission. Leaving the policy unset means 'DefaultClipboardSetting' (Default clipboard site permission) applies for all sites if it's set. If it isn't set, the user's personal setting applies. For more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. Example value: https://www.example.com [*.]example.edu
SmartActionsBlockList Block smart actions for a list of services
If you disable or don't configure this policy: - The smart action in the mini and full context menu is enabled for all profiles.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\SmartActionsBlockList
- Supported on
- Microsoft Edge version 89, Windows 7 or later
- Template
- msedge.admx
List specific services, such as PDFs, and websites that don't show smart actions. (Smart actions are actions like "define" which are available in full and mini context menus in Microsoft Edge.) If you enable the policy: - The smart action in the mini and full context menu is disabled for all profiles for services that match the given list. - Users won't see the smart action in the mini and full context menu on text selection for services that match the given list. - In Microsoft Edge settings, the smart action in the mini and full context menu is disabled for services that match the given list. If you disable or don't configure this policy: - The smart action in the mini and full context menu is enabled for all profiles. - Users will see the smart action in the mini and full context menu on text selection. - In Microsoft Edge settings, the smart action in the mini and full context menu is enabled. Policy options mapping: * smart_actions (smart_actions) = Smart actions in pdfs and on websites * smart_actions_website (smart_actions_website) = Smart actions on websites * smart_actions_pdf (smart_actions_pdf) = Smart actions in PDF Use the preceding information when configuring this policy. Example value: smart_actions smart_actions_website smart_actions_pdf
SerialBlockedForUrls Block the Serial API on specific sites
If not configured, Microsoft Edge uses the value from the DefaultSerialGuardSetting policy (if set), or the user's settings.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\SerialBlockedForUrls
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
Specifies URL patterns for sites that aren't allowed to request access to a serial port. If not configured, Microsoft Edge uses the value from the DefaultSerialGuardSetting policy (if set), or the user's settings. For unmatched sites, the following order applies: 1. SerialAskForUrls (if matched). 2. DefaultSerialGuardSetting (if set). 3. User's settings. URL patterns in this policy must not conflict with those in SerialAskForUrls. This policy takes precedence. For detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Example value: https://www.contoso.com [*.]contoso.edu
BlockThirdPartyCookies Block third party cookies
If you don't configure this policy, third-party cookies are allowed by default, but users can change this setting.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- BlockThirdPartyCookies
- Enabled / Disabled
- 1 / 0
- Stated default
- If you don't configure this policy, third-party cookies are allowed by default, but users can change this setting. In InPrivate, third-party cookies are blocked by default and can only be allowed at the site level using the CookiesAllowedForUrls policy.
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
This policy controls whether third-party cookies are blocked in regular browsing sessions. If you enable this policy, web page elements that are not from the domain shown in the address bar can't set cookies. If you disable this policy, third-party cookies are allowed, including from domains other than the one shown in the address bar. If you don't configure this policy, third-party cookies are allowed by default, but users can change this setting. Note: This policy doesn't apply in InPrivate mode. In InPrivate, third-party cookies are blocked by default and can only be allowed at the site level using the CookiesAllowedForUrls policy.
TrackingPrevention Block tracking of users' web-browsing activity
If you disable this policy or don't configure it, users set their own level of tracking prevention.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- TrackingPrevention
- Supported on
- Microsoft Edge version 78, Windows 7 or later
- Template
- msedge.admx
0Off (no tracking prevention)1Basic (blocks harmful trackers, content and ads will be personalized)2Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)3Strict (blocks harmful trackers and majority of trackers from all sites; content and ads will have minimal personalization. Some parts of sites might not work)Lets you decide whether to block websites from tracking users' web-browsing activity. If you disable this policy or don't configure it, users set their own level of tracking prevention. Policy options mapping: * TrackingPreventionOff (0) = Off (no tracking prevention) * TrackingPreventionBasic (1) = Basic (blocks harmful trackers, content and ads will be personalized) * TrackingPreventionBalanced (2) = Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized) * TrackingPreventionStrict (3) = Strict (blocks harmful trackers and majority of trackers from all sites; content and ads will have minimal personalization. Some parts of sites might not work) Use the preceding information when configuring this policy.
BrowserSignin Browser sign-in settings
If you don't configure this policy, users can decide if they want to enable the browser sign-in option and use it as they see fit.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- BrowserSignin
- Stated default
- Signing in to the browser doesn't mean that sync is turned on by default; the user must separately opt in to use this feature. By default, this allows the user to choose whether they want to sync to their account, unless sync is disabled by the domain admin or with the 'SyncDisabled' policy.
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
0Disable browser sign-in1Enable browser sign-in2Force users to sign-in to use the browser (all profiles)Specify whether a user can sign into Microsoft Edge with their account and use account-related services like sync and single sign-on (SSO). To control the availability of sync, use the 'SyncDisabled' (Disable synchronization of data using Microsoft sync services) policy instead. If you set this policy to 'Disable', make sure that you also set the 'NonRemovableProfileEnabled' (Configure whether a user always has a default profile automatically signed in with their work or school account) policy to disabled because 'NonRemovableProfileEnabled' disables the creation of an automatically signed in browser profile. If both policies are set, Microsoft Edge uses the 'Disable browser sign-in' policy and behaves as if 'NonRemovableProfileEnabled' is set to disabled. If you set this policy to 'Enable', users can sign in to the browser. Signing in to the browser doesn't mean that sync is turned on by default; the user must separately opt in to use this feature. If you set this policy to 'Force', users must sign in to a profile to use the browser. By default, this allows the user to choose whether they want to sync to their account, unless sync is disabled by the domain admin or with the 'SyncDisabled' policy. The default value of 'BrowserGuestModeEnabled' (Enable guest mode) policy is set to false. If you don't configure this policy, users can decide if they want to enable the browser sign-in option and use it as they see fit. Policy options mapping: * Disable (0) = Disable browser sign-in * Enable (1) = Enable browser sign-in * Force (2) = Force users to sign-in to use the browser (all profiles) Use the preceding information when configuring this policy.
BrowsingDataLifetime Browsing Data Lifetime Settings
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- BrowsingDataLifetime
- Supported on
- Microsoft Edge version 89, Windows 7 or later
- Template
- msedge.admx
This policy controls how long specific types of browsing data are retained. If Sync is enabled, this policy has no effect. You can specify the following data types: 'browsing_history' 'download_history' 'cookies_and_other_site_data' 'cached_images_and_files' 'password_signin' 'autofill' 'site_settings' 'hosted_app_data' Microsoft Edge periodically deletes data of the selected types that's older than the value set by 'time_to_live_in_hours'. Expired data is removed 15 seconds after browser startup and every hour while the browser is running. Note: Deleting cookies using this policy doesn't sign the user out of their profile, the user stays signed in. Example value: [ { "data_types": [ "browsing_history" ], "time_to_live_in_hours": 24 }, { "data_types": [ "password_signin", "autofill" ], "time_to_live_in_hours": 12 } ]
BrowsingWithCopilotAllowList Browsing with Copilot Allowed URLs
If you disable or do not configure this policy, browsing with Copilot is unavailable on all sites, even if the 'AllowBrowsingWithCopilot' (Controls the availability of browsing with Copilot in Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\BrowsingWithCopilotAllowList
- Supported on
- Microsoft Edge version 148, Windows 7 or later
- Template
- msedge.admx
Allows you to define a list of URLs where browsing with Copilot is available. Users cannot modify this list. If you enable this policy, browsing with Copilot is available only on the sites specified in the list. To allow a broader set of sites while blocking specific exceptions, configure this policy together with the 'BrowsingWithCopilotBlockList' (Browsing with Copilot Blocked URLs) policy. For example, you can include '*' to allow all sites, and then use the block list to restrict access to specific URLs. You can define exceptions based on schemes, subdomains, ports, or origins. When multiple filters apply, the most specific match determines whether a URL is allowed or blocked. The block list takes precedence over the allow list. If you disable or do not configure this policy, browsing with Copilot is unavailable on all sites, even if the 'AllowBrowsingWithCopilot' (Controls the availability of browsing with Copilot in Microsoft Edge.) policy is enabled. Browsing with Copilot supports only HTTP and HTTPS protocols. Wildcards (*) are supported, and subdomains are matched even without wildcards. This policy applies only to the site origin; any path specified in the URL pattern is ignored. For guidance on formatting URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Example value: https://www.contoso.com [*.]contoso.edu contoso.net login.contoso.us
BrowsingWithCopilotBlockList Browsing with Copilot Blocked URLs
If you don't configure this policy, no exceptions are applied to 'BrowsingWithCopilotAllowList'.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\BrowsingWithCopilotBlockList
- Supported on
- Microsoft Edge version 148, Windows 7 or later
- Template
- msedge.admx
Controls the list of URLs where browsing with Copilot is blocked. Users can't modify this list. Use this policy to define exceptions to broader allowlists. For example, you can set 'BrowsingWithCopilotAllowList' (Browsing with Copilot Allowed URLs) to '*' to allow all sites, and then use this policy to block access to specific URLs. This policy supports blocking by scheme, subdomain, or port. When multiple URL patterns apply, the most specific match determines whether access is allowed or blocked. Blocklist entries take precedence over allowlist entries. If you don't configure this policy, no exceptions are applied to 'BrowsingWithCopilotAllowList'. Browsing with Copilot supports only HTTP and HTTPS protocols. Wildcards (*) are supported, and subdomains are matched even without wildcards. URL matching is based on the site origin only; any path specified in the pattern is ignored. For information about URL pattern format, see https://go.microsoft.com/fwlink/?linkid=2095322. Example value: https://www.contoso.com [*.]contoso.edu contoso.net login.contoso.us
CECPQ2Enabled CECPQ2 post-quantum key-agreement enabled for TLS (obsolete)
If you enable or don't configure this policy, then Microsoft Edge follows the default rollout process for CECPQ2, a post-quantum key-agreement algorithm in Transport Layer Security (TLS).
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- CECPQ2Enabled
- Enabled / Disabled
- 1 / 0
- Stated default
- It served to disable CECPQ2, but CECPQ2 is disabled by default.
- Supported on
- Microsoft Edge version 93-113, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 113. This policy was removed in Microsoft Edge version 114 and is ignored if set. It served to disable CECPQ2, but CECPQ2 is disabled by default. A separate policy is introduced to control the rollout of the replacement of CECPQ2. That replacement is a combination of the standard key-agreement X25519 with NIST's chosen post-quantum KEM, called "Kyber". If you enable or don't configure this policy, then Microsoft Edge follows the default rollout process for CECPQ2, a post-quantum key-agreement algorithm in Transport Layer Security (TLS). CECPQ2 results in larger TLS messages that, in rare cases, can trigger bugs in some networking hardware. This policy can be set to False to disable CECPQ2 while networking issues are resolved. This policy is a temporary measure and is removed in future versions of Microsoft Edge.
RSAKeyUsageForLocalAnchorsEnabled Check RSA key usage for server certificates issued by local trust anchors (obsolete)
If this policy isn't configured, Microsoft Edge behaves as if the policy is enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RSAKeyUsageForLocalAnchorsEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- This policy is available for administrators to preview the behavior of a future release, which will enable this check by default.
- Supported on
- Microsoft Edge version 123-135, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 135. The X.509 key usage extension declares how the key in a certificate can be used. These instructions ensure certificates aren't used in an unintended context, which protects against a class of cross-protocol attacks on HTTPS and other protocols. HTTPS clients must verify that server certificates match the connection's TLS parameters. Starting in Microsoft Edge 124, this check is always enabled. Microsoft Edge 123 and earlier have the following behavior: If this policy is set to enabled, Microsoft Edge performs this key check. This helps prevent attacks where an attacker manipulates the browser into interpreting a key in ways that the certificate owner didn't intend. If this policy is set to disabled, Microsoft Edge skips this key check-in HTTPS connections that negotiate TLS 1.2 and use an RSA certificate that chains to a local trust anchor. Examples of local trust anchors include policy-provided or user-installed root certificates. In all other cases, the check is performed independent of this policy's setting. If this policy isn't configured, Microsoft Edge behaves as if the policy is enabled. This policy is available for administrators to preview the behavior of a future release, which will enable this check by default. At that point, this policy will remain temporarily available for administrators that need more time to update their certificates to meet the new RSA key usage requirements. Connections that fail this check will fail with the error ERR_SSL_KEY_USAGE_INCOMPATIBLE. Sites that fail with this error likely have a misconfigured certificate. Modern ECDHE_RSA cipher suites use the "digitalSignature" key usage option, while legacy RSA decryption cipher suites use the "keyEncipherment" key usage option. If uncertain, administrators should include both in RSA certificates meant for HTTPS. The policy has been obsoleted starting from Microsoft Edge version 136, but the key check has been always enabled since Microsoft Edge version 124.
ClearBrowsingDataOnExit Clear browsing data when Microsoft Edge closes
Note that if you enable this policy, it takes precedence over how you configured 'DefaultCookiesSetting' (Configure cookies) If you disable or don't configure this policy, users can configure the Clear browsing data option in Settings. If you enable this policy, don't configure the 'AllowDeletingBrowserHistory' (Enable deleting browser and download history) or the 'ClearCachedImagesAndFilesOnExit' (Clear cached images and files when Microsoft Edge closes) policy, because they all deal with deleting browsing data.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ClearBrowsingDataOnExit
- Enabled / Disabled
- 1 / 0
- Stated default
- Microsoft Edge doesn't clear the browsing data by default when it closes.
- Supported on
- Microsoft Edge version 78, Windows 7 or later
- Template
- msedge.admx
Microsoft Edge doesn't clear the browsing data by default when it closes. Browsing data includes information entered in forms, passwords, and even the websites visited. If you enable this policy, all browsing data is deleted each time Microsoft Edge closes. Note that if you enable this policy, it takes precedence over how you configured 'DefaultCookiesSetting' (Configure cookies) If you disable or don't configure this policy, users can configure the Clear browsing data option in Settings. If you enable this policy, don't configure the 'AllowDeletingBrowserHistory' (Enable deleting browser and download history) or the 'ClearCachedImagesAndFilesOnExit' (Clear cached images and files when Microsoft Edge closes) policy, because they all deal with deleting browsing data. If you configure the preceding policies and this policy, all browsing data is deleted when Microsoft Edge closes, regardless of how you configured 'AllowDeletingBrowserHistory' or 'ClearCachedImagesAndFilesOnExit'. To exclude cookies from being deleted on exit, configure the 'SaveCookiesOnExit' (Save cookies when Microsoft Edge closes) policy. To exclude passwords from being deleted on exit, configure the 'PasswordDeleteOnBrowserCloseEnabled' (Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes) policy.
ClearCachedImagesAndFilesOnExit Clear cached images and files when Microsoft Edge closes
If you don't configure this policy, users can choose whether cached images and files are cleared on exit.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ClearCachedImagesAndFilesOnExit
- Enabled / Disabled
- 1 / 0
- Stated default
- Microsoft Edge doesn't clear cached images and files by default when it closes.
- Supported on
- Microsoft Edge version 83, Windows 7 or later
- Template
- msedge.admx
Microsoft Edge doesn't clear cached images and files by default when it closes. If you enable this policy, cached images and files are deleted each time Microsoft Edge closes. If you disable this policy, users can't configure the cached images and files option in edge://settings/clearBrowsingDataOnClose. If you don't configure this policy, users can choose whether cached images and files are cleared on exit. If you disable this policy, don't enable the 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) policy, because they both deal with deleting data. If you configure both, the 'ClearBrowsingDataOnExit' policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured 'ClearCachedImagesAndFilesOnExit' (Clear cached images and files when Microsoft Edge closes).
InternetExplorerModeClearDataOnExitEnabled Clear history for IE and IE mode every time you exit
If you disable or don't configure this policy, Internet Explorer browsing history won't be cleared on browser exit.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerModeClearDataOnExitEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 111, Windows 7 or later
- Template
- msedge.admx
This policy controls whether browsing history is deleted from Internet Explorer and Internet Explorer mode every time Microsoft Edge is closed. Users can configure this setting in the 'Clear browsing data for Internet Explorer' option in the Privacy, search, and services menu of Settings. If you enable this policy, Internet Explorer browsing history will be cleared on browser exit. If you disable or don't configure this policy, Internet Explorer browsing history won't be cleared on browser exit.
OnBulkDataEntryEnterpriseConnector Configuration policy for bulk data entry for Microsoft Edge for Business Data Loss Prevention Connectors
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- OnBulkDataEntryEnterpriseConnector
- Supported on
- Microsoft Edge version 137, Windows 7 or later
- Template
- msedge.admx
Specifies the list of Microsoft Edge for Business Data Loss Prevention Connector service settings that apply when users paste data from the clipboard or drag and drop web content into Microsoft Edge. Connector Fields 1. url_list, tags, enable, disable These fields determine whether the connector sends data for analysis when content is entered on a specific page, and which tags to include in the analysis request. A tag associated with an enable pattern is included in the request if the page URL matches the pattern—unless a corresponding disable pattern also matches. Analysis is triggered if at least one tag is included in the request. 2. service_provider Identifies the analysis service provider the configuration applies to. 3. block_until_verdict If set to 1, Microsoft Edge waits for a response from the analysis service before giving the page access to the data. Any other integer value allows the page to access the data immediately. 4. default_action If set to block, Microsoft Edge denies page access to the data if an error occurs while contacting the analysis service. Any other value permits the page to access the data. 5. minimum_data_size Specifies the minimum size (in bytes) that the entered data must meet or exceed to be scanned. Default: 100 bytes if the field isn't set. This policy requires further setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2320413. Example value: [ { "block_until_verdict": 0, "default_action": "allow", "disable": [ { "tags": [ "malware" ], "url_list": [ "*.us.com" ] } ], "enable": [ { "tags": [ "malware" ], "url_list": [ "*" ] }, { "tags": [ "dlp" ], "url_list": [ "*.them.com", "*.others.com" ] } ], "minimum_data_size": 100, "service_provider": "local_system_agent" } ]
OnFileAttachedEnterpriseConnector Configuration policy for files attached for Microsoft Edge for Business Data Loss Prevention Connectors
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- OnFileAttachedEnterpriseConnector
- Supported on
- Microsoft Edge version 137, Windows 7 or later
- Template
- msedge.admx
Specifies the list of Microsoft Edge for Business Data Loss Prevention Connectors service settings that apply when users attach files in Microsoft Edge. Connector Fields 1. url_list, tags, enable, disable These fields determine whether the connector sends data for analysis when content is entered on a specific page, and which tags to include in the analysis request. A tag associated with an enable pattern is included in the request if the page URL matches the pattern—unless a corresponding disable pattern also matches. Analysis is triggered if at least one tag is included in the request. 2. service_provider Identifies the analysis service provider the configuration applies to. 3. block_until_verdict If set to 1, Microsoft Edge waits for a response from the analysis service before giving the page access to the data. Any other integer value allows the page to access the data immediately. 4. default_action If set to block, Microsoft Edge denies page access to the data if an error occurs while contacting the analysis service. Any other value permits the page to access the data. This policy requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2320413. Example value: [ { "block_until_verdict": 0, "default_action": "allow", "disable": [ { "tags": [ "malware" ], "url_list": [ "*.us.com" ] } ], "enable": [ { "tags": [ "malware" ], "url_list": [ "*" ] }, { "tags": [ "dlp" ], "url_list": [ "*.them.com", "*.others.com" ] } ], "service_provider": "local_system_agent" } ]
OnSecurityEventEnterpriseConnector Configuration policy for Microsoft Edge for Business Reporting Connectors
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- OnSecurityEventEnterpriseConnector
- Supported on
- Microsoft Edge version 139, Windows 7 or later
- Template
- msedge.admx
Defines the Microsoft Edge for Business Reporting Connectors service settings that apply when a security event occurs in Microsoft Edge. These events include negative verdicts from Data Loss Prevention Connectors, password reuse, navigation to unsafe pages, and other security-sensitive actions. The service_provider field specifies the reporting service provider. The enabled_event_names field lists the security events enabled for that provider. This policy can only be configured through the Microsoft 365 Admin Center. It requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2325446. Example value: [ { "enabled_event_names": [ "passwordChangedEvent", "sensitiveDataEvent" ], "enabled_opt_in_events": [ { "name": "loginEvent", "url_patterns": [ "*" ] }, { "name": "passwordBreachEvent", "url_patterns": [ "example.com", "other.example.com" ] } ], "service_provider": "microsoft" } ]
OnPrintEnterpriseConnector Configuration policy for print for Microsoft Edge for Business Data Loss Prevention Connectors
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- OnPrintEnterpriseConnector
- Supported on
- Microsoft Edge version 137, Windows 7 or later
- Template
- msedge.admx
Specifies the list of Microsoft Edge for Business Data Loss Prevention Connectors service settings that apply when users print a page or file from Microsoft Edge. Connector Fields 1. url_list, tags, enable, disable These fields determine whether the connector sends data for analysis when content is entered on a specific page, and which tags to include in the analysis request. A tag associated with an enable pattern is included in the request if the page URL matches the pattern—unless a corresponding disable pattern also matches. Analysis is triggered if at least one tag is included in the request. 2. service_provider Identifies the analysis service provider the configuration applies to. 3. block_until_verdict If set to 1, Microsoft Edge waits for a response from the analysis service before giving the page access to the data. Any other integer value allows the page to access the data immediately. 4. default_action If set to block, Microsoft Edge denies page access to the data if an error occurs while contacting the analysis service. Any other value permits the page to access the data. This policy requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2320413. Example value: [ { "block_until_verdict": 0, "default_action": "allow", "disable": [ { "tags": [ "dlp" ], "url_list": [ "*.us.com" ] } ], "enable": [ { "tags": [ "dlp" ], "url_list": [ "*.them.com", "*.others.com" ] } ], "service_provider": "local_system_agent" } ]
AddressBarEditingEnabled Configure address bar editing
If you enable or don't configure this policy, users can change the URL in the address bar.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AddressBarEditingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 98, Windows 7 or later
- Template
- msedge.admx
If you enable or don't configure this policy, users can change the URL in the address bar. If you disable this policy, it prevents users from changing the URL in the address bar. Note: This policy doesn't prevent the browser from navigating to any URL. Users can still navigate to any URL using the search option in the default New Tab Page, or using any link that leads to a web search engine. To ensure that users can only go to sites you expect, consider configuring the following policies in addition to this policy: - 'NewTabPageLocation' (Configure the new tab page URL) - 'HomepageLocation' (Configure the home page URL) - 'HomepageIsNewTabPage' (Set the new tab page as the home page) - 'URLBlocklist' (Block access to a list of URLs) and 'URLAllowlist' (Define a list of allowed URLs) to scope the pages that browser can navigate to.
AutomaticHttpsDefault Configure Automatic HTTPS (obsolete)
If set to "AlwaysUpgrade" or left unset, this feature is enabled by default.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AutomaticHttpsDefault
- Supported on
- Microsoft Edge version 92-139, Windows 7 or later
- Template
- msedge.admx
0Automatic HTTPS functionality is disabled.1(Deprecated) Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.2All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 139. This policy lets you manage settings for 'AutomaticHttpsDefault' (Configure Automatic HTTPS), which switches connections from HTTP to HTTPS. This feature helps protect against man-in-the-middle attacks by enforcing more secure connections, but users might experience more connection errors. Microsoft Edge attempts to upgrade some navigations from HTTP to HTTPS, when possible. This policy can be used to disable this behavior. If set to "AlwaysUpgrade" or left unset, this feature is enabled by default. The separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature. This policy is obsolete, and is replaced with the policy 'HttpsUpgradesEnabled' (Enable automatic HTTPS upgrades). Policy options mapping: * DisableAutomaticHttps (0) = Automatic HTTPS functionality is disabled. * UpgradeCapableDomains (1) = (Deprecated) Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS. * AlwaysUpgrade (2) = All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often. Use the preceding information when configuring this policy.
ConfigureOnPremisesAccountAutoSignIn Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ConfigureOnPremisesAccountAutoSignIn
- Supported on
- Microsoft Edge version 81, Windows 7 or later
- Template
- msedge.admx
0Disabled1Sign in and make domain account non-removableEnables the use of Azure Active Directory (Azure AD) accounts for automatic sign in if your users' machines are Domain Joined and if your environment isn't hybrid joined. If you want users automatically signed in with their Azure AD accounts instead, Azure AD join (See https://go.microsoft.com/fwlink/?linkid=2118197 for more information) or hybrid join (See https://go.microsoft.com/fwlink/?linkid=2118365 for more information) your environment. On every launch, Microsoft Edge tries to sign in using this policy, as long as the first profile being launched isn't signed in or an auto sign in doesn't happen before. If you configure the 'BrowserSignin' (Browser sign-in settings) policy to disabled, this policy doesn't take any effect. If you enable this policy and set it to 'SignInAndMakeDomainAccountNonRemovable', Microsoft Edge automatically signs in users that are on domain-joined machines using their Azure AD accounts. If you set this policy to 'Disabled' or don't set it, Microsoft Edge doesn't automatically sign in users that are on domain-joined machines with Azure AD accounts. From Microsoft Edge version 89, if there's an existing on-premises profile with 'RoamingProfileSupportEnabled' (Enable using roaming copies for Microsoft Edge profile data) policy disabled, and if the machine is now hybrid joined, that is, it has an Azure AD account, it autoupgrades the on-premises profile to Azure AD profile to get full Azure AD sync facilities. From Microsoft Edge version 93, if policy 'ImplicitSignInEnabled' (Enable implicit sign-in) is disabled, this policy doesn't take any effect. From Microsoft Edge version 94, if policy 'OnlyOnPremisesImplicitSigninEnabled' (Only on-premises account enabled for implicit sign-in) is enabled, and this policy is set to 'SignInAndMakeDomainAccountNonRemovable', it takes effect even on hybrid-joined environment. Microsoft Edge automatically signs in users using their Azure AD domain account even if there are Microsoft Account (MSA) or Azure AD accounts. Policy options mapping: * Disabled (0) = Disabled * SignInAndMakeDomainAccountNonRemovable (1) = Sign in and make domain account non-removable Use the preceding information when configuring this policy.
BrowserCodeIntegritySetting Configure browser process code integrity guard setting
If you disable or don't configure this policy, it prevents the browser from enabling code integrity guard in the browser process.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- BrowserCodeIntegritySetting
- Supported on
- Microsoft Edge version 104, Windows 7 or later
- Template
- msedge.admx
0Do not enable code integrity guard in the browser process.1Enable code integrity guard audit mode in the browser process.2Enable code integrity guard enforcement in the browser process.This policy controls the use of code integrity guard in the browser process, which only allows Microsoft signed binaries to load. If you enable this policy, it enables code integrity guard in the browser process. If you disable or don't configure this policy, it prevents the browser from enabling code integrity guard in the browser process. The policy value Audit (1) is obsolete as of Microsoft Edge version 110. Setting this value is equivalent to the Disabled value. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, or Windows 10 Pro or Enterprise instances that enrolled for device management. This policy only takes effect on Windows 10 RS2 and above. Policy options mapping: * Disabled (0) = Do not enable code integrity guard in the browser process. * Audit (1) = Enable code integrity guard audit mode in the browser process. * Enabled (2) = Enable code integrity guard enforcement in the browser process. Use the preceding information when configuring this policy.
ConfigureDoNotTrack Configure Do Not Track
If you don't configure this policy, users can choose whether to send these requests.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ConfigureDoNotTrack
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, Microsoft Edge doesn't send Do Not Track requests, but users can turn on this feature to send them.
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specify whether to send Do Not Track requests to websites that ask for tracking info. Do Not Track requests let the websites you visit know that you don't want your browsing activity to be tracked. By default, Microsoft Edge doesn't send Do Not Track requests, but users can turn on this feature to send them. If you enable this policy, Do Not Track requests are always sent to websites asking for tracking info. If you disable this policy, requests are never sent. If you don't configure this policy, users can choose whether to send these requests.
InternetExplorerIntegrationEnhancedHangDetection Configure enhanced hang detection for Internet Explorer mode
If you set this policy to 'Enabled' or don't configure it, websites running in Internet Explorer mode use enhanced hang detection.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerIntegrationEnhancedHangDetection
- Supported on
- Microsoft Edge version 84, Windows 7 or later
- Template
- msedge.admx
0Enhanced hang detection disabled1Enhanced hang detection enabledEnhanced hang detection is a more granular approach to detecting hung webpages in Internet Explorer mode than what standalone Internet Explorer uses. When a hung webpage is detected, the browser applies a mitigation to prevent the rest of the browser from hanging. This setting allows you to configure the use of enhanced hang detection in case you run into incompatible issues with any of your websites. We recommend disabling this policy only if you see notifications such as "(website) is not responding" in Internet Explorer mode but not in standalone Internet Explorer. This setting works in conjunction with: 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode' and 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy where the list has at least one entry. If you set this policy to 'Enabled' or don't configure it, websites running in Internet Explorer mode use enhanced hang detection. If you set this policy to 'Disabled', enhanced hang detection is disabled, and users get the basic Internet Explorer hang detection behavior. To learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210 Policy options mapping: * Disabled (0) = Enhanced hang detection disabled * Enabled (1) = Enhanced hang detection enabled Use the preceding information when configuring this policy.
ManagedFavorites Configure favorites
By default the folder name is "Managed favorites" but you can change it by adding to the list of favorites a dictionary containing the key "toplevel_name" with the desired folder name as the value.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ManagedFavorites
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Configures a list of managed favorites. The policy creates a list of favorites. Each favorite contains the keys "name" and "url," which hold the favorite's name and its target. You can configure a subfolder by defining a favorite without an "url" key but with an extra "children" key that contains a list of favorites as defined earlier (some of which may be folders again). Microsoft Edge amends incomplete URLs as if they were submitted via the Address Bar, for example "microsoft.com" becomes "https://microsoft.com/". These favorites are placed in a folder that can't be modified by the user (but the user can choose to hide it from the favorites bar). By default the folder name is "Managed favorites" but you can change it by adding to the list of favorites a dictionary containing the key "toplevel_name" with the desired folder name as the value. Managed favorites aren't synced to the user account and can't be modified by extensions. Example value: [ { "toplevel_name": "My managed favorites folder" }, { "name": "Microsoft", "url": "microsoft.com" }, { "name": "Bing", "url": "bing.com" }, { "children": [ { "name": "Microsoft Edge Insiders", "url": "www.microsoftedgeinsider.com" }, { "name": "Microsoft Edge", "url": "www.microsoft.com/windows/microsoft-edge" } ], "name": "Microsoft Edge links" } ]
InternetExplorerIntegrationSiteListRefreshInterval Configure how frequently the Enterprise Mode Site List is refreshed
If you disable or don't configure this policy, Microsoft Edge uses a default refresh interval, it's 10080 minutes (7 days) starting from version 110 or later, 120 minutes from version 93 to 110, and 30 minutes before version 93.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerIntegrationSiteListRefreshInterval
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
This setting lets you specify a custom refresh interval for the Enterprise Mode Site List. The refresh interval is specified in minutes. The minimum refresh interval is 30 minutes. This setting is applicable only when the 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) or 'InternetExplorerIntegrationCloudSiteList' (Configure the Enterprise Mode Cloud Site List) setting is configured. If you configure this policy, Microsoft Edge attempts to retrieve an updated version of the configured Enterprise Mode Site List using the specified refresh interval. If you disable or don't configure this policy, Microsoft Edge uses a default refresh interval, it's 10080 minutes (7 days) starting from version 110 or later, 120 minutes from version 93 to 110, and 30 minutes before version 93.
AdsTransparencyEnabled Configure if the ads transparency feature is enabled
AdsTransparencyEnabled will only have an effect if 'TrackingPrevention' is set to TrackingPreventionBalanced or isn't configured. If you enable or don't configure this policy, transparency metadata provided by ads are available to the user when the feature is active.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AdsTransparencyEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 100, Windows 7 or later
- Template
- msedge.admx
Lets you decide whether the ads transparency feature is enabled. This behavior only applies to the "balanced" mode of tracking prevention, and doesn't impact "basic" or "strict" modes. Your users' tracking prevention level can be configured using the 'TrackingPrevention' (Block tracking of users' web-browsing activity) policy. AdsTransparencyEnabled will only have an effect if 'TrackingPrevention' is set to TrackingPreventionBalanced or isn't configured. If you enable or don't configure this policy, transparency metadata provided by ads are available to the user when the feature is active. When the feature is enabled, Tracking Prevention enables exceptions for the associated ad providers that have met Microsoft's privacy standards. If you disable this policy, Tracking Prevention won't adjust its behavior even when transparency metadata is provided by ads.
InPrivateModeAvailability Configure InPrivate mode availability
If you don't configure this policy or set it to 'Enabled', users can open pages in InPrivate mode.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InPrivateModeAvailability
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
0InPrivate mode available1InPrivate mode disabled2InPrivate mode forcedSpecifies whether the user can open pages in InPrivate mode in Microsoft Edge. If you don't configure this policy or set it to 'Enabled', users can open pages in InPrivate mode. Set this policy to 'Disabled' to stop users from using InPrivate mode. Set this policy to 'Forced' to always use InPrivate mode. The 'InPrivateModeUrlAllowlist' (Allow access to a list of URLs in InPrivate mode.) policy takes precedence over this policy and can allow specific URLs to open in InPrivate mode. If this policy disables InPrivate mode and an allowlist is configured, InPrivate mode is permitted only for URLs that match entries in the allowlist. All other URLs are blocked from opening in InPrivate mode. Policy options mapping: * Enabled (0) = InPrivate mode available * Disabled (1) = InPrivate mode disabled * Forced (2) = InPrivate mode forced Use the preceding information when configuring this policy.
InternetExplorerIntegrationLevel Configure Internet Explorer integration
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerIntegrationLevel
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
0None1Internet Explorer mode2Internet Explorer 11For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210 Policy options mapping: * None (0) = None * IEMode (1) = Internet Explorer mode * NeedIE (2) = Internet Explorer 11 Use the preceding information when configuring this policy.
WebAppInstallForceList Configure list of force-installed Web Apps
If disabled or unset, the web app at the given url is installed normally.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebAppInstallForceList
- Supported on
- Microsoft Edge version 80, Windows 7 or later
- Template
- msedge.admx
Setting the policy specifies a list of web apps that install silently, without user interaction. Users can't turn off the policy or uninstall these web apps. Each list item of the policy is an object with a mandatory member: url (the URL of the web app to install) and 6 optional members: - default_launch_container (for how the web app opens—a new tab is the default) - create_desktop_shortcut (True if you want to create Linux and Microsoft Windows desktop shortcuts). - fallback_app_name (Starting with Microsoft Edge version 90, you can permanently override the app name if it's not a Progressive Web App (PWA) or you can temporarily override the app name if authentication is required before installation can be completed. If both custom_name and fallback_app_name are provided, the latter is ignored.) - custom_name (Starting with Microsoft Edge version 112 on all desktop platforms, you can permanently override the app name for all web apps and PWAs.) - custom_icon (Starting with Microsoft Edge version 112 on all desktop platforms, you can override the app icon of installed apps. The icons have to be square, maximal 1 MB in size, and in one of the following formats: jpeg, png, gif, webp, ico. The hash value has to be the SHA256 hash of the icon file. The url should be accessible without authentication to ensure that the icon can be used upon app installation.) - install_as_shortcut (Starting with Microsoft Edge version 107). If enabled, the given url is installed as a shortcut, as if done via the "Create Shortcut..." option in the desktop browser GUI. When installed as a shortcut, it won't be updated if the manifest in url changes. If disabled or unset, the web app at the given url is installed normally. (This isn't currently supported in Microsoft Edge.) The 'WebAppInstallByUserEnabled' policy doesn't affect this policy. Web apps specified by this policy are installed regardless of the 'WebAppInstallByUserEnabled' policy setting. Example value: [ { "create_desktop_shortcut": true, "default_launch_container": "window", "url": "https://www.contoso.com/maps" }, { "default_launch_container": "tab", "url": "https://app.contoso.edu" }, { "default_launch_container": "window", "fallback_app_name": "Editor", "url": "https://app.contoso.edu/editor" }, { "custom_name": "Spreadsheets", "default_launch_container": "window", "install_as_shortcut": true, "url": "https://app.contoso.edu/sheets" }, { "custom_icon": { "hash": "c28f469c450e9ab2b86ea47038d2b324c6ad3b1e9a4bd8960da13214afd0ca38", "url": "https://mydomain.example.com/sunny_icon.png" }, "url": "https://weather.example.com" } ]
ConfigureOnlineTextToSpeech Configure Online Text To Speech
If you enable or don't configure this policy, web-based applications that use the SpeechSynthesis API can use Online Text to Speech voice fonts.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ConfigureOnlineTextToSpeech
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Set whether the browser can apply Online Text to Speech voice fonts, part of Azure Cognitive Services. These voice fonts are higher quality than the pre-installed system voice fonts. If you enable or don't configure this policy, web-based applications that use the SpeechSynthesis API can use Online Text to Speech voice fonts. If you disable this policy, the voice fonts aren't available. Read more about this feature here: SpeechSynthesis API: https://go.microsoft.com/fwlink/?linkid=2110038 Cognitive Services: https://go.microsoft.com/fwlink/?linkid=2110141
RelatedMatchesCloudServiceEnabled Configure Related Matches in Find on Page (obsolete)
If you enable or don't configure this policy, users can receive related matches in Find on Page on all sites.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RelatedMatchesCloudServiceEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 99-134, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 134. Specifies how the user receives related matches in Find on Page, which provides spellcheck, synonyms, and Q&A results in Microsoft Edge. If you enable or don't configure this policy, users can receive related matches in Find on Page on all sites. The results are processed through a cloud service. If you disable this policy, users can receive related matches in Find on Page on a limited set of sites. In this case, results are processed locally on the user's device. Note: This policy is obsolete. The associated cloud service is discontinued, so the feature and policy aren't supported on any versions of Microsoft Edge.
InternetExplorerIntegrationCloudUserSitesReporting Configure reporting of IE Mode user list entries to the M365 Admin Center Site Lists app
If you disable or don't configure this policy, Microsoft Edge never sends reports about URLs added to a user's local site list to the Site Lists app.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerIntegrationCloudUserSitesReporting
- Supported on
- Microsoft Edge version 99, Windows 7 or later
- Template
- msedge.admx
This setting lets you enable reporting of sites that Microsoft Edge users add to their local IE Mode site list. The user must be signed in to Microsoft Edge with a valid work or school account for reports to be sent, and the user's account tenant must match the tenant that the policy specifies. If you configure this policy, Microsoft Edge sends a report to the Microsoft 365 Admin Center Site Lists app when a user adds a site to their local IE mode site list. The report shows the URL of the site the user added, minus any query string or fragment. The user's identity isn't reported. For this reporting to work correctly, you must successfully visit the Microsoft Edge Site Lists app in the Microsoft 365 Admin Center at least once. This visit activates a per-tenant storage account used to store these reports. Microsoft Edge still attempts to send reports if this step isn't completed. However, the reports aren't stored in the Site Lists app. If you enable this policy, you must specify your O365 tenant ID. To learn more about finding your O365 tenant ID, see https://go.microsoft.com/fwlink/?linkid=2185668. If you disable or don't configure this policy, Microsoft Edge never sends reports about URLs added to a user's local site list to the Site Lists app. To learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2165707. Example value: aba95e58-070f-4784-8dcd-e5fd46c2c6d6
InternetExplorerIntegrationCloudNeutralSitesReporting Configure reporting of potentially misconfigured neutral site URLs to the M365 Admin Center Site Lists app
If you disable or don't configure this policy, Microsoft Edge never sends reports about misconfigured neutral sites to the Site Lists app.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerIntegrationCloudNeutralSitesReporting
- Supported on
- Microsoft Edge version 99, Windows 7 or later
- Template
- msedge.admx
This setting lets you enable reporting of sites that need to be configured as a neutral site on the Enterprise Mode Site List. The user must be signed in to Microsoft Edge with a valid work or school account for reports to be sent, and the user's account tenant must match the tenant specified by the policy. If you configure this policy, Microsoft Edge sends a report to the Microsoft 365 Admin Center Site Lists app when a navigation appears stuck redirecting back and forth between the Microsoft Edge and Internet Explorer (IE) engines several times. This indicates that redirection to an authentication server is switching engines, which repeatedly fails in a loop. The report shows the URL of the site that's the redirect target, minus any query string or fragment. The user's identity isn't reported. For this reporting to work correctly, you must have successfully visited the Microsoft Edge Site Lists app in the Microsoft 365 Admin Center at least once. This activates a per-tenant storage account used to store these reports. Microsoft Edge still attempts to send reports if this step hasn't been completed. However, the reports aren't stored in the Site Lists app. If you enable this policy, you must specify your Office 365 tenant ID. To learn more about finding your Office 365 tenant ID, see https://go.microsoft.com/fwlink/?linkid=2185668. If you disable or don't configure this policy, Microsoft Edge never sends reports about misconfigured neutral sites to the Site Lists app. To learn more about IE mode, see https://go.microsoft.com/fwlink/?linkid=2165707. Example value: aba95e58-070f-4784-8dcd-e5fd46c2c6d6
ShadowStackCrashRollbackBehavior Configure ShadowStack crash rollback behavior (obsolete)
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ShadowStackCrashRollbackBehavior
- Supported on
- Microsoft Edge version 95-109, Windows 7 or later
- Template
- msedge.admx
0Disable Hardware-enforced Stack Protection1Disable Hardware-enforced Stack Protection until the next Microsoft Edge update2Enable Hardware-enforced Stack ProtectionOBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 109. This policy is deprecated as it served only as a short-term mechanism to give enterprises more time to update their environments and report issues if they're found to be incompatible with Hardware-enforced Stack Protection. It doesn't work in Microsoft Edge starting with version 109. Microsoft Edge includes a Hardware-enforced Stack Protection security feature. This feature can result in the browser crashing unexpectedly in cases that don't represent an attempt to compromise the browser's security. Using this policy, you can control the behavior of the Hardware-enforced Stack Protection feature after a crash triggered by this feature is encountered. Set this policy to 'Disable' to disable the feature. Set this policy to 'DisableUntilUpdate' to disable the feature until Microsoft Edge updates next time. Set this policy to 'Enable' to keep the feature enabled. Policy options mapping: * Disable (0) = Disable Hardware-enforced Stack Protection * DisableUntilUpdate (1) = Disable Hardware-enforced Stack Protection until the next Microsoft Edge update * Enable (2) = Enable Hardware-enforced Stack Protection Use the preceding information when configuring this policy.
SpeechRecognitionEnabled Configure Speech Recognition
If you enable or don't configure this policy, web-based applications that use the Web Speech API can use Speech Recognition.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SpeechRecognitionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 87, Windows 7 or later
- Template
- msedge.admx
Set whether websites can use the W3C Web Speech API to recognize speech from the user. The Microsoft Edge implementation of the Web Speech API uses Azure Cognitive Services, so voice data leaves the machine. If you enable or don't configure this policy, web-based applications that use the Web Speech API can use Speech Recognition. If you disable this policy, Speech Recognition isn't available through the Web Speech API. Read more about this feature here: SpeechRecognition API: https://go.microsoft.com/fwlink/?linkid=2143388 Cognitive Services: https://go.microsoft.com/fwlink/?linkid=2143680
ConfigureFriendlyURLFormat Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users
* Not configured = The users are able to choose their preferred paste format.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ConfigureFriendlyURLFormat
- Stated default
- By default, this is set to the friendly URL format.
- Supported on
- Microsoft Edge version 87, Windows 7 or later
- Template
- msedge.admx
1The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.3Titled Hyperlink: A hyperlink that points to the copied URL but whose visible text is the title of the destination page. This is the Friendly URL format.4Coming soon. If set, behaves the same as 'Plain URL'.If FriendlyURLs are enabled, Microsoft Edge computes more representations of the URL and places them on the clipboard. This policy configures what format is pasted when the user pastes in external applications or inside Microsoft Edge without the 'Paste as' context menu item. If you configure this policy, it makes a choice on behalf of the user. The options in edge://settings/shareCopyPaste will be grayed out, and the options in the 'Paste As' context menu won't be available. * Not configured = The users are able to choose their preferred paste format. By default, this is set to the friendly URL format. The 'Paste As' menu will be available in Microsoft Edge. * 1 = No additional formats are stored on the clipboard. There will be no 'Paste as' context menu item in Microsoft Edge, and the only format available to paste will be the plain text URL format. Effectively, the friendly URL feature is disabled. * 3 = The user gets a friendly URL whenever they paste into surfaces that accept rich text. The plain URL is still available for nonrich surfaces. There will be no 'Paste As' menu in Microsoft Edge. * 4 = (Not currently used) The richer formats may not be supported in some paste destinations and/or websites. In these scenarios, the plain URL option is recommended when configuring this policy. The recommended policy is available in Microsoft Edge 105 or later. Policy options mapping: * PlainText (1) = The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description. * TitledHyperlink (3) = Titled Hyperlink: A hyperlink that points to the copied URL but whose visible text is the title of the destination page. This is the Friendly URL format. * WebPreview (4) = Coming soon. If set, behaves the same as 'Plain URL'. Use the preceding information when configuring this policy.
InternetExplorerIntegrationCloudSiteList Configure the Enterprise Mode Cloud Site List
If you disable or don't configure this policy, Microsoft Edge will use the 'InternetExplorerIntegrationSiteList' policy instead.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerIntegrationCloudSiteList
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
The Microsoft Edge Site Lists setting in the Microsoft 365 Admin Center allows you to host your site list(s) in a compliant cloud location and manage the contents of your site list(s) through the built-in experience. This setting allows you to specify which site list within the Microsoft 365 Admin Center is to be deploy to your users. The user must be signed in to Microsoft Edge with a valid work or school account. Otherwise, Microsoft Edge doesn't download the site list from the cloud location. This setting is applicable only when the 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) setting is configured. If you configure this policy, Microsoft Edge uses the specified site list. When enabled, you can enter the identifier of the site list that you created and published to the cloud in M365 Admin Center. This setting takes precedence over the 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy of Microsoft Edge as well as Internet Explorer's site list setting (Use the Enterprise mode IE website list). If you disable or don't configure this policy, Microsoft Edge will use the 'InternetExplorerIntegrationSiteList' policy instead. To learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2165707 Example value: aba95e58-070f-4784-8dcd-e5fd46c2c6d6
InternetExplorerIntegrationSiteList Configure the Enterprise Mode Site List
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerIntegrationSiteList
- Supported on
- Microsoft Edge version 78, Windows 7 or later
- Template
- msedge.admx
For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210 Example value: https://internal.contoso.com/sitelist.xml
ConfigureKeyboardShortcuts Configure the list of commands for which to disable keyboard shortcuts
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ConfigureKeyboardShortcuts
- Supported on
- Microsoft Edge version 101, Windows 7 or later
- Template
- msedge.admx
Configure the list of Microsoft Edge commands for which keyboard shortcuts must be disabled. See https://go.microsoft.com/fwlink/?linkid=2186950 for a list of possible commands to disable. If you enable this policy, commands in the 'disabled' list are no longer activated by keyboard shortcuts. If you disable this policy, all keyboard shortcuts behave as usual. Note: Disabling a command only removes its shortcut mapping. Commands in the 'disabled' list still function if accessed via browser UI. Example value: { "disabled": [ "new_tab", "fullscreen" ] } Compact example value: {"disabled": ["new_tab", "fullscreen"]}
EnhanceSecurityModeEnforceListDomains Configure the list of domains for which enhance security mode will always be enforced
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\EnhanceSecurityModeEnforceListDomains
- Supported on
- Microsoft Edge version 98, Windows 7 or later
- Template
- msedge.admx
Configure the list of enhance security untrusted domains. This means that enhance security mode is always enforced when loading the sites in untrusted domains. Example value: mydomain.com myuniversity.edu
EnhanceSecurityModeBypassListDomains Configure the list of domains for which enhance security mode will not be enforced
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\EnhanceSecurityModeBypassListDomains
- Supported on
- Microsoft Edge version 98, Windows 7 or later
- Template
- msedge.admx
Configures the list of enhance security trusted domains. This means that enhance security mode isn't enforced when loading the sites in trusted domains. Example value: mydomain.com myuniversity.edu
HSTSPolicyBypassList Configure the list of names that will bypass the HSTS policy check
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\HSTSPolicyBypassList
- Supported on
- Microsoft Edge version 79, Windows 7 or later
- Template
- msedge.admx
Setting the policy specifies a list of hostnames that bypass preloaded HSTS (HTTP Strict Transport Security) upgrades from http to https. Only single-label hostnames are allowed in this policy, and this policy only applies to static HSTS-preloaded entries (for example, "app", "new", "search", and "play"). This policy doesn't prevent HSTS upgrades for servers that have dynamically requested HSTS upgrades using a Strict-Transport-Security response header. Supplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase. This policy only applies to the specific single-label hostnames specified and not to subdomains of those names. Example value: meet
AllowTokenBindingForUrls Configure the list of sites for which Microsoft Edge will attempt to establish a Token Binding with (obsolete)
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\AllowTokenBindingForUrls
- Supported on
- Microsoft Edge version 83-129, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 129. This policy is obsolete because Token Binding is no longer supported, starting with Microsoft Edge 130. Configure the list of URL patterns for sites that the browser attempts to perform the Token Binding protocol with. For the domains on this list, the browser sends the Token Binding ClientHello in the TLS handshake (See https://tools.ietf.org/html/rfc8472). If the server responds with a valid ServerHello response, the browser creates and sends Token Binding messages on subsequent https requests. See https://tools.ietf.org/html/rfc8471 for more info. If this list is empty, Token Binding is disabled. This policy is only available on Windows 10 devices with Virtual Secure Mode capability. Starting in Microsoft Edge 86, this policy no longer supports dynamic refresh. Example value: mydomain.com [*.]mydomain2.com [*.].mydomain2.com
SyncTypesListDisabled Configure the list of types that are excluded from synchronization
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\SyncTypesListDisabled
- Supported on
- Microsoft Edge version 83, Windows 7 or later
- Template
- msedge.admx
If you enable this policy, all the specified data types are excluded from synchronization. This policy can be used to limit the type of data uploaded to the Microsoft Edge synchronization service. You can provide one of the following data types for this policy: "favorites", "settings", "passwords", "addressesAndMore", "extensions", "history", "openTabs", "edgeWallet", "collections", "apps", and "edgeFeatureUsage". The "edgeFeatureUsage" data type are supported starting in Microsoft Edge version 134. These data type names are case sensitive. Users can't override the disabled data types. Example value: favorites
ForceSyncTypes Configure the list of types that are included for synchronization
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ForceSyncTypes
- Supported on
- Microsoft Edge version 96, Windows 7 or later
- Template
- msedge.admx
If you enable this policy, all the specified data types are included for synchronization for Azure AD/Azure AD-Degraded user profiles. This policy can be used to ensure the type of data uploaded to the Microsoft Edge synchronization service. You can provide one of the following data types for this policy: "favorites", "settings", "passwords", "addressesAndMore", "extensions", "history", "openTabs", "edgeWallet", "collections", "apps", and "edgeFeatureUsage". The "edgeFeatureUsage" data type is supported starting in Microsoft Edge version 134. Note that these data type names are case sensitive. Users can't override the enabled data types. Example value: favorites
InternetExplorerIntegrationWindowOpenHeightAdjustment Configure the pixel adjustment between window.open heights sourced from IE mode pages vs. Edge mode pages
If you disable or don't configure this policy, Microsoft Edge will treat IE mode window.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerIntegrationWindowOpenHeightAdjustment
- Supported on
- Microsoft Edge version 95, Windows 7 or later
- Template
- msedge.admx
This setting lets you specify a custom adjustment to the height of popup windows generated via window.open from the Internet Explorer mode site. If you configure this policy, Microsoft Edge will add the adjustment value to the height, in pixels. The exact difference depends on the UI configuration of both IE and Edge, but a typical difference is 5. If you disable or don't configure this policy, Microsoft Edge will treat IE mode window.open the same as Edge mode window.open in window height calculations.
InternetExplorerIntegrationWindowOpenWidthAdjustment Configure the pixel adjustment between window.open widths sourced from IE mode pages vs. Edge mode pages
If you disable or don't configure this policy, Microsoft Edge will treat IE mode window.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerIntegrationWindowOpenWidthAdjustment
- Supported on
- Microsoft Edge version 95, Windows 7 or later
- Template
- msedge.admx
This setting lets you specify a custom adjustment to the width of popup windows generated via window.open from the Internet Explorer mode site. If you configure this policy, Microsoft Edge will add the adjustment value to the width, in pixels. The exact difference depends on the UI configuration of both IE and Edge, but a typical difference is 4. If you disable or don't configure this policy, Microsoft Edge will treat IE mode window.open the same as Edge mode window.open in window width calculations.
ConfigureShare Configure the Share experience
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ConfigureShare
- Supported on
- Microsoft Edge version 83, Windows 7 or later
- Template
- msedge.admx
0Allow using the Share experience1Don't allow using the Share experienceIf you set this policy to 'ShareAllowed' (the default), users can access the Share experience from the Settings and More Menu in Microsoft Edge to share with other apps on the system. If you set this policy to 'ShareDisallowed', users can't access the Share experience. If the Share button is on the toolbar, it's hidden as well. Policy options mapping: * ShareAllowed (0) = Allow using the Share experience * ShareDisallowed (1) = Don't allow using the Share experience Use the preceding information when configuring this policy.
ConfigureViewInFileExplorer Configure the View in File Explorer feature for SharePoint pages in Microsoft Edge
If you disable or don't configure this policy, you can't use the "View in File Explorer" feature on SharePoint document libraries.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ConfigureViewInFileExplorer
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
This setting allows you to configure the View in File Explorer capability for file management in SharePoint Online while using Microsoft Edge. You'll need to list the specific domains where this is allowed and list cookies needed for SharePoint authentication (rtFa and FedAuth). Behind the scenes, the policy allows URLs with the viewinfileexplorer: scheme to open WebDAV URLs in Windows File Explorer on pages matching the list of domains and uses the cookies you specified for WebDAV authentication. If you enable this policy, you can use the "View in File Explorer" feature on the SharePoint document libraries you list. You'll need to specify the SharePoint domain and authentication cookies. See example value below. If you disable or don't configure this policy, you can't use the "View in File Explorer" feature on SharePoint document libraries. Note that while this is an available option through Microsoft Edge, rather than use the View in File Explorer option, the recommended approach to managing files and folders outside of SharePoint is to sync your SharePoint files or move or copy files in SharePoint. Sync your SharePoint files: https://go.microsoft.com/fwlink/p/?linkid=2166983 Move or copy files in SharePoint: https://go.microsoft.com/fwlink/p/?linkid=2167123 This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, or Windows 10 Pro or Enterprise instances enrolled for device management. Example value: [ { "cookies": [ "rtFa", "FedAuth" ], "domain": "contoso.sharepoint.com" }, { "cookies": [ "rtFa", "FedAuth" ], "domain": "contoso2.sharepoint.com" } ]
AllowTrackingForUrls Configure tracking prevention exceptions for specific sites
If you don't configure this policy, the global default value from the "Block tracking of users' web-browsing activity" policy (if set) or the user's personal configuration is used for all sites.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\AllowTrackingForUrls
- Supported on
- Microsoft Edge version 78, Windows 7 or later
- Template
- msedge.admx
Configure the list of URL patterns that are excluded from tracking prevention. If you configure this policy, the list of configured URL patterns is excluded from tracking prevention. If you don't configure this policy, the global default value from the "Block tracking of users' web-browsing activity" policy (if set) or the user's personal configuration is used for all sites. Example value: https://www.contoso.com [*.]contoso.edu
WebContentFilteringBlockedCategories Configure Web Content Filtering
If the policy is not configured or is disabled, no categories will be blocked.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\WebContentFilteringBlockedCategories
- Supported on
- Microsoft Edge version 135, Windows 7 or later
- Template
- msedge.admx
Configure this policy to block access to specific categories of websites in Microsoft Edge on Windows devices. Web Content Filtering is available exclusively in Microsoft Edge on Windows and requires the appropriate Microsoft 365 licensing. When this policy is enabled, users are blocked from accessing URLs that fall within the defined list of content categories. You can configure this by adding Category Strings to the list of blocked categories. If the policy is not configured or is disabled, no categories will be blocked. To view the list of supported content categories, including each Category String and its definition, refer to: https://learn.microsoft.com/en-us/defender-endpoint/web-content-filtering?view=o365-worldwide#category-definitions To block a specific URL outside of a category, use the “Block access to a list of URLs” policy. To allow a specific URL that falls under a blocked category, use the “Define a list of allowed URLs” policy. Note: This policy is supported only when deployed through the Edge management service, not via Microsoft Intune. To use this policy, your organization must have one of the following licenses: - Microsoft 365 A1, A3, or A5 - Microsoft 365 Business Premium - Microsoft 365 Business Basic or Standard with Intune Plan 1 or Plan 2 Policy options mapping: * chat (chat) = Chat * child_abuse_images (child_abuse_images) = Child Abuse Images * criminal_activity (criminal_activity) = Criminal Activity * download_sites (download_sites) = Download Sites * gambling (gambling) = Gambling * games (games) = Games * hacking (hacking) = Hacking * hate_and_intolerance (hate_and_intolerance) = Hate and Intolerance * illegal_drug (illegal_drug) = Illegal Drug * illegal_software (illegal_software) = Illegal Software * image_sharing (image_sharing) = Image Sharing * instant_messaging (instant_messaging) = Instant Messaging * nudity (nudity) = Nudity * peer_to_peer (peer_to_peer) = Peer to Peer * pornography_or_sexually_explicit (pornography_or_sexually_explicit) = Pornography or Sexually Explicit * professional_networking (professional_networking) = Professional Networking * self_harm (self_harm) = Self Harm * sex_education (sex_education) = Sex Education * social_networking (social_networking) = Social Networking * streaming_and_downloads (streaming_and_downloads) = Streaming Media and Downloads * tasteless (tasteless) = Tasteless * violence (violence) = Violence * weapons (weapons) = Weapons * web_based_email (web_based_email) = Web Based Email * gen_ai (gen_ai) = Gen AI * shopping (shopping) = Shopping * 3p_search_engines (3p_search_engines) = 3P Search Engines * none (none) = None Use the preceding information when configuring this policy. Example value: gambling streaming_and_downloads games
NonRemovableProfileEnabled Configure whether a user always has a default profile automatically signed in with their work or school account
If you disable or don't configure this policy, the profile automatically signs in with a user's work or school account on Windows can be signed out or removed by the user.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NonRemovableProfileEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 78, Windows 7 or later
- Template
- msedge.admx
This policy determines if a user can remove the Microsoft Edge profile automatically signed in with a user's work or school account. If you enable this policy, a nonremovable profile is created with the user's work or school account on Windows. This profile can't be signed out or removed. The profile is nonremovable only if profile is signed-in with either on-premises account or Azure AD account that matches OS sign-in account. If you disable or don't configure this policy, the profile automatically signs in with a user's work or school account on Windows can be signed out or removed by the user. If you want to configure browser sign in, use the 'BrowserSignin' (Browser sign-in settings) policy. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro, or Enterprise instances that enrolled for device management. From Microsoft Edge version 89 onward, if there is an existing on-premises profile with sync disabled and machine is hybrid joined, it will auto-upgrade the on-premises profile to Azure AD profile and make it non-removable instead of creating a new non-removable Azure AD profile. From Microsoft Edge version 93 onward, if policy 'ImplicitSignInEnabled' (Enable implicit sign-in) is disabled, this policy doesn't take any effect.
InternetExplorerIntegrationComplexNavDataTypes Configure whether form data and HTTP headers will be sent when entering or exiting Internet Explorer mode
If you disable or don't configure this policy, Microsoft Edge uses the new behavior of including form data in navigations that change modes.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerIntegrationComplexNavDataTypes
- Supported on
- Microsoft Edge version 96, Windows 7 or later
- Template
- msedge.admx
0Do not send form data or headers1Send form data only2Send additional headers only3Send form data and additional headersFrom Microsoft Edge version 96, navigations that switch between Internet Explorer mode and Microsoft Edge include form data. If you enable this policy, you specify which data types are included in navigations between Microsoft Edge and Internet Explorer mode. If you disable or don't configure this policy, Microsoft Edge uses the new behavior of including form data in navigations that change modes. To learn more, see https://go.microsoft.com/fwlink/?linkid=2174004. Policy options mapping: * IncludeNone (0) = Do not send form data or headers * IncludeFormDataOnly (1) = Send form data only * IncludeHeadersOnly (2) = Send additional headers only * IncludeFormDataAndHeaders (3) = Send form data and additional headers Use the preceding information when configuring this policy.
ForceCertificatePromptsOnMultipleMatches Configure whether Microsoft Edge should automatically select a certificate when there are multiple certificate matches for a site configured with "AutoSelectCertificateForUrls" (deprecated)
If you don't configure 'AutoSelectCertificateForUrls' for a site, the user is always prompted to select a certificate. If you disable or don't configure this policy, Microsoft Edge automatically selects a certificate even if there are multiple matches for a certificate.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ForceCertificatePromptsOnMultipleMatches
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 81, Windows 7 or later
- Template
- msedge.admx
DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. This policy is deprecated because we are moving to a new policy. It won't work in Microsoft Edge version 104. The new policy to use is 'PromptOnMultipleMatchingCertificates' (Prompt the user to select a certificate when multiple certificates match). Toggles whether users are prompted to select a certificate if there are multiple certificates available and a site is configured with 'AutoSelectCertificateForUrls' (Automatically select client certificates for these sites). If you don't configure 'AutoSelectCertificateForUrls' for a site, the user is always prompted to select a certificate. If you enable this policy, Microsoft Edge prompts a user to select a certificate for sites on the list defined in 'AutoSelectCertificateForUrls' if and only if there's more than one certificate. If you disable or don't configure this policy, Microsoft Edge automatically selects a certificate even if there are multiple matches for a certificate. The user won't be prompted to select a certificate for sites on the list defined in 'AutoSelectCertificateForUrls'.
VerticalTabsAllowed Configures availability of a vertical layout for tabs on the side of the browser
If you enable or don't configure this policy, the tab layout remains at the top, but a user has the option to turn on vertical tabs on the side.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- VerticalTabsAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 88, Windows 7 or later
- Template
- msedge.admx
Configures whether a user can access an alternative layout where tabs are vertically aligned on the side of the browser instead of at the top. When there are several tabs open, this layout provides better tab viewing and management. There's better visibility of the site titles, it's easier to scan aligned icons, and there's more space to manage and close tabs. If you disable this policy, then the vertical tab layout isn't available as an option for users. If you enable or don't configure this policy, the tab layout remains at the top, but a user has the option to turn on vertical tabs on the side.
BackgroundModeEnabled Continue running background apps after Microsoft Edge closes
If you don't configure this policy, background mode is initially turned off, and the user can configure its behavior in edge://settings/system.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- BackgroundModeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows Microsoft Edge processes to start at OS sign-in and keep running after the last browser window is closed. In this scenario, background apps and the current browsing session remain active, including any session cookies. An open background process displays an icon in the system tray and can always be closed from there. If you enable this policy, background mode is turned on. If you disable this policy, background mode is turned off. If you don't configure this policy, background mode is initially turned off, and the user can configure its behavior in edge://settings/system.
EdgeHistoryAISearchEnabled Control access to AI-enhanced search in History
When enabled or not configured, users can search using synonyms, natural language phrases, and minor spelling errors to find previously visited pages.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeHistoryAISearchEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 138, Windows 7 or later
- Template
- msedge.admx
This policy controls whether users can use AI-enhanced search in their browsing history in Microsoft Edge. When enabled or not configured, users can search using synonyms, natural language phrases, and minor spelling errors to find previously visited pages. When disabled, users can only perform exact match (verbatim) searches in their history.
ComposeInlineEnabled Control access to Microsoft 365 Copilot writing assistance in Microsoft Edge for Business
If you don't configure this policy, the default behavior is as follows: - Rewrite is available to users - Users can enable or disable Microsoft 365 Copilot access to Microsoft Edge page content using the toggle in Microsoft Edge settings.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ComposeInlineEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 115, Windows 7 or later
- Template
- msedge.admx
This policy controls whether users can use writing support features in Microsoft Edge for Business, such as Rewrite, which utilizes Microsoft 365 Copilot Chat. With Rewrite, users can receive help with drafting content, rewriting text, and adjusting style directly in their browser tab. In Microsoft Edge, users can trigger it when highlighting editable content in their main browser through the right-click context menu. This policy applies only to Microsoft Entra accounts and doesn't apply to Microsoft accounts. If you enable this policy, users can use Rewrite in Microsoft Edge when logged in with an Entra account. If you disable this policy, users within your tenant can't use Rewrite. If you don't configure this policy, the default behavior is as follows: - Rewrite is available to users - Users can enable or disable Microsoft 365 Copilot access to Microsoft Edge page content using the toggle in Microsoft Edge settings. Note: Rewrite isn't available on pages protected by data loss prevention (DLP) policies to help maintain compliance. Learn more about Microsoft 365 Copilot Chat data, privacy, and security here: https://go.microsoft.com/fwlink/?linkid=2321816
ExperimentationAndConfigurationServiceControl Control communication with the Experimentation and Configuration Service
If you don't configure this policy on a managed device, the behavior on Beta and Stable channels is the same as the 'ConfigurationsOnlyMode'. If you don't configure this policy on an unmanaged device, the behavior is the same as the 'FullMode'.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ExperimentationAndConfigurationServiceControl
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
2Retrieve configurations and experiments1Retrieve configurations only0Disable communication with the Experimentation and Configuration ServiceThe Experimentation and Configuration Service is used to deploy Experimentation and Configuration payloads to the client. Experimentation payload consists of a list of early-in-development features that Microsoft is enabling for testing and feedback. Configuration payload consists of a list of recommended settings that Microsoft wants to deploy to optimize the user experience. Configuration payload may also contain a list of actions to take on certain domains for compatibility reasons. For example, the browser may override the User Agent string on a website if that website is broken. Each of these actions is intended to be temporary while Microsoft tries to resolve the issue with the site owner. If you set this policy to 'FullMode', the full payload is downloaded from the Experimentation and Configuration Service. This includes both the experimentation and configuration payloads. If you set this policy to 'ConfigurationsOnlyMode', only the configuration payload is downloaded. If you set this policy to 'RestrictedMode', the communication with the Experimentation and Configuration Service is stopped completely. Microsoft doesn't recommend this setting. If you don't configure this policy on a managed device, the behavior on Beta and Stable channels is the same as the 'ConfigurationsOnlyMode'. On Canary and Dev channels, the behavior is the same as 'FullMode'. If you don't configure this policy on an unmanaged device, the behavior is the same as the 'FullMode'. Policy options mapping: * FullMode (2) = Retrieve configurations and experiments * ConfigurationsOnlyMode (1) = Retrieve configurations only * RestrictedMode (0) = Disable communication with the Experimentation and Configuration Service Use the preceding information when configuring this policy.
EdgeEntraCopilotPageContext Control Copilot access to Microsoft Edge page content and browsing history for Entra account user profiles when using Copilot in the Microsoft Edge sidepane
If you don't configure this policy: - Access is enabled by default in non-EU regions.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeEntraCopilotPageContext
- Enabled / Disabled
- 1 / 0
- Stated default
- If you don't configure this policy: - Access is enabled by default in non-EU regions. - Access is disabled by default in EU regions.
- Supported on
- Microsoft Edge version 130, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Copilot in the Microsoft Edge side pane can access page content and browsing history. This includes page summarization and other contextual queries. This policy applies only to users who are signed in to Microsoft Edge with a Microsoft Entra account and are using Copilot in the side pane. It applies to Copilot experiences in the side pane, including Microsoft 365 Copilot Business Chat and Microsoft Copilot with enterprise data protection (EDP). If you enable this policy, Copilot can access page content and browsing history when users initiate contextual queries in the side pane or from Edge. If you disable this policy, Copilot can't access page content or browsing history. This also disables the M365LinksAutoOpenCopilotEnabled feature, because Copilot requires page content access to provide contextual insights for Microsoft 365 links. If you don't configure this policy: - Access is enabled by default in non-EU regions. - Access is disabled by default in EU regions. - Users can turn this setting on or off in Microsoft Edge settings. Copilot can't access page content on pages protected by data loss prevention (DLP) policies, even if this policy is enabled. For more information about Copilot data usage and consent, see https://go.microsoft.com/fwlink/?linkid=2288056
CopilotPageContext Control Copilot access to page context for Microsoft Entra ID profiles
If you don't configure this policy: - Access is enabled by default in non-EU regions.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- CopilotPageContext
- Enabled / Disabled
- 1 / 0
- Stated default
- If you don't configure this policy: - Access is enabled by default in non-EU regions. - Access is disabled by default in EU regions.
- Supported on
- Microsoft Edge version 124, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Copilot in the Microsoft Edge side pane can access page content. This policy applies only to Microsoft Entra ID profiles in Microsoft Edge. It doesn't apply to Microsoft account (MSA) profiles. Copilot requires access to page content to summarize pages and interact with text selections. This policy doesn't control access for Copilot with enterprise data protection (EDP). Access for Copilot with EDP is controlled by the 'EdgeEntraCopilotPageContext' (Control Copilot access to Microsoft Edge page content and browsing history for Entra account user profiles when using Copilot in the Microsoft Edge sidepane) policy. If you enable this policy, Copilot can access page content. If you disable this policy, Copilot can't access page content. This also disables the 'M365LinksAutoOpenCopilotEnabled' (Automatically open Copilot side pane with contextual insights for links opened from Outlook) feature, because Copilot requires page content access to provide contextual insights for Microsoft 365 links. If you don't configure this policy: - Access is enabled by default in non-EU regions. - Access is disabled by default in EU regions. - Users can turn this setting on or off in Microsoft Edge settings.
CopilotCDPPageContext Control Copilot with Commercial Data Protection access to page context for Microsoft Entra ID profiles (obsolete)
If you don't configure this policy, a user can enable access to page context for Copilot with Commercial Data Protection using the setting toggle in Edge.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- CopilotCDPPageContext
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 124-132, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 132. This policy has been obsoleted as of Edge 133. Instead of this obsolete policy, we recommend using 'EdgeEntraCopilotPageContext' (Control Copilot access to Microsoft Edge page content and browsing history for Entra account user profiles when using Copilot in the Microsoft Edge sidepane). This policy controls access to page contents for Copilot with Commercial Data Protection in the Edge sidebar. This policy applies only to Microsoft Entra ID profiles. To summarize pages and interact with text selections, it needs to be able to access the page contents. This policy doesn't apply to MSA profiles. This policy doesn't control access for Copilot without Commercial Data Protection. Access for Copilot without Commercial Data Protection is controlled by the policy CopilotPageContext. If you enable this policy, Copilot with Commercial Data Protection will have access to page context. If you don't configure this policy, a user can enable access to page context for Copilot with Commercial Data Protection using the setting toggle in Edge. If you disable this policy, Copilot with Commercial Data Protection won't be able to access page context.
SetTimeoutWithout1MsClampEnabled Control Javascript setTimeout() function minimum timeout (obsolete)
If you don't configure this policy, use the browser's default behavior for setTimeout() function. For users where this policy is unset, Microsoft Edge Stable rolls out the change gradually on the stable channel.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SetTimeoutWithout1MsClampEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 101-109, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 109. This policy is obsolete and doesn't work in Microsoft Edge after version 109. This policy was only provided temporarily to allow Enterprises to adapt to the new clamping behavior. If you enable this policy, the JavaScript setTimeout() with a timeout of 0 ms is no longer fixed to 1 ms to schedule timer-based callbacks. If you disable this policy, the JavaScript setTimeout() with a timeout of 0 ms is fixed to 1 ms to schedule timer-based callbacks. If you don't configure this policy, use the browser's default behavior for setTimeout() function. This is a web standards compliancy feature; however, it may change task ordering on a webpage, leading to unexpected behavior on sites that are dependent on a certain ordering. It also affects sites with many setTimeout()s with a timeout of 0-ms usage, for example, increasing CPU load. For users where this policy is unset, Microsoft Edge Stable rolls out the change gradually on the stable channel.
XSLTEnabled Control the availability of the XSLT feature
If you don't configure this policy, XSLT availability is determined by the browser's default configuration and any applicable field trials.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- XSLTEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 147, Windows 7 or later
- Template
- msedge.admx
Controls whether the XSLT feature (the XSLTProcessor JavaScript API and the XSL processing instruction) is available in Microsoft Edge. If you enable this policy, XSLT is available regardless of the browser's default configuration. If you disable this policy, XSLT is unavailable regardless of the browser's default configuration. If you don't configure this policy, XSLT availability is determined by the browser's default configuration and any applicable field trials. This policy is temporary and will be removed in a future version of Microsoft Edge.
BeforeunloadEventCancelByPreventDefaultEnabled Control the behavior for the cancel dialog produced by the beforeunload event (obsolete)
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- BeforeunloadEventCancelByPreventDefaultEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 118-130, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 130. This policy provides a temporary opt-out for two related fixes to the behavior of the confirmation dialog that’s shown by the beforeunload event. If you've enabled this policy, the new (correct) behavior is used. If you've disabled this policy, the old (legacy) behavior is used. If you haven't configured this policy, the default behavior is used. Note: This policy is a temporary workaround and is going to be removed in a future release. New and correct behavior: In `beforeunload`, calling `event.preventDefault()` triggers the confirmation dialog. Setting `event.returnValue` to the empty string doesn’t trigger the confirmation dialog. Old and legacy behavior: In `beforeunload`, calling `event.preventDefault()` doesn’t trigger the confirmation dialog. Setting `event.returnValue` to the empty string triggers the confirmation dialog.
IntensiveWakeUpThrottlingEnabled Control the IntensiveWakeUpThrottling feature
If you don't configure this policy, the feature is controlled by its own internal logic.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- IntensiveWakeUpThrottlingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 85, Windows 7 or later
- Template
- msedge.admx
When enabled, the IntensiveWakeUpThrottling feature causes Javascript timers in background tabs to be aggressively throttled and coalesced, running no more than once per minute after a page was backgrounded for 5 minutes or more. This feature is a web standards compliant feature, but it may break functionality on some websites by causing certain actions to be delayed by up to a minute. However, it results in significant CPU and battery savings when enabled. For more information, see https://bit.ly/30b1XR4. If you enable this policy, the feature is force enabled, and users can't override this setting. If you disable this policy, the feature is force disabled, and users can't override this setting. If you don't configure this policy, the feature is controlled by its own internal logic. Users can manually configure this setting. The policy is applied per renderer process, with the most recent value of the policy setting in force when a renderer process starts. A full restart is required to ensure that all the loaded tabs receive a consistent policy setting. It's harmless for processes to be running with different values of this policy.
DnsOverHttpsMode Control the mode of DNS-over-HTTPS
If you don't configure this policy for managed devices, DNS-over-HTTPS queries aren't sent.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DnsOverHttpsMode
- Supported on
- Microsoft Edge version 83, Windows 7 or later
- Template
- msedge.admx
Disable DNS-over-HTTPSEnable DNS-over-HTTPS with insecure fallbackEnable DNS-over-HTTPS without insecure fallbackControl the mode of the DNS-over-HTTPS resolver. This policy only sets the default mode for each query. The mode can be overridden for special types of queries such as requests to resolve a DNS-over-HTTPS server hostname. The "off" mode disables DNS-over-HTTPS. The "automatic" mode sends DNS-over-HTTPS queries first if a DNS-over-HTTPS server is available, and falls back to sending insecure queries on error. The "secure" mode only sends DNS-over-HTTPS queries and will fail to resolve on error. If you don't configure this policy for managed devices, DNS-over-HTTPS queries aren't sent. Instead, the browser may send DNS requests to a resolver associated with the user's system resolver. This could lead to a less secure or private DNS resolution process, depending on the resolver in use. Policy options mapping: * off (off) = Disable DNS-over-HTTPS * automatic (automatic) = Enable DNS-over-HTTPS with insecure fallback * secure (secure) = Enable DNS-over-HTTPS without insecure fallback Use the preceding information when configuring this policy. Example value: off
SendMouseEventsDisabledFormControlsEnabled Control the new behavior for event dispatching on disabled form controls (obsolete)
If you enable or don't configure this policy, the new behavior is used.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SendMouseEventsDisabledFormControlsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 109-120, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 120. Event dispatching on disabled form controls is being changed in Microsoft Edge to improve compatibility with other browsers and to improve the developer experience. With this change, MouseEvents get dispatched on disabled form control elements. Exceptions for this behavior are click, mouseup, and mousedown. Some examples of the new events are mousemove, mouseenter, and mouseleave. This change also truncates the event path of click, mouseup, and mousedown when they’re dispatched on children of disabled form controls. These events aren’t dispatched on the disabled form control or on any of its ancestors. Note: This new behavior might break some websites. If you enable or don't configure this policy, the new behavior is used. If you disable this policy, the old behavior is used.
UserAgentClientHintsGREASEUpdateEnabled Control the User-Agent Client Hints GREASE Update feature (obsolete)
io/ua-client-hints/#grease If this policy is enabled or not configured, the User-Agent GREASE algorithm from the specification is used.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- UserAgentClientHintsGREASEUpdateEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- This policy will be obsolete after version 133 because the updated GREASE algorithm is on by default since Microsoft Edge version 102.
- Supported on
- Microsoft Edge version 102-133, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 133. The User-Agent GREASE specification recommends the inclusion of more GREASE characters beyond the current semicolon and space, and recommends that the arbitrary version number is varied over time. When enabled, the User-Agent Client Hints GREASE Update feature aligns the User-Agent GREASE algorithm with the latest version from the specification. The updated specification can break some websites that restrict the characters that requests may contain. For more information, see the following specification: https://wicg.github.io/ua-client-hints/#grease If this policy is enabled or not configured, the User-Agent GREASE algorithm from the specification is used. If the policy is disabled, the prior User-Agent GREASE algorithm is used. This policy will be obsolete after version 133 because the updated GREASE algorithm is on by default since Microsoft Edge version 102.
HeadlessModeEnabled Control use of the Headless Mode
If you enable or don't configure this policy, Microsoft Edge allows use of the headless mode.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- HeadlessModeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 92, Windows 7 or later
- Template
- msedge.admx
This policy setting lets you decide whether users can launch Microsoft Edge in headless mode. If you enable or don't configure this policy, Microsoft Edge allows use of the headless mode. If you disable this policy, Microsoft Edge denies use of the headless mode.
DefaultSerialGuardSetting Control use of the Serial API
If you don't configure this policy, by default, websites can ask users whether they can access a serial port, and users can change this setting.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultSerialGuardSetting
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
2Do not allow any site to request access to serial ports via the Serial API3Allow sites to ask for user permission to access a serial portSet whether websites can access serial ports. You can completely block access or ask the user each time a website wants to get access to a serial port. Setting the policy to 3 lets websites ask for access to serial ports. Setting the policy to 2 denies access to serial ports. You can override this policy for specific URL patterns by using the 'SerialAskForUrls' (Allow the Serial API on specific sites) and 'SerialBlockedForUrls' (Block the Serial API on specific sites) policies. If you don't configure this policy, by default, websites can ask users whether they can access a serial port, and users can change this setting. Policy options mapping: * BlockSerial (2) = Do not allow any site to request access to serial ports via the Serial API * AskSerial (3) = Allow sites to ask for user permission to access a serial port Use the preceding information when configuring this policy.
DeveloperToolsAvailability Control where developer tools can be used
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DeveloperToolsAvailability
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
0Block the developer tools on extensions installed by enterprise policy, allow in other contexts1Allow using the developer tools2Don't allow using the developer toolsControls whether users can access developer tools in Microsoft Edge. If you set this policy to 'DeveloperToolsDisallowedForForceInstalledExtensions' (default), users can access developer tools and the JavaScript console, except in the context of extensions installed by enterprise policy. If you set this policy to 'DeveloperToolsAllowed', users can access developer tools and the JavaScript console in all contexts, including extensions installed by enterprise policy. If you set this policy to 'DeveloperToolsDisallowed', users cannot access developer tools or inspect website elements. Keyboard shortcuts, menu options, and context menu entries that open developer tools or the JavaScript console are disabled. As of version 99, this policy also controls access to the 'View page source' feature. If you set this policy to 'DeveloperToolsDisallowed', users cannot view page source through keyboard shortcuts or the context menu. To fully block source viewing, add 'view-source:*' to the 'URLBlocklist' (Block access to a list of URLs) policy. As of version 119, this policy also controls whether developer mode for Isolated Web Apps can be enabled. As of version 128, this policy does not control developer mode on the extensions page if the 'ExtensionDeveloperModeSettings' (Control the availability of developer mode on extensions page) policy is configured. Developer tools availability is determined in the following order of precedence: 1. If a URL matches a pattern in 'DeveloperToolsAvailabilityAllowlist' (List of URL patterns for which developer tools are allowed to be opened), developer tools are allowed. 2. If the allowlist is configured and the blocklist is not, URLs not on the allowlist are blocked. 3. If a URL matches a pattern in 'DeveloperToolsAvailabilityBlocklist' (List of URL patterns for which developer tools are blocked), developer tools are blocked. 4. If a URL is not covered by either list, this policy ('DeveloperToolsAvailability' (Control where developer tools can be used)) applies. Policy options mapping: * DeveloperToolsDisallowedForForceInstalledExtensions (0) = Block the developer tools on extensions installed by enterprise policy, allow in other contexts * DeveloperToolsAllowed (1) = Allow using the developer tools * DeveloperToolsDisallowed (2) = Don't allow using the developer tools Use the preceding information when configuring this policy.
OverrideSecurityRestrictionsOnInsecureOrigin Control where security restrictions on insecure origins apply
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\OverrideSecurityRestrictionsOnInsecureOrigin
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specifies a list of origins (URLs) or hostname patterns (like "*.contoso.com") for which security restrictions on insecure origins don't apply. This policy allows you to specify permitted origins for legacy applications that can't deploy TLS or for internal web development staging servers. It enables developers to test features requiring secure contexts without the need to configure TLS on the staging server. Patterns are only accepted for hostnames; URLs or origins with schemes must be exact matches. This policy also prevents the origin from being labeled "Not Secure" in the omnibox. Setting a list of URLs in this policy has the same effect as setting the command-line flag '--unsafely-treat-insecure-origin-as-secure' to a comma-separated list of the same URLs. If you enable this policy, it overrides the command-line flag. For more information on secure contexts, see https://www.w3.org/TR/secure-contexts/. Example value: http://testserver.contoso.com/ *.contoso.com
WhatsNewPageForEntraProfilesEnabled Control whether an informational webpage for Edge for Business is shown in the new tab after major browser updates
If you enable this policy or do not configure it, Microsoft Edge shows the informational page by default.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WhatsNewPageForEntraProfilesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 144, Windows 7 or later
- Template
- msedge.admx
Starting in Microsoft Edge version 145, users with Microsoft Entra ID profiles will see an informational page about new Edge for Business features after major browser updates. This page highlights recent enhancements designed to promote secure and productive browsing. This policy controls whether users with Microsoft Entra ID profiles see this informational page. This policy applies only to Microsoft Entra ID profiles and does not apply to Microsoft account (MSA) profiles. This policy is available starting in Microsoft Edge version 144 to allow configuration ahead of the changes introduced in version 145. If you enable this policy or do not configure it, Microsoft Edge shows the informational page by default. If you disable this policy, Microsoft Edge does not show the informational page to users.
Microsoft365CopilotChatIconEnabled Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar
If the policy isn't configured: Otherwise, Copilot shows in the toolbar and users can enable or disable Copilot from showing by using the Show Copilot toggle in settings.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- Microsoft365CopilotChatIconEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 139, Windows 7 or later
- Template
- msedge.admx
For users in an Entra ID Microsoft Edge profile, this policy controls whether the Microsoft 365 Copilot Chat icon is shown in the Microsoft Edge for Business toolbar for Microsoft 365 Copilot licensed and unlicensed users. This policy only applies when users are accessing Copilot in the sidepane. If the policy is enabled: Copilot appears in the toolbar. If the policy is disabled: Copilot doesn't appear in the toolbar. If the policy isn't configured: Otherwise, Copilot shows in the toolbar and users can enable or disable Copilot from showing by using the Show Copilot toggle in settings.
StaticStorageQuotaEnabled Control whether storage quota APIs will return static values
When unset, the browser uses the default platform behavior.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- StaticStorageQuotaEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 145, Windows 7 or later
- Template
- msedge.admx
Controls how the Storage Quota APIs report the available quota to websites. When enabled, the Storage Quota APIs return a static quota value equal to the current usage plus the smaller of 10 GiB or the device's total storage rounded up to the nearest 1 GiB. When disabled, the Storage Quota APIs return a dynamic quota value that reflects the actual available device storage. When unset, the browser uses the default platform behavior. This policy does not affect sites with unlimited storage permissions or enforced quota settings.
TLS13EarlyDataEnabled Control whether TLS 1.3 Early Data is enabled in Microsoft Edge
Not configured – Microsoft Edge follows the default rollout process for TLS 1.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- TLS13EarlyDataEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 138, Windows 7 or later
- Template
- msedge.admx
This policy controls whether TLS 1.3 Early Data is enabled in Microsoft Edge. TLS 1.3 Early Data is an extension that allows an HTTP request to be sent in parallel with the TLS handshake. When enabled and supported by the server, this can improve page load performance. Enabled – Microsoft Edge enables TLS 1.3 Early Data. Disabled – Microsoft Edge disables TLS 1.3 Early Data. Not configured – Microsoft Edge follows the default rollout process for TLS 1.3 Early Data. NOTE: When this feature is enabled, whether TLS 1.3 Early Data is used depends on server support. Most modern TLS servers and middleware can handle or reject Early Data without interrupting the connection. However, improperly implemented TLS stacks may cause connection failures. If such issues occur, contact the device or software vendor for a resolution. This policy is temporary and intended to help test for compatibility issues. It may be removed in a future release once the feature is fully rolled out.
EdgeSidebarAppUrlHostForceList Control which apps are forced to be shown in Microsoft Edge sidebar
If you don't configure this policy, no app is forced to be shown in sidebar.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\EdgeSidebarAppUrlHostForceList
- Supported on
- Microsoft Edge version 133, Windows 7 or later
- Template
- msedge.admx
Define a list of sites, based on URL, that are forced to be shown in sidebar. If you don't configure this policy, no app is forced to be shown in sidebar. If the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy is disabled, this list isn't used, and no sidebar can be shown. For detailed information about valid URL, see https://go.microsoft.com/fwlink/?linkid=2281313. Note: URL patterns aren't supported in this policy. You should provide the exact URL of the app. Example value: https://www.contoso.com
EdgeSidebarAppUrlHostBlockList Control which apps cannot be opened in Microsoft Edge sidebar
If you don't configure this policy, a user can open any app in sidebar.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\EdgeSidebarAppUrlHostBlockList
- Supported on
- Microsoft Edge version 127, Windows 7 or later
- Template
- msedge.admx
Define a list of sites, based on URL patterns, that cannot be opened in sidebar. If you don't configure this policy, a user can open any app in sidebar. If the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy is disabled, this list isn't used and no sidebar can be opened. For detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2281313. Note: A blocklist value of '*' means all apps are blocked unless they are explicitly listed in the 'EdgeSidebarAppUrlHostAllowList' (Allow specific apps to be opened in Microsoft Edge sidebar) policy. Starting in Microsoft Edge version 149, the 'Microsoft365CopilotChatIconEnabled' (Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar) policy controls the display of Copilot in the sidebar. Example value: https://www.contoso.com [*.]contoso.edu
AllowBrowsingWithCopilot Controls the availability of browsing with Copilot in Microsoft Edge.
If you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AllowBrowsingWithCopilot
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 148, Windows 7 or later
- Template
- msedge.admx
When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically. Browsing with Copilot is available only on domains specified in the 'BrowsingWithCopilotAllowList' (Browsing with Copilot Allowed URLs) policy and is blocked on domains specified in the 'BrowsingWithCopilotBlockList' (Browsing with Copilot Blocked URLs) policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled. This feature is available only to users with an active Microsoft 365 Copilot subscription. For more information about configuring browsing with Copilot, see https://go.microsoft.com/fwlink/?LinkId=2341535. If you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off. If you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on. If you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.
CSSCustomStateDeprecatedSyntaxEnabled Controls whether the deprecated :--foo syntax for CSS custom state is enabled (obsolete)
If you disable or don't configure this policy, the deprecated syntax is disabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- CSSCustomStateDeprecatedSyntaxEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 127-132, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 132. The :--foo syntax for the CSS custom state feature is being changed to :state(foo) in Microsoft Edge to comply with changes that are made in Firefox and Safari. This policy allows the deprecated syntax to be used until Stable 132. This deprecation breaks some Microsoft Edge-only websites that use the deprecated :--foo syntax. If you enable this policy, the deprecated syntax is enabled. If you disable or don't configure this policy, the deprecated syntax is disabled.
SelectParserRelaxationEnabled Controls whether the new HTML parser behavior for the <select> element is enabled (obsolete)
If this policy is enabled or unset, the HTML parser allows additional tags inside the <select> element.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SelectParserRelaxationEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 132-138, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 138. The HTML parser is being changed to allow additional HTML tags inside the <select> element. This policy supports the old HTML parser behavior through Microsoft Edge version 138. If this policy is enabled or unset, the HTML parser allows additional tags inside the <select> element. If this policy is disabled, then the HTML parser restricts which tags can be put in the <select> element.
ForcePermissionPolicyUnloadDefaultEnabled Controls whether unload event handlers can be disabled.
If you disable this policy or don't configure it, unload event handlers are gradually deprecated in-line with the deprecation rollout, and sites that don't set Permissions-Policy header stop firing `unload` events.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ForcePermissionPolicyUnloadDefaultEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- Currently, the policy allows them by default. In the future, they move to being disallowed by default, and sites must explicitly enable them using Permissions-Policy headers.
- Supported on
- Microsoft Edge version 118, Windows 7 or later
- Template
- msedge.admx
unload event handlers are being deprecated. Whether they fire depends on the unload Permissions-Policy. Currently, the policy allows them by default. In the future, they move to being disallowed by default, and sites must explicitly enable them using Permissions-Policy headers. This enterprise policy can be used to opt out of this gradual deprecation by forcing the default to stay enabled. Pages might depend on unload event handlers to save data or to signal the end of a user session to the server. This dependency isn't recommended because it's unreliable and impacts performance by blocking use of BackForwardCache. Recommended alternatives exist, but the unload event has been used for a long time. Some applications might still rely on them. If you disable this policy or don't configure it, unload event handlers are gradually deprecated in-line with the deprecation rollout, and sites that don't set Permissions-Policy header stop firing `unload` events. If you enable this policy, the unload event handlers continue to work by default.
CORSNonWildcardRequestHeadersSupport CORS non-wildcard request header support enabled
If you enable or don't configure the policy, Microsoft Edge supports the CORS non-wildcard request headers and behaves as previously described.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- CORSNonWildcardRequestHeadersSupport
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 97, Windows 7 or later
- Template
- msedge.admx
This policy lets you configure support for CORS non-wildcard request headers. Microsoft Edge version 97 introduces support for CORS non-wildcard request headers. When a script makes a cross-origin network request via fetch() and XMLHttpRequest with a script-added Authorization header, the header is explicitly allowed by the Access-Control-Allow-Headers header in the CORS preflight response. "Explicitly" here means that the wild card symbol "*" doesn't cover the Authorization header. For more information, see https://go.microsoft.com/fwlink/?linkid=2180022. If you enable or don't configure the policy, Microsoft Edge supports the CORS non-wildcard request headers and behaves as previously described. If you disable this policy, Microsoft Edge allows the wildcard symbol ("*") in the Access-Control-Allow-Headers header in the CORS preflight response to cover the Authorization header. This policy is a temporary workaround for the new CORS non-wildcard request header feature. It's planned to be removed in the future.
DefaultClipboardSetting Default clipboard site permission
Setting the policy to 3 or leaving it unset lets the user change the setting and decide if the clipboard APIs are available when a site wants to use an API.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultClipboardSetting
- Supported on
- Microsoft Edge version 109, Windows 7 or later
- Template
- msedge.admx
2Do not allow any site to use the clipboard site permission3Allow sites to ask the user to grant the clipboard site permissionThis policy controls the default value for the clipboard site permission. Setting the policy to 2 blocks sites from using the clipboard site permission. Setting the policy to 3 or leaving it unset lets the user change the setting and decide if the clipboard APIs are available when a site wants to use an API. This policy can be overridden for specific URL patterns using the 'ClipboardAllowedForUrls' (Allow clipboard use on specific sites) and 'ClipboardBlockedForUrls' (Block clipboard use on specific sites) policies. This policy only affects clipboard operations controlled by the clipboard site permission and doesn't affect sanitized clipboard writes or trusted copy and paste operations. Policy options mapping: * BlockClipboard (2) = Do not allow any site to use the clipboard site permission * AskClipboard (3) = Allow sites to ask the user to grant the clipboard site permission Use the preceding information when configuring this policy.
DefaultSensorsSetting Default sensors setting
If you don't configure this policy, websites can access and use sensors, and users can change this setting.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultSensorsSetting
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
1Allow sites to access sensors2Do not allow any site to access sensors3Ask whenever a site wants to access sensorsSet whether websites can access and use sensors such as motion and light sensors. You can completely block or allow websites to get access to sensors. Setting the policy to 1 lets websites access and use sensors. Setting the policy to 2 denies access to sensors. Setting the policy to 3 prompts the user when a site requests access to sensors if the tri-state feature flag is enabled; otherwise, it defaults to allowing access to sensors. You can override this policy for specific URL patterns by using the 'SensorsAllowedForUrls' (Allow access to sensors on specific sites) and 'SensorsBlockedForUrls' (Block access to sensors on specific sites) policies. If you don't configure this policy, websites can access and use sensors, and users can change this setting. This setting is the global default for 'SensorsAllowedForUrls' and 'SensorsBlockedForUrls'. Policy options mapping: * AllowSensors (1) = Allow sites to access sensors * BlockSensors (2) = Do not allow any site to access sensors * AskSensors (3) = Ask whenever a site wants to access sensors Use the preceding information when configuring this policy.
URLAllowlist Define a list of allowed URLs
If you don't configure this policy, there are no exceptions to the blocklist in the 'URLBlocklist' policy.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\URLAllowlist
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Setting the policy provides access to the listed URLs as exceptions to 'URLBlocklist' (Block access to a list of URLs). Format the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322. You can use this policy to open exceptions to restrictive blocklists. For example, you can include '*' in the blocklist to block all requests, and then use this policy to allow access to a limited list of URLs. You can use this policy to open exceptions to certain schemes, subdomains of other domains, ports, or specific paths. The most specific filter determines if a URL is blocked or allowed. The allowed list takes precedence over the blocked list. This policy is limited to 1000 entries; subsequent entries are ignored. This policy also allows the browser to automatically invoke external applications registered as protocol handlers for protocols like "tel:" or "ssh:". If you don't configure this policy, there are no exceptions to the blocklist in the 'URLBlocklist' policy. This policy doesn't work as expected with file://* wildcards. Example value: contoso.com https://ssl.server.com hosting.com/good_path https://server:8080/path .exact.hostname.com
AutoLaunchProtocolsFromOrigins Define a list of protocols that can launch an external application from listed origins without prompting the user
If you don't configure this policy, no protocols can launch without a prompt.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AutoLaunchProtocolsFromOrigins
- Supported on
- Microsoft Edge version 85, Windows 7 or later
- Template
- msedge.admx
Allows you to set a list of protocols, and for each protocol an associated list of allowed origin patterns, that can launch an external application without prompting the user. The trailing separator shouldn't be included when listing the protocol and the protocol should be all lower case. For example, list "skype" instead of "skype:", "skype://" or "Skype". If you configure this policy, a protocol is only permitted to launch an external application without prompting by policy if: - the protocol is listed - the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list. If either condition is false, the external protocol launch prompt isn't omitted, by policy. If you don't configure this policy, no protocols can launch without a prompt. Users can opt out of prompts on a per-protocol/per-site basis unless the 'ExternalProtocolDialogShowAlwaysOpenCheckbox' (Show an "Always open" checkbox in external protocol dialog) policy is set to Disabled. This policy has no impact on per-protocol/per-site prompt exemptions set by users. The origin-matching patterns use a similar format to those for the 'URLBlocklist' (Block access to a list of URLs) policy, which are documented at https://go.microsoft.com/fwlink/?linkid=2095322. However, origin-matching patterns for this policy can't contain "/path" or "@query" elements. Any pattern that contains a "/path" or "@query" element is ignored. This policy doesn't work as expected with file://* wildcards. Example value: [ { "allowed_origins": [ "example.com", "http://www.example.com:8080" ], "protocol": "spotify" }, { "allowed_origins": [ "https://example.com", "https://.mail.example.com" ], "protocol": "msteams" }, { "allowed_origins": [ "*" ], "protocol": "msoutlook" } ]
DoNotSilentlyBlockProtocolsFromOrigins Define a list of protocols that can not be silently blocked by anti-flood protection
If you don't configure this policy, no protocols can bypass being silently blocked.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DoNotSilentlyBlockProtocolsFromOrigins
- Supported on
- Microsoft Edge version 99, Windows 7 or later
- Template
- msedge.admx
Allows you to create a list of protocols and an associated list of allowed origin patterns, for each protocol. These origins aren't silently blocked from launching an external application by anti-flood protection. The trailing separator shouldn't be included when listing the protocol. For example, list "skype" instead of "skype:" or "skype://". If you configure this policy, a protocol is only permitted to bypass being silently blocked by anti-flood protection if: - the protocol is listed - the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list. If either condition is false, anti-flood protection protection blocks the external protocol launch. If you don't configure this policy, no protocols can bypass being silently blocked. The origin-matching patterns use a similar format to those patterns for the 'URLBlocklist' (Block access to a list of URLs) policy, which are documented at https://go.microsoft.com/fwlink/?linkid=2095322. However, origin-matching patterns for this policy can't contain "/path" or "@query" elements. Any pattern that contains a "/path" or "@query" element is ignored. This policy doesn't work as expected with file://* wildcards. Example value: [ { "allowed_origins": [ "example.com", "http://www.example.com:8080" ], "protocol": "spotify" }, { "allowed_origins": [ "https://example.com", "https://.mail.example.com" ], "protocol": "msteams" }, { "allowed_origins": [ "*" ], "protocol": "msoutlook" } ]
DefinePreferredLanguages Define an ordered list of preferred languages that websites should display in if the site supports the language
If you don't configure or disable this policy, Microsoft Edge sends websites the user-specified preferred languages as part of the Accept-Language request HTTP header.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefinePreferredLanguages
- Supported on
- Microsoft Edge version 89, Windows 7 or later
- Template
- msedge.admx
Configures the language variants that Microsoft Edge sends to websites as part of the Accept-Language request HTTP header and prevents users from adding, removing, or changing the order of preferred languages in Microsoft Edge settings. Users who want to change the languages Microsoft Edge displays in or offers to translate pages to will be limited to the languages configured in this policy. If you enable this policy, websites will appear in the first language in the list that they support unless other site-specific logic is used to determine the display language. The language variants defined in this policy override the languages configured as part of the 'SpellcheckLanguage' (Enable specific spellcheck languages) policy. If you don't configure or disable this policy, Microsoft Edge sends websites the user-specified preferred languages as part of the Accept-Language request HTTP header. For detailed information on valid language variants, see https://go.microsoft.com/fwlink/?linkid=2148854. Example value: en-US,fr,es
AllowedDomainsForApps Define domains allowed to access Google Workspace
If you don't provide a domain name or leave this policy unset, users can access Google Workspace with any account.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AllowedDomainsForApps
- Supported on
- Microsoft Edge version 104, Windows 7 or later
- Template
- msedge.admx
Setting the policy on Microsoft Edge turns on the restricted sign-in feature in Google Workspace and prevents users from changing this setting. Users can only access Google tools using accounts from the specified domains. To allow gmail or googlemail accounts, add consumer_accounts to the list of domains. This policy is based on the Chrome policy of the same name. If you don't provide a domain name or leave this policy unset, users can access Google Workspace with any account. Users can't change or override this setting. Note: This policy causes the X-GoogApps-Allowed-Domains header to be appended to all HTTP and HTTPS requests to all google.com domains, as described in https://go.microsoft.com/fwlink/?linkid=2197973. Example value: example.com
DeleteDataOnMigration Delete old browser data on migration
If you set this policy to "Disabled", or the policy isn't configured, user browsing data isn't deleted after migrating to the Microsoft Edge version 83 or later.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DeleteDataOnMigration
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 83, Windows 7 or later
- Template
- msedge.admx
This policy determines whether user browsing data from Microsoft Edge Legacy will be deleted after migrating to the Microsoft Edge version 81 or later. If you set this policy to "Enabled", all browsing data from Microsoft Edge Legacy after migrating to the Microsoft Edge version 81 or later is deleted. This policy must be set before migrating to the Microsoft Edge version 81 or later to have any effect on existing browsing data. If you set this policy to "Disabled", or the policy isn't configured, user browsing data isn't deleted after migrating to the Microsoft Edge version 83 or later.
EnforceLocalAnchorConstraintsEnabled Determines whether the built-in certificate verifier will enforce constraints encoded into trust anchors loaded from the platform trust store (obsolete)
If you enable this policy or don't configure it, Microsoft Edge enforces constraints encoded into trust anchors loaded from the platform trust store.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EnforceLocalAnchorConstraintsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 113-127, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 127. X.509 certificates might encode constraints, such as Name Constraints, in extensions in the certificate. RFC 5280 specifies that enforcing such constraints on trust anchor certificates is optional. From Microsoft Edge 112, such constraints in certificates loaded from the platform certificate store will now be enforced. This policy exists as a temporary opt-out in case an enterprise encounters issues with the constraints encoded in their private roots. In that case this policy may be used to temporarily disable enforcement of the constraints while correcting the certificate issues. If you enable this policy or don't configure it, Microsoft Edge enforces constraints encoded into trust anchors loaded from the platform trust store. If you disable this policy, Microsoft Edge won't enforce constraints encoded into trust anchors loaded from the platform trust store. This policy has no effect if the 'MicrosoftRootStoreEnabled' (Determines whether the Microsoft Root Store and built-in certificate verifier will be used to verify server certificates) policy is disabled. This policy was removed in Microsoft Edge version 128. Starting with that version, constraints in trust anchors are always enforced.
MicrosoftRootStoreEnabled Determines whether the Microsoft Root Store and built-in certificate verifier will be used to verify server certificates (obsolete)
If you don't configure this policy, the Microsoft Root Store or system-provided roots may be used.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- MicrosoftRootStoreEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 109-114, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 114. If you enable this policy, Microsoft Edge performs verification of server certificates using the built-in certificate verifier with the Microsoft Root Store as the source of public trust. If you disable this policy, Microsoft Edge uses the system certificate verifier and system root certificates. If you don't configure this policy, the Microsoft Root Store or system-provided roots may be used. This policy is planned to be removed in Microsoft Edge version 121 for Android devices when support for using the platform-supplied roots is planned to be removed. This policy was removed in Microsoft Edge version 115 for Microsoft Windows and macOS, Microsoft Edge version 120 for Linux, and Microsoft Edge version 121 for Android when support for using the platform-supplied certificate verifier and roots was removed.
CertificateTransparencyEnforcementDisabledForLegacyCas Disable Certificate Transparency enforcement for a list of legacy certificate authorities (obsolete)
If you don't configure this policy, any certificate that's required to be disclosed via Certificate Transparency is treated as untrusted if it isn't disclosed according to the Certificate Transparency policy.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\CertificateTransparencyEnforcementDisabledForLegacyCas
- Stated default
- A legacy CA is a CA publicly trusted, by default, by one or more operating systems supported by Microsoft Edge.
- Supported on
- Microsoft Edge version 77-131, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 131. Disables enforcing Certificate Transparency requirements for a list of legacy certificate authorities (Cas). This policy lets you disable Certificate Transparency disclosure requirements for certificate chains that contain certificates with one of the specified subjectPublicKeyInfo hashes. This disablement of requirements allows otherwise-untrusted certificates (on account of not being publicly disclosed) to continue to be used for enterprise hosts. For Certificate Transparency enforcement to be disabled, you must set the hash to a subjectPublicKeyInfo appearing in an authority-issued certificate that's recognized as a legacy certificate authority (CA). A legacy CA is a CA publicly trusted, by default, by one or more operating systems supported by Microsoft Edge. You specify a subjectPublicKeyInfo hash by concatenating the hash algorithm name, the "/" character, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. This Base64 encoding is the same format as an SPKI Fingerprint, as defined in RFC 7469, Section 2.4. Unrecognized hash algorithms are ignored. The only supported hash algorithm at this time is "sha256". If you don't configure this policy, any certificate that's required to be disclosed via Certificate Transparency is treated as untrusted if it isn't disclosed according to the Certificate Transparency policy. This policy is obsolete because the feature to disable Certificate Transparency enforcement for legacy certificates has been removed. Example value: sha256/AAAAAAAAAAAAAAAAAAAAAA== sha256//////////////////////w==
CertificateTransparencyEnforcementDisabledForCas Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes
If you disable this policy or don't configure it, any certificate required to be disclosed via Certificate Transparency is treated as untrusted if not disclosed according to the Certificate Transparency policy.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\CertificateTransparencyEnforcementDisabledForCas
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Disables enforcement of Certificate Transparency requirements for a list of subjectPublicKeyInfo hashes. This policy lets you disable Certificate Transparency disclosure requirements for certificate chains that contain certificates with one of the specified subjectPublicKeyInfo hashes. This allows certificates that would otherwise be untrusted because they weren't properly publicly disclosed to still be used for Enterprise hosts. To disable Certificate Transparency enforcement when this policy is set, one of the following sets of conditions must be met: 1. The hash is of the server certificate's subjectPublicKeyInfo. 2. The hash is of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, that CA certificate is constrained via the X.509v3 nameConstraints extension, one or more directoryName nameConstraints are present in the permittedSubtrees, and the directoryName contains an organizationName attribute. 3. The hash is of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, the CA certificate has one or more organizationName attributes in the certificate Subject, and the server's certificate contains the same number of organizationName attributes, in the same order, and with byte-for-byte identical values. A subjectPublicKeyInfo hash is specified by concatenating the hash algorithm name, the "/" character, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. This Base64 encoding is the same format as an SPKI Fingerprint, as defined in RFC 7469, Section 2.4. Unrecognized hash algorithms are ignored. The only supported hash algorithm at this time is "sha256". If you disable this policy or don't configure it, any certificate required to be disclosed via Certificate Transparency is treated as untrusted if not disclosed according to the Certificate Transparency policy. Example value: sha256/AAAAAAAAAAAAAAAAAAAAAA== sha256//////////////////////w==
CertificateTransparencyEnforcementDisabledForUrls Disable Certificate Transparency enforcement for specific URLs
If you don't configure this policy, any certificate that should be disclosed via Certificate Transparency is treated as untrusted if it's not disclosed.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\CertificateTransparencyEnforcementDisabledForUrls
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Disables enforcing Certificate Transparency requirements for the listed URLs. This policy lets you not disclose certificates for the hostnames in the specified URLs via Certificate Transparency. This lets you use certificates that would otherwise be untrusted, because they weren't properly publicly disclosed, but it makes it harder to detect mis-issued certificates for those hosts. Form your URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322. Because certificates are valid for a given hostname, independent of the scheme, port, or path, only the hostname part of the URL is considered. Wildcard hosts aren't supported. If you don't configure this policy, any certificate that should be disclosed via Certificate Transparency is treated as untrusted if it's not disclosed. This policy doesn't work as expected with file://* wildcards. Example value: contoso.com .contoso.com
ExemptFileTypeDownloadWarnings Disable download file type extension-based warnings for specified file types on domains
If you disable this policy or don't configure it, file types that trigger extension-based download warnings show warnings to the user.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ExemptFileTypeDownloadWarnings
- Supported on
- Microsoft Edge version 105, Windows 7 or later
- Template
- msedge.admx
You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that are exempted from file type extension-based download warnings. This exemption lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the "jnlp" extension is associated with "website1.com", users can't see a warning when downloading "jnlp" files from "website1.com" but can see a download warning when downloading "jnlp" files from "website2.com". Files with file type extensions specified for domains identified by this policy are still subject to nonfile type extension-based security warnings such as mixed-content download warnings and Microsoft Defender SmartScreen warnings. If you disable this policy or don't configure it, file types that trigger extension-based download warnings show warnings to the user. If you enable this policy: * The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322. * The file type extension entered must be in lower-cased ASCII. The leading separator shouldn't be included when listing the file type extension; so, list "jnlp" should be used instead of ".jnlp". Example: The following example value prevents file type extension-based download warnings on swf, exe, and jnlp extensions for *.contoso.com domains. It shows the user a file type extension-based download warning on any other domain for exe and jnlp files, but not for swf files. [ { "file_extension": "jnlp", "domains": ["contoso.com"] }, { "file_extension": "exe", "domains": ["contoso.com"] }, { "file_extension": "swf", "domains": ["*"] } ] While the preceding example shows the suppression of file type extension-based download warnings for "swf" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension isn't recommended due to security concerns. It's shown in the example merely to demonstrate the ability to do so. Example value: [ { "domains": [ "https://contoso.com", "contoso2.com" ], "file_extension": "jnlp" }, { "domains": [ "*" ], "file_extension": "swf" } ]
ExemptDomainFileTypePairsFromFileTypeDownloadWarnings Disable download file type extension-based warnings for specified file types on domains (obsolete)
If you disable this policy or don't configure it, file types that trigger extension-based download warnings show warnings to the user.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ExemptDomainFileTypePairsFromFileTypeDownloadWarnings
- Supported on
- Microsoft Edge version 85-109, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 109. This policy is obsoleted in favor of 'ExemptFileTypeDownloadWarnings' (Disable download file type extension-based warnings for specified file types on domains) because of a type mismatch that caused errors in Mac. You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that are exempted from file type extension-based download warnings. This exemption lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the "jnlp" extension is associated with "website1.com", users don't see a warning when downloading "jnlp" files from "website1.com" but see a download warning when downloading "jnlp" files from "website2.com". Files with file type extensions specified for domains identified by this policy are still subject to nonfile type extension-based security warnings such as mixed-content download warnings and Microsoft Defender SmartScreen warnings. If you disable this policy or don't configure it, file types that trigger extension-based download warnings show warnings to the user. If you enable this policy: * The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322. * The file type extension entered must be in lower-cased ASCII. The leading separator shouldn't be included when listing the file type extension; so, list "jnlp" should be used instead of ".jnlp". Example: The following example value prevents file type extension-based download warnings on swf, exe, and jnlp extensions for *.contoso.com domains. It shows the user a file type extension-based download warning on any other domain for exe and jnlp files but not for swf files. [ { "file_extension": "jnlp", "domains": ["contoso.com"] }, { "file_extension": "exe", "domains": ["contoso.com"] }, { "file_extension": "swf", "domains": ["*"] } ] While the preceding example shows the suppression of file type extension-based download warnings for "swf" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension isn't recommended due to security concerns. It's shown in the example merely to demonstrate the ability to do so. Example value: {"domains": ["https://contoso.com", "contoso2.com"], "file_extension": "jnlp"} {"domains": ["*"], "file_extension": "swf"}
SavingBrowserHistoryDisabled Disable saving browser history
If you disable this policy or don't configure it, browsing history is saved.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SavingBrowserHistoryDisabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Disables saving browser history and prevents users from changing this setting. If you enable this policy, browsing history isn't saved. This also disables tab syncing. If you disable this policy or don't configure it, browsing history is saved.
Disable3DAPIs Disable support for 3D graphics APIs
If you don't configure or disable this policy, it potentially allows web pages to use the WebGL API and plug-ins to use the Pepper 3D API.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- Disable3DAPIs
- Enabled / Disabled
- 1 / 0
- Stated default
- Microsoft Edge might, by default, still require command line arguments to be passed in order to use these APIs.
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Prevent web pages from accessing the graphics processing unit (GPU). Specifically, web pages can't access the WebGL API and plug-ins can't use the Pepper 3D API. If you don't configure or disable this policy, it potentially allows web pages to use the WebGL API and plug-ins to use the Pepper 3D API. Microsoft Edge might, by default, still require command line arguments to be passed in order to use these APIs. If 'HardwareAccelerationModeEnabled' (Use graphics acceleration when available) policy is set to false, the setting for 'Disable3DAPIs' policy is ignored - it's the equivalent of setting 'Disable3DAPIs' policy to true.
SyncDisabled Disable synchronization of data using Microsoft sync services
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SyncDisabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing. This policy disables cloud synchronization only and has no impact on the 'RoamingProfileSupportEnabled' (Enable using roaming copies for Microsoft Edge profile data) policy. If you don't set this policy or apply it as recommended, users can turn on or turn off sync. If you apply this policy as mandatory, users won't be able to turn on sync.
DisableScreenshots Disable taking screenshots
If you disable or don't configure this policy, users can take screenshots.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DisableScreenshots
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Controls if users can take screenshots of the browser page. If you enable this policy, users can't take screenshots using keyboard shortcuts or extension APIs. If you disable or don't configure this policy, users can take screenshots. Note: Even if you disable screenshots using this policy, users might still be able to take screenshots using Web Capture within the browser or other methods outside of the browser. For example, using an operating system feature or another application.
EdgeDiscoverEnabled Discover feature In Microsoft Edge (obsolete)
If you enable or don't configure this policy, you can use the Discover button on Microsoft Edge to start using this feature.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeDiscoverEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 97-105, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 105. This policy doesn't work because Discover is now contained within the Edge Sidebar and can be managed using the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy. This policy lets you configure the Discover feature in Microsoft Edge. Working in the background when enabled, this feature sends URLs to Microsoft Bing to search for related recommendations. If you enable or don't configure this policy, you can use the Discover button on Microsoft Edge to start using this feature. If you disable this policy, you can't use the Discover feature in Microsoft Edge.
InternetExplorerZoomDisplay Display zoom in IE Mode tabs with DPI Scale included like it is in Internet Explorer
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerZoomDisplay
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 103, Windows 7 or later
- Template
- msedge.admx
Lets you display zoom in IE Mode tabs similar to how it was displayed in Internet Explorer, where the DPI scale of the display is factored in. For example, if you have a page zoomed to 200% on a 100 DPI scale display and you change the display to 150 DPI, Microsoft Edge would still display the zoom as 200%. However, Internet Explorer factors in the DPI scale and displays 300%. If you enable this policy, zoom values will be displayed with the DPI scale included for IE Mode tabs. If you disable or don't configure this policy, zoom values will be displayed without DPI scale included for IE Mode tabs
DNSInterceptionChecksEnabled DNS interception checks enabled
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DNSInterceptionChecksEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 80, Windows 7 or later
- Template
- msedge.admx
This policy configures a local switch that can be used to disable DNS interception checks. These checks attempt to discover whether the browser is behind a proxy that redirects unknown host names. This detection might not be necessary in an enterprise environment where the network configuration is known. It can be disabled to avoid additional DNS and HTTP traffic on start-up and each DNS configuration change. If you enable or don't set this policy, the DNS interception checks are performed. If you disable this policy, DNS interception checks aren't performed.
TargetBlankImpliesNoOpener Do not set window.opener for links targeting _blank (obsolete)
If you enable this policy or leave it unset, the window.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- TargetBlankImpliesNoOpener
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 88-102, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 102. If you enable this policy or leave it unset, the window.opener property is set to null unless the anchor specifies rel="opener". If you disable this policy, popups that target _blank are permitted to access (via JavaScript) the page that requested to open the popup.
DoubleClickCloseTabEnabled Double Click feature in Microsoft Edge enabled (only available in China)
If you enable or don't configure this policy, you can use the double click feature to close a tab on Microsoft Edge to start using this feature.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DoubleClickCloseTabEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 104, Windows 7 or later
- Template
- msedge.admx
This policy lets you configure the double click feature in Microsoft Edge. Double Click lets users close a tab by double clicking the left mouse button. If you enable or don't configure this policy, you can use the double click feature to close a tab on Microsoft Edge to start using this feature. If you disable this policy, you can't use the double click feature in Microsoft Edge.
DynamicCodeSettings Dynamic Code Settings
If you set this policy to 0 (the default) or leave unset, then Microsoft Edge uses the default settings.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DynamicCodeSettings
- Supported on
- Microsoft Edge version 128, Windows 7 or later
- Template
- msedge.admx
Microsoft Security BaselineDynamicCodeSettings = 1
0Default dynamic code settings1Prevent the browser process from creating dynamic codeThis policy controls the dynamic code settings for Microsoft Edge. Disabling dynamic code improves the security of Microsoft Edge by preventing potentially hostile dynamic code and third-party code from making changes to Microsoft Edge's behavior. However this might cause compatibility issues with third-party software (for example, certain printer drivers) that must run in the browser process. If you set this policy to 0 (the default) or leave unset, then Microsoft Edge uses the default settings. If you set this policy to 1 – (EnabledForBrowser) then the Microsoft Edge browser process is prevented from creating dynamic code. Policy options mapping: * Default (0) = Default dynamic code settings * EnabledForBrowser (1) = Prevent the browser process from creating dynamic code Use the preceding information when configuring this policy.
Edge3PSerpTelemetryEnabled Edge 3P SERP Telemetry Enabled
If you enable or don't configure this policy, Edge 3P SERP Telemetry feature is enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- Edge3PSerpTelemetryEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 120, Windows 7 or later
- Template
- msedge.admx
Edge3P Telemetry in Microsoft Edge captures the searches that a user does on third-party search providers without identifying the person or the device only if the user has consented to this collection of data. User can turn off the collection at any time in the browser settings. If you enable or don't configure this policy, Edge 3P SERP Telemetry feature is enabled. If you disable this policy, Edge 3P SERP Telemetry feature is disabled.
EdgeWalletEtreeEnabled Edge Wallet E-Tree Enabled (deprecated)
If you enable or don't configure this policy, users can use the Edge Wallet E-Tree feature.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeWalletEtreeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 117, Windows 7 or later
- Template
- msedge.admx
DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. This policy is deprecated because the E-Tree feature has been removed from Microsoft Edge. If you enable or don't configure this policy, users can use the Edge Wallet E-Tree feature. If you disable this policy, users can't use the Edge Wallet E-Tree feature.
TripleDESEnabled Enable 3DES cipher suites in TLS (obsolete)
If the policy is unset, 3DES cipher suites are disabled by default.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- TripleDESEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 93-96, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 96. This policy was removed in version 97 after 3DES was removed from Microsoft Edge. If you enable this policy, then 3DES cipher suites in TLS are enabled. If you disable this policy, then the 3DES cipher suites in TLS are disabled. If the policy is unset, 3DES cipher suites are disabled by default. This policy may be used to temporarily retain compatibility with an outdated server. This is a stopgap measure and the server should be reconfigured.
TLS13HardeningForLocalAnchorsEnabled Enable a TLS 1.3 security feature for local trust anchors (obsolete)
If you enable or don't configure this policy, Microsoft Edge enables these security protections for all connections.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- TLS13HardeningForLocalAnchorsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 81-85, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 85. This policy doesn't work because it was only intended to be a short-term mechanism to give enterprises more time to upgrade affected proxies. This policy controls a security feature in TLS 1.3 that protects connections against downgrade attacks. It's backwards-compatible and doesn't affect connections to compliant TLS 1.2 servers or proxies. However, older versions of some TLS-intercepting proxies have an implementation flaw which causes them to be incompatible. If you enable or don't configure this policy, Microsoft Edge enables these security protections for all connections. If you disable this policy, Microsoft Edge disables these security protections for connections authenticated with locally-installed CA certificates. These protections are always enabled for connections authenticated with publicly-trusted CA certificates. This policy can be used to test for any affected proxies and upgrade them. Affected proxies are expected to fail connections with an error code of ERR_TLS13_DOWNGRADE_DETECTED.
WebAudioOutputBufferingEnabled Enable adaptive buffering for Web Audio
If this policy is disabled or not configured, the browser automatically decides during the feature launch process whether to use adaptive buffering.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebAudioOutputBufferingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 134, Windows 7 or later
- Template
- msedge.admx
This policy determines whether the browser enables adaptive buffering for Web Audio. Adaptive buffering can reduce audio glitches but can increase latency to varying degrees. If this policy is enabled, the browser uses adaptive buffering. If this policy is disabled or not configured, the browser automatically decides during the feature launch process whether to use adaptive buffering.
AdditionalSearchBoxEnabled Enable additional search box in browser
If you enable or don't configure this policy, the search box is visible and available for use.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AdditionalSearchBoxEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 123, Windows 7 or later
- Template
- msedge.admx
A search box is another text input field located next to the address bar in a web browser. It allows users to perform web searches directly from the browser interface. If you enable or don't configure this policy, the search box is visible and available for use. Users can toggle the search box in Microsoft Edge Settings page edge://settings/appearance#SearchBoxInToolbar. If you disable this policy, search box won't be visible, and users have to use the address bar or navigate to a search engine to perform web searches.
AmbientAuthenticationInPrivateModesEnabled Enable Ambient Authentication for InPrivate and Guest profiles
In Microsoft Edge version 81 and later, if you don't configure this policy, ambient authentication is enabled in regular sessions only.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AmbientAuthenticationInPrivateModesEnabled
- Supported on
- Microsoft Edge version 81, Windows 7 or later
- Template
- msedge.admx
0Enable ambient authentication in regular sessions only1Enable ambient authentication in InPrivate and regular sessions2Enable ambient authentication in guest and regular sessions3Enable ambient authentication in regular, InPrivate, and guest sessionsConfigures this policy to allow/disallow ambient authentication for InPrivate and Guest profiles in Microsoft Edge. Ambient Authentication is http authentication with default credentials when explicit credentials aren't provided via New Technology LAN Manager (NTLM)/Kerberos/Negotiate challenge/response schemes. If you set the policy to 'RegularOnly', it allows ambient authentication for Regular sessions only. InPrivate and Guest sessions aren't allowed to ambiently authenticate. If you set the policy to 'InPrivateAndRegular', it allows ambient authentication for InPrivate and Regular sessions. Guest sessions aren't allowed to ambiently authenticate. If you set the policy to 'GuestAndRegular', it allows ambient authentication for Guest and Regular sessions. InPrivate sessions aren't allowed to ambiently authenticate If you set the policy to 'All', it allows ambient authentication for all sessions. Ambient authentication is always allowed on regular profiles. In Microsoft Edge version 81 and later, if you don't configure this policy, ambient authentication is enabled in regular sessions only. Policy options mapping: * RegularOnly (0) = Enable ambient authentication in regular sessions only * InPrivateAndRegular (1) = Enable ambient authentication in InPrivate and regular sessions * GuestAndRegular (2) = Enable ambient authentication in guest and regular sessions * All (3) = Enable ambient authentication in regular, InPrivate, and guest sessions Use the preceding information when configuring this policy.
ApplicationBoundEncryptionEnabled Enable Application Bound Encryption
Enabling this policy or leaving it unset binds the encryption keys used for local data storage to Microsoft Edge whenever possible.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ApplicationBoundEncryptionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 127, Windows 7 or later
- Template
- msedge.admx
Microsoft Security BaselineApplicationBoundEncryptionEnabled = 1
Enabling this policy or leaving it unset binds the encryption keys used for local data storage to Microsoft Edge whenever possible. Disabling this policy has a detrimental effect on Microsoft Edge's security because unknown and potentially hostile apps can retrieve the encryption keys used to secure data. Only turn off this policy if there are compatibility issues, such as scenarios where other applications need legitimate access to Microsoft Edge's data. Encrypted user data is expected to be fully portable between different computers or the integrity and location of Microsoft Edge's executable files isn’t consistent.
AutofillAddressEnabled Enable AutoFill for addresses
If you have enabled or not configured this policy, users manage AutoFill for addresses in Microsoft Edge settings.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AutofillAddressEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enables the AutoFill feature and allows users to autocomplete address information in web forms through previously stored information. If you have enabled or not configured this policy, users manage AutoFill for addresses in Microsoft Edge settings. AutoFill allows users to complete address fields in web forms using previously saved information. If you have disabled this policy, Microsoft Edge doesn't suggest, fill in, or save address information. AutoFill is also disabled for all web forms except payment and password fields, and previously saved addresses aren't available. If you disable this policy, then 'EdgeAutofillMlEnabled' (Machine learning powered autofill suggestions) is turned off. If you disable this policy, all activities for all web forms are stopped, except payment and password forms. No further entries are saved, and Microsoft Edge doesn't suggest or AutoFill any previous entries.
AutofillCreditCardEnabled Enable AutoFill for payment instruments
If you enable this policy or don't configure it, users can control AutoFill for payment instruments.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AutofillCreditCardEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enables Microsoft Edge's AutoFill feature and lets users auto complete payment instruments like credit or debit cards in web forms using previously stored information. Includes suggesting new payment instruments like Buy Now Pay Later (BNPL) in web forms and Express Checkout. If you enable this policy or don't configure it, users can control AutoFill for payment instruments. If you disable this policy, AutoFill never suggests, fills, or recommends new payment Instruments. Additionally, it won't save any payment instrument information that users submit while browsing the web.
HttpsUpgradesEnabled Enable automatic HTTPS upgrades
If this policy is enabled or not configured, automatic HTTPS upgrades are turned on by default.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- HttpsUpgradesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 136, Windows 7 or later
- Template
- msedge.admx
As of Microsoft Edge version 120, Microsoft Edge tries to upgrade HTTP navigations to HTTPS, whenever possible, to improve security. Navigations to captive portals, IP addresses, and nonunique hostnames are excluded from automatic upgrades. If this policy is enabled or not configured, automatic HTTPS upgrades are turned on by default. If this policy is disabled, Microsoft Edge doesn't attempt to upgrade HTTP connections to HTTPS. To exempt specific hostnames or hostname patterns from being upgraded, use the HttpAllowlist policy.
BrowserLegacyExtensionPointsBlockingEnabled Enable browser legacy extension point blocking
If you enable or don't configure this policy, the ProcessExtensionPointDisablePolicy is applied to block legacy extension points in the browser process.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- BrowserLegacyExtensionPointsBlockingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 95, Windows 7 or later
- Template
- msedge.admx
Microsoft Security BaselineBrowserLegacyExtensionPointsBlockingEnabled = 1
Sets the ProcessExtensionPointDisablePolicy on Microsoft Edge's browser process to block code injection from legacy third party applications. If you enable or don't configure this policy, the ProcessExtensionPointDisablePolicy is applied to block legacy extension points in the browser process. If you disable this policy, the ProcessExtensionPointDisablePolicy isn't applied to block legacy extension points in the browser process. This action has a detrimental effect on Microsoft Edge's security and stability as unknown and potentially hostile code can load inside Microsoft Edge's browser process. Only turn off the policy if there are compatibility issues with third-party software that must run inside Microsoft Edge's browser process.
AddressBarClipboardSuggestEnabled Enable clipboard suggestions in the address bar
If you enable this policy or don't configure it, Microsoft Edge may show suggestions based on clipboard content in the address bar suggestion dropdown.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AddressBarClipboardSuggestEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 151, Windows 7 or later
- Template
- msedge.admx
This policy controls whether suggestions based on clipboard content are shown in the address bar suggestion dropdown. If you enable this policy or don't configure it, Microsoft Edge may show suggestions based on clipboard content in the address bar suggestion dropdown. If you disable this policy, Microsoft Edge doesn't show suggestions based on clipboard content in the address bar suggestion dropdown.
ComponentUpdatesEnabled Enable component updates in Microsoft Edge
If you enable or don't configure this policy, component updates are enabled in Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ComponentUpdatesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
If you enable or don't configure this policy, component updates are enabled in Microsoft Edge. If you disable this policy or set it to false, component updates are disabled for all components in Microsoft Edge. However, some components are exempt from this policy. This includes any component that doesn't contain executable code, doesn't significantly alter the behavior of the browser, or that's critical for security. That is, updates that are deemed "critical for security" are still applied even if you disable this policy. Examples of such components include the certificate revocation lists and security lists like tracking prevention lists. Disabling this policy can potentially prevent the Microsoft Edge developers from providing critical security fixes in a timely manner and is thus not recommended.
CopilotAddressBarSuggestionsEnabled Enable Copilot address bar suggestions
If you enable this policy or don't configure it, Copilot chat suggestions appear in the address bar.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- CopilotAddressBarSuggestionsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 149, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Copilot chat suggestions appear in the address bar of Microsoft Edge. If you enable this policy or don't configure it, Copilot chat suggestions appear in the address bar. If you disable this policy, Copilot chat suggestions don't appear in the address bar.
CryptoWalletEnabled Enable CryptoWallet feature (obsolete)
If you enable this policy or don't configure it, users can use CryptoWallet feature that allows users to securely store, manage, and transact digital assets such as Bitcoin, Ethereum, and other cryptocurrencies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- CryptoWalletEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 112-128, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 128. This policy is obsoleted because this feature will no longer be supported, starting in Microsoft Edge 128. There's no replacement for this policy. Enables CryptoWallet feature in Microsoft Edge. If you enable this policy or don't configure it, users can use CryptoWallet feature that allows users to securely store, manage, and transact digital assets such as Bitcoin, Ethereum, and other cryptocurrencies. Therefore, Microsoft Edge may access Microsoft servers to communicate with the web3 world during the use of the CryptoWallet feature. If you disable this policy, users can't use CryptoWallet feature.
AllowDeletingBrowserHistory Enable deleting browser and download history
If you enable this policy or don't configure it, users can delete the browsing and download history.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AllowDeletingBrowserHistory
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enables deleting browser history and download history and prevents users from changing this setting. Even if this policy is disabled, the browsing and download history aren't guaranteed to be retained: users can edit or delete the history database files directly, and the browser itself can remove (based on expiration period) or archive any or all history items at any time. If you enable this policy or don't configure it, users can delete the browsing and download history. If you disable this policy, users can't delete browsing and download history. Disabling this policy disables history sync and open tab sync. If you enable this policy, don't enable the 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) policy, because they both deal with deleting data. If you enable both, the 'ClearBrowsingDataOnExit' policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how this policy is configured.
MutationEventsEnabled Enable deprecated/removed Mutation Events (obsolete)
If you disable or don't configure this policy, these events won't be fired.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- MutationEventsEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- If you enable this policy, mutation events continue to be fired, even if they've been disabled by default for normal web users.
- Supported on
- Microsoft Edge version 124-136, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 136. This policy provides a temporary opt-in back to a deprecated and removed set of platform events named Mutation Events. If you enable this policy, mutation events continue to be fired, even if they've been disabled by default for normal web users. If you disable or don't configure this policy, these events won't be fired. Note: This policy is a temporary workaround and will be obsolete starting with Microsoft Edge version 137.
DiscoverPageContextEnabled Enable Discover access to page contents for AAD profiles (obsolete)
If you enable or don't configure this policy, Discover has access to page contents.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DiscoverPageContextEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 113-127, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 127. This policy is obsolete as of Microsoft Edge version 127. Two new Microsoft Edge Policies took its place. Those policies are CopilotPageContext (Control Copilot access to page contents for AAD profiles) and CopilotCDPPageContext (Control Copilot with Commercial Data Protection access to page contents for AAD profiles). This policy didn't allow for separate control of Copilot and Copilot with Commercial Data Protection. The new policies allow separate control of these versions of Copilot. The new policies also allow admins to force-enable Copilot access to Microsoft Edge page contents by enabling the policy, whereas DiscoverPageContextEnabled only allows force-disabling of Copilot page access. This policy controls Discover access to page contents for AAD profiles. Discover is an extension that hosts Bing Chat. To summarize pages and interact with text selections, it must access the page contents. When enabled, page contents are sent to Bing. This policy doesn't affect MSA profiles. If you enable or don't configure this policy, Discover has access to page contents. If you disable this policy, Discover can't access page contents.
EnableDomainActionsDownload Enable Domain Actions Download from Microsoft (obsolete)
If you don't configure this policy, the list of Domain Actions continues to be downloaded from the Experimentation and Configuration Service.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EnableDomainActionsDownload
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77-84, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 84. This policy doesn't work because conflicting states should be avoided. This policy was used to enable/disable download of the domain actions list, but it didn't always achieve the desired state. The Experimentation and Configuration Service, which handles the download, has its own policy to configure what's downloaded from the service. Use the 'ExperimentationAndConfigurationServiceControl' (Control communication with the Experimentation and Configuration Service) policy instead. In Microsoft Edge, Domain Actions represent a series of compatibility features that help the browser work correctly on the web. Microsoft keeps a list of actions to take on certain domains for compatibility reasons. For example, the browser may override the User Agent string on a website if that website is broken due to the new User Agent string on Microsoft Edge. Each of these actions is intended to be temporary while Microsoft tries to resolve the issue with the site owner. When the browser starts up and then periodically afterwards, the browser will contact the Experimentation and Configuration Service that contains the most up to date list of compatibility actions to perform. This list is saved locally after it's first retrieved so that subsequent requests will only update the list if the server's copy has changed. If you enable this policy, the list of Domain Actions continues to be downloaded from the Experimentation and Configuration Service. If you disable this policy, the list of Domain Actions will no longer be downloaded from the Experimentation and Configuration Service. If you don't configure this policy, the list of Domain Actions continues to be downloaded from the Experimentation and Configuration Service.
EdgeEDropEnabled Enable Drop feature in Microsoft Edge
If you enable or don't configure this policy, you can use the Drop feature in Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeEDropEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 104, Windows 7 or later
- Template
- msedge.admx
This policy lets you configure the Drop feature in Microsoft Edge. Drop lets users send messages or files to themselves. If you enable or don't configure this policy, you can use the Drop feature in Microsoft Edge. If you disable this policy, you can't use the Drop feature in Microsoft Edge.
TaskManagerEndProcessEnabled Enable ending processes in the Browser task manager
If you enable or don't configure this policy, users can end processes in the Browser task manager.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- TaskManagerEndProcessEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
If you enable or don't configure this policy, users can end processes in the Browser task manager. If you disable it, users can't end processes, and the End process button is disabled in the Browser task manager.
FavoritesBarEnabled Enable favorites bar
If this policy is not configured, then the user can decide to use the favorites bar or not.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- FavoritesBarEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enables or disables the favorites bar. If you enable this policy, users will see the favorites bar. If you disable this policy, users won't see the favorites bar. If this policy is not configured, then the user can decide to use the favorites bar or not.
EdgeFollowEnabled Enable Follow service in Microsoft Edge (obsolete)
If you enable or don't configure this policy, Follow in Microsoft Edge is applied.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeFollowEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 98-126, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 126. Lets Microsoft Edge browser enable Follow service and apply it to users. Users can use the Follow feature for an influencer, site, or topic in Microsoft Edge. If you enable or don't configure this policy, Follow in Microsoft Edge is applied. If you disable this policy, Microsoft Edge won't communicate with Follow service to provide the follow feature. This policy is obsolete after version 126.
PromotionalTabsEnabled Enable full-tab promotional content (deprecated)
If you enable this policy (set it true) or don't configure it, Microsoft Edge can show full-tab content to users to provide product information.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PromotionalTabsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. Control the presentation of full-tab promotional or educational content. This setting controls the presentation of welcome pages that help users sign into Microsoft Edge, choose their default browser, or learn about product features. If you enable this policy (set it true) or don't configure it, Microsoft Edge can show full-tab content to users to provide product information. If you disable (set to false) this policy, Microsoft Edge can't show full-tab content to users. This is deprecated - use ShowRecommendationsEnabled instead.
GloballyScopeHTTPAuthCacheEnabled Enable globally scoped HTTP auth cache
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- GloballyScopeHTTPAuthCacheEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 81, Windows 7 or later
- Template
- msedge.admx
This policy configures a single global per profile cache with HTTP server authentication credentials. If you disable or don't set this policy, the browser uses the default behavior of cross-site auth. This behavior is to scope HTTP server authentication credentials by top-level site. So, if two sites use resources from the same authenticating domain, credentials need to be provided independently in the context of both sites. Cached proxy credentials are reused across sites. If you enable this policy, HTTP auth credentials entered in the context of one site is automatically used in the context of another site. Enabling this policy leaves sites open to some types of cross-site attacks, and allows users to be tracked across sites even without cookies by adding entries to the HTTP auth cache using credentials embedded in URLs. This policy is intended to give enterprises depending on the legacy behavior a chance to update their login procedures and will be removed in the future.
BrowserGuestModeEnabled Enable guest mode
If you enable this policy or don't configure it, Microsoft Edge lets users browse in guest profiles.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- BrowserGuestModeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enable the option to allow the use of guest profiles in Microsoft Edge. In a guest profile, the browser doesn't import browsing data from existing profiles, and it deletes browsing data when all guest profiles are closed. If you enable this policy or don't configure it, Microsoft Edge lets users browse in guest profiles. If you disable this policy, Microsoft Edge doesn't let users browse in guest profiles.
KeyboardFocusableScrollersEnabled Enable keyboard focusable scrollers (obsolete)
When this policy is Enabled or unset, scrollers without focusable children are keyboard focusable by default.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- KeyboardFocusableScrollersEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- When this policy is Enabled or unset, scrollers without focusable children are keyboard focusable by default. When this policy is Disabled, scrollers aren't keyboard focusable by default.
- Supported on
- Microsoft Edge version 128-138, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 138. This policy provides a temporary opt-out for the new keyboard focusable scrollers behavior. When this policy is Enabled or unset, scrollers without focusable children are keyboard focusable by default. When this policy is Disabled, scrollers aren't keyboard focusable by default. This policy is a temporary workaround. Starting in Microsoft Edge version 139, this policy is obsolete.
AddressBarTrendingSuggestEnabled Enable Microsoft Bing trending suggestions in the address bar
If this policy is enabled or not configured, Microsoft Bing trending suggestions appear in the address bar suggestion dropdown.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AddressBarTrendingSuggestEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 135, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Microsoft Bing trending suggestions appear in the address bar’s suggestion dropdown when users select the address bar while on a New Tab Page. If this policy is enabled or not configured, Microsoft Bing trending suggestions appear in the address bar suggestion dropdown. If this policy is disabled, Microsoft Edge doesn't display Microsoft Bing trending suggestions when users select the address bar.
AddressBarMicrosoftSearchInBingProviderEnabled Enable Microsoft Search in Bing suggestions in the address bar (obsolete)
If you enable or don't configure this policy, users can see internal results powered by Microsoft Search in Bing in the Microsoft Edge address bar suggestion list.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AddressBarMicrosoftSearchInBingProviderEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 81-136, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 136. Enables the display of relevant Microsoft Search in Bing suggestions in the address bar's suggestion list when the user enters a search query in the address bar. If you enable or don't configure this policy, users can see internal results powered by Microsoft Search in Bing in the Microsoft Edge address bar suggestion list. To access Microsoft Search in Bing results, the user must be signed in to Microsoft Edge with their organization's Azure AD account. If you disable this policy, users won't see internal results in the Microsoft Edge address bar suggestion list. Starting with Microsoft Edge version 89, Microsoft Search in Bing suggestions will be available even if Bing isn't the user's default search provider. This policy is no longer applicable due to changes in access to work search through Bing-related endpoints.
NativeWindowOcclusionEnabled Enable Native Window Occlusion (deprecated)
If you don't configure this policy, occlusion detection is enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NativeWindowOcclusionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 84, Windows 7 or later
- Template
- msedge.admx
DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. This policy is deprecated, use the ''WindowOcclusionEnabled' (Enable Window Occlusion)' policy instead. It won't work in Microsoft Edge version 92. Enables native window occlusion in Microsoft Edge. If you enable this policy, to reduce CPU and power consumption Microsoft Edge detects when a window is covered by other windows, and will suspend work painting pixels. If you disable this policy Microsoft Edge won't detect when a window is covered by other windows. If you don't configure this policy, occlusion detection is enabled.
NetworkPredictionOptions Enable network prediction
If you don't configure this policy, network prediction is enabled but the user can change it.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NetworkPredictionOptions
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
0Predict network actions on any network connection1Not supported, if this value is used it will be treated as if 'Predict network actions on any network connection' (0) was set2Don't predict network actions on any network connectionEnables network prediction and prevents users from changing this setting. This controls DNS prefetching, TCP and SSL preconnection, and prerendering of web pages. If you don't configure this policy, network prediction is enabled but the user can change it. Policy options mapping: * NetworkPredictionAlways (0) = Predict network actions on any network connection * NetworkPredictionWifiOnly (1) = Not supported, if this value is used it will be treated as if 'Predict network actions on any network connection' (0) was set * NetworkPredictionNever (2) = Don't predict network actions on any network connection Use the preceding information when configuring this policy.
EnableOnlineRevocationChecks Enable online OCSP/CRL checks
If you disable the policy or don't configure it, Microsoft Edge can't perform online revocation checks.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EnableOnlineRevocationChecks
- Enabled / Disabled
- 1 / 0
- Stated default
- Online revocation checks don't provide a significant security benefit and are disabled by default.
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Online revocation checks don't provide a significant security benefit and are disabled by default. If you enable this policy, Microsoft Edge performs soft-fail, online OCSP/CRL checks. "Soft fail" means that if the revocation server can't be reached, the certificate is considered valid. If you disable the policy or don't configure it, Microsoft Edge can't perform online revocation checks.
DataUrlInWebWorkerOpaqueOriginEnabled Enable opaque origins for data URLs in Web Workers
If you enable this policy or don't configure it, Web Workers created from data URLs are assigned a unique opaque origin.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DataUrlInWebWorkerOpaqueOriginEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- Starting in Microsoft Edge version 149, Web Workers created from data URLs are assigned a unique opaque origin by default.
- Supported on
- Microsoft Edge version 149, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Web Workers created from data URLs are assigned a unique opaque origin. Web Workers can be created using a data URL that contains the worker script. Previously, these workers inherited the origin of the page that created them, which allowed them to access the same origin-bound data, such as local storage and cookies. Starting in Microsoft Edge version 149, Web Workers created from data URLs are assigned a unique opaque origin by default. This behavior improves security and aligns with the HTML specification by isolating these workers from the page that created them. If you enable this policy or don't configure it, Web Workers created from data URLs are assigned a unique opaque origin. If you disable this policy, Web Workers created from data URLs inherit the origin of the page that created them. Use this setting only as a temporary mitigation for compatibility issues with internal applications that depend on the legacy behavior. This policy is temporary and will be removed in Microsoft Edge version 157.
EdgeOpenInSidebarEnabled Enable open in sidebar
If you enable or don't configure this policy, users can access the feature.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeOpenInSidebarEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 122, Windows 7 or later
- Template
- msedge.admx
Allow/Disallow user open a website or an app to the sidebar. If you enable or don't configure this policy, users can access the feature. If you disable this policy, users won't be able to access the feature.
ForceMajorVersionToMinorPositionInUserAgent Enable or disable freezing the User-Agent string at major version 99 (obsolete)
If you set this policy to 'Default' or don't configure it, then it defaults to browser settings for the User-Agent string major version.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ForceMajorVersionToMinorPositionInUserAgent
- Supported on
- Microsoft Edge version 99-117, Windows 7 or later
- Template
- msedge.admx
0Default to browser settings for User-Agent string version.1The User-Agent string won't freeze the major version.2The User-Agent string will freeze the major version as 99 and include the browser's major version in the minor position.OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 117. This policy was removed in Microsoft Edge 118 and is ignored if configured. This policy controls whether the User-Agent string major version should be frozen at 99. The User-Agent request header lets websites identify the application, operating system, vendor, and/or version of the requesting user agent. Some websites make assumptions about how this header is formatted and may encounter issues with version strings that include three digits in the major position (for example, 100.0.0.0). If you set this policy to 'Default' or don't configure it, then it defaults to browser settings for the User-Agent string major version. If you set this policy to 'ForceEnabled', the User-Agent string will always report the major version as 99 and include the browser's major version in the minor position. For example, browser version 101.0.0.0 would send a User-Agent request header that reports version 99.101.0.0. If you set this policy to 'ForceDisabled', the User-Agent string won't freeze the major version. This policy is temporary and will be deprecated in the future. If this policy and User-Agent Reduction are both enabled, the User-Agent version string will always be 99.0.0.0. Policy options mapping: * Default (0) = Default to browser settings for User-Agent string version. * ForceDisabled (1) = The User-Agent string won't freeze the major version. * ForceEnabled (2) = The User-Agent string will freeze the major version as 99 and include the browser's major version in the minor position. Use the preceding information when configuring this policy.
UserAgentReduction Enable or disable the User-Agent Reduction (obsolete)
dev/articles/migrate-to-ua-ch If you don't configure this policy or set it to Default, the User-Agent header will be reduced and controlled by experimentation.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- UserAgentReduction
- Stated default
- The User-Agent HTTP request header has been reduced by default since Microsoft Edge version 119.
- Supported on
- Microsoft Edge version 99-144, Windows 7 or later
- Template
- msedge.admx
0Reduced User Agent, or controlled by experimentation.1Full (legacy) User Agent.2Reduced User Agent.OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 144. The User-Agent HTTP request header has been reduced by default since Microsoft Edge version 119. To continue receiving detailed platform information, migrate to User-Agent Client Hints, which replace the deprecated detailed User-Agent header. For more information, visit: https://web.dev/articles/migrate-to-ua-ch If you don't configure this policy or set it to Default, the User-Agent header will be reduced and controlled by experimentation. Set this policy to 'ForceEnabled' to force the reduced version of the User-Agent request header for all origins. Set this policy to 'ForceDisabled' to always use the full (legacy) User-Agent header. To learn more about the User-Agent string, read here: https://go.microsoft.com/fwlink/?linkid=2186267 Policy options mapping: * Default (0) = Reduced User Agent, or controlled by experimentation. * ForceDisabled (1) = Full (legacy) User Agent. * ForceEnabled (2) = Reduced User Agent. Use the preceding information when configuring this policy.
PictureInPictureOverlayEnabled Enable Picture in Picture overlay feature on supported webpages in Microsoft Edge
If you enable or don't configure this policy, you can use the Picture in Picture floating overlay button in Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PictureInPictureOverlayEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 118, Windows 7 or later
- Template
- msedge.admx
This policy lets you configure the Picture in Picture floating overlay button in Microsoft Edge. The Picture in Picture floating overlay button lets the user watch videos in a floating window on top of other windows. If you enable or don't configure this policy, you can use the Picture in Picture floating overlay button in Microsoft Edge. If you disable this policy, you can't use the Picture in Picture floating overlay button in Microsoft Edge.
PostQuantumKeyAgreementEnabled Enable post-quantum key agreement for TLS (obsolete)
If you enable or don't configure this policy, Microsoft Edge offers a post-quantum key agreement in TLS connections.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PostQuantumKeyAgreementEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- Post-quantum key agreement is now enabled by default and cannot be disabled.
- Supported on
- Microsoft Edge version 120-146, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 146. This policy configures whether Microsoft Edge offers a post-quantum key agreement algorithm in TLS. This lets supporting servers protect user traffic from being decrypted by quantum computers. If you enable or don't configure this policy, Microsoft Edge offers a post-quantum key agreement in TLS connections. TLS connections are protected from quantum computers when communicating with compatible servers. If you disable this policy, Microsoft Edge won't offer a post-quantum key agreement in TLS connections. User traffic is unprotected from decryption by quantum computers. Offering a post-quantum key agreement is backwards-compatible. Existing TLS servers and networking middleware are expected to ignore the new option and continue selecting previous options. However, devices that don't implement TLS correctly may malfunction when offered the new option. For example, they might disconnect in response to unrecognized options or the resulting larger messages. These devices aren't post-quantum-ready and will interfere with an enterprise's post-quantum transition. If this issue is encountered, administrators should contact the vendor for a fix. This policy has been removed starting in Microsoft Edge version 147. Post-quantum key agreement is now enabled by default and cannot be disabled. Enterprises should work with device vendors to obtain fixes for proper post-quantum support.
ProactiveAuthEnabled Enable Proactive Authentication (obsolete)
If you don't configure this policy, Proactive Authentication is turned on.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ProactiveAuthEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77-90, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 90. This policy is obsolete because it doesn't work independently of browser sign in. It doesn't work in Microsoft Edge after version 90. If you want to configure browser sign in, use the 'BrowserSignin' (Browser sign-in settings) policy. Lets you configure whether to turn on Proactive Authentication in Microsoft Edge. If you enable this policy, Microsoft Edge tries to seamlessly authenticate to websites and services using the account which is signed-in to the browser. If you disable this policy, Microsoft Edge doesn't try to authenticate with websites or services using single sign-on (SSO). Authenticated experiences like the Enterprise New Tab Page won't work (for example, recent and recommended Office documents will not be available). If you don't configure this policy, Proactive Authentication is turned on.
ProcessIsolationEnabled Enable Process Isolation
If this policy is unset, Microsoft Edge will follow the default rollout process for the Process Isolation feature, which means that the feature will be gradually rolled out to an increasing number of users.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ProcessIsolationEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 151, Windows 7 or later
- Template
- msedge.admx
This policy controls Process Isolation in Microsoft Edge. When this policy is enabled, Microsoft Edge uses Process Isolation to help improve browser security by preventing authorized applications on the device from reading or modifying the contents of Microsoft Edge's running processes. This also helps prevent other applications from accessing encrypted data used by Microsoft Edge. Enabling Process Isolation may cause incompatibilities with third party applications that rely on being able to inject or tamper with Microsoft Edge's processes, such as antivirus, screen reader or window manager applications. Setting the policy to Enabled turns on process isolation in Microsoft Edge. Setting the policy to Disabled turns off process isolation in Microsoft Edge. If this policy is unset, Microsoft Edge will follow the default rollout process for the Process Isolation feature, which means that the feature will be gradually rolled out to an increasing number of users. Note: This policy is applied when Microsoft Edge starts. If the policy is changed while Microsoft Edge is running, the new setting will take effect on the next restart.
BrowserAddProfileEnabled Enable profile creation from the Identity flyout menu or the Settings page
If you enable this policy or don't configure it, Microsoft Edge allows users to use **Add profile** on the Identity flyout menu or the Settings page to create new profiles.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- BrowserAddProfileEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows users to create new profiles, using the **Add profile** option. If you enable this policy or don't configure it, Microsoft Edge allows users to use **Add profile** on the Identity flyout menu or the Settings page to create new profiles. If you disable this policy, users cannot add new profiles from the Identity flyout menu or the Settings page.
QRCodeGeneratorEnabled Enable QR Code Generator
If you enable this policy or don't configure it, the QR Code Generator feature is enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- QRCodeGeneratorEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 125, Windows 7 or later
- Template
- msedge.admx
This policy enables the QR Code generator feature in Microsoft Edge. If you enable this policy or don't configure it, the QR Code Generator feature is enabled. If you disable this policy, the QR Code Generator feature is disabled.
ReadAloudEnabled Enable Read Aloud feature in Microsoft Edge
If you enable this policy or don't configure it, the Read Aloud option shows up in the address bar, right click context menu, more menu, on the PDF toolbar, and within Immersive Reader.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ReadAloudEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 113, Windows 7 or later
- Template
- msedge.admx
Enables the Read Aloud feature within Microsoft Edge. With this feature, users can listen to the content on the web page. This feature enables users to multi-task or improve their reading comprehension by hearing content at their own pace. If you enable this policy or don't configure it, the Read Aloud option shows up in the address bar, right click context menu, more menu, on the PDF toolbar, and within Immersive Reader. If you disable this policy, users can't access the Read Aloud feature from the address bar, right click context menu, more menu, on the PDF toolbar, and within Immersive Reader.
RendererCodeIntegrityEnabled Enable renderer code integrity (obsolete)
Setting the policy to Enabled or leaving it unset turns on Renderer Code Integrity.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RendererCodeIntegrityEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 78-118, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 118. Setting the policy to Enabled or leaving it unset turns on Renderer Code Integrity. Setting the policy to Disabled has a detrimental effect on Microsoft Edge's security and stability as unknown and potentially hostile code can load inside Microsoft Edge's renderer processes. Only turn off the policy if there are compatibility issues with third-party software that must run inside Microsoft Edge's renderer processes. This policy is removed in Microsoft Edge version 119 and is ignored if set.
RendererAppContainerEnabled Enable renderer in app container
If you don't configure this policy, Microsoft Edge launches the renderer process in an app container in a future update.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RendererAppContainerEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 96, Windows 7 or later
- Template
- msedge.admx
Launches Renderer processes into an App Container for more security benefits. If you don't configure this policy, Microsoft Edge launches the renderer process in an app container in a future update. If you enable this policy, Microsoft Edge launches the renderer process in an app container. If you disable this policy, Microsoft Edge won't launch the renderer process in an app container. Only turn off the policy if there are compatibility issues with third-party software that must run inside Microsoft Edge's renderer processes. This policy will only take effect on Windows 10 RS5 and above.
ResolveNavigationErrorsUseWebService Enable resolution of navigation errors using a web service
If you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ResolveNavigationErrorsUseWebService
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allow Microsoft Edge to issue a dataless connection to a web service to probe networks for connectivity in cases like hotel and airport Wi-Fi. If you enable this policy, a web service is used for network connectivity tests. If you disable this policy, Microsoft Edge uses native APIs to try to resolve network connectivity and navigation issues. **Note**: Except on Windows 8 and later versions of Windows, Microsoft Edge *always* uses native APIs to resolve connectivity issues. If you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy. Specifically, there's a **Use a web service to help resolve navigation errors** toggle, which the user can switch on or off. Be aware that if you have enabled this policy (ResolveNavigationErrorsUseWebService), the **Use a web service to help resolve navigation errors** setting is turned on, but the user can't change the setting by using the toggle. If you have disabled this policy, the **Use a web service to help resolve navigation errors** setting is turned off, and the user can't change the setting by using the toggle.
ScrollToTextFragmentEnabled Enable scrolling to text specified in URL fragments
If you enable or don't configure this policy, web page scrolling to specific text fragments via a URL is enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ScrollToTextFragmentEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 83, Windows 7 or later
- Template
- msedge.admx
This feature lets hyperlink and address bar URL navigations target specific text on a web page, which will be scrolled to after the web page finishes loading. If you enable or don't configure this policy, web page scrolling to specific text fragments via a URL is enabled. If you disable this policy, web page scrolling to specific text fragments via a URL is disabled.
SearchSuggestEnabled Enable search suggestions
If this policy is left not set, search suggestions are enabled but the user can change that.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SearchSuggestEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enables web search suggestions in Microsoft Edge's Address Bar and Auto-Suggest List and prevents users from changing this policy. If you enable this policy, web search suggestions are used. If you disable this policy, web search suggestions are never used, however local history and local favorites suggestions still appear. If you disable this policy, neither the typed characters, nor the URLs visited will be included in telemetry to Microsoft. If this policy is left not set, search suggestions are enabled but the user can change that.
CommandLineFlagSecurityWarningsEnabled Enable security warnings for command-line flags
If enabled or unset, security warnings are displayed when these command-line flags are used to launch Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- CommandLineFlagSecurityWarningsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 78, Windows 7 or later
- Template
- msedge.admx
If disabled, this policy prevents security warnings from appearing when Microsoft Edge is launched with potentially dangerous command-line flags. If enabled or unset, security warnings are displayed when these command-line flags are used to launch Microsoft Edge. For example, the --disable-gpu-sandbox flag generates this warning: You're using an unsupported command-line flag: --disable-gpu-sandbox. This poses stability and security risks. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.
EdgeReadingModeServiceBasedExtractionEnabled Enable service-based extraction for Reading Mode in Microsoft Edge
If you enable or don't configure this policy, Microsoft Edge can send the text of the page being read to the service for processing.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeReadingModeServiceBasedExtractionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 151, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Microsoft Edge can use the Microsoft online extraction service to improve Reading Mode rendering. If you enable or don't configure this policy, Microsoft Edge can send the text of the page being read to the service for processing. If you disable this policy, Microsoft Edge doesn't send the text of the page being read to the service. Reading Mode remains available, but extraction quality may be limited.
EdgeSidebarCustomizeEnabled Enable sidebar customize
If you enable or don't configure this policy, users can access sidebar customize.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeSidebarCustomizeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 122, Windows 7 or later
- Template
- msedge.admx
Allow/Disallow to use sidebar customize. If you enable or don't configure this policy, users can access sidebar customize. If you disable this policy, users won't be able to access the sidebar customize.
SignedHTTPExchangeEnabled Enable Signed HTTP Exchange (SXG) support
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SignedHTTPExchangeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 78, Windows 7 or later
- Template
- msedge.admx
Enable support for Signed HTTP Exchange (SXG). If this policy isn't set or enabled, Microsoft Edge accepts web contents served as Signed HTTP Exchanges. If this policy is set to disabled, Signed HTTP Exchanges can't be loaded.
SilentPrintingEnabled Enable Silent Printing
If you disable or don't configure this policy, silent printing is disabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SilentPrintingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 144, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Microsoft Edge uses silent printing. If you enable this policy, Edge automatically closes the print preview window and prints to the default printer using its default settings. If the default printer is Save as PDF, the file is saved to the user's Downloads folder. If you disable or don't configure this policy, silent printing is disabled. The print preview window stays open and the user must choose print settings as usual.
SitePerProcess Enable site isolation for every site
If you disable or don't configure this policy, a user can opt out of site isolation.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SitePerProcess
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Microsoft Security BaselineSitePerProcess = 1
The 'SitePerProcess' policy can be used to prevent users from opting out of the default behavior of isolating all sites. You can also use the 'IsolateOrigins' (Enable site isolation for specific origins) policy to isolate additional, finer-grained origins. If you enable this policy, users can't opt out of the default behavior where each site runs in its own process. If you disable or don't configure this policy, a user can opt out of site isolation. (For example, by using "Disable site isolation" entry in edge://flags.) Disabling the policy or not configuring the policy doesn't turn off Site Isolation.
IsolateOrigins Enable site isolation for specific origins
If you disable or don't configure this policy, pages are isolated on a per-Site basis.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- IsolateOrigins
- Stated default
- By default, Microsoft Edge isolates pages from each Site into its own process.
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specify origins to run in an isolated process. By default, Microsoft Edge isolates pages from each Site into its own process. This policy enables more granular isolation based on Origin rather than Site. For example, specifying https://subdomain.contoso.com/ causes pages from https://subdomain.contoso.com/ to be isolated in a different process than pages from other Origins within the https://contoso.com/ Site. If you enable this policy, each of the named origins in a comma-separated list runs in its own process. If you disable or don't configure this policy, pages are isolated on a per-Site basis. Example value: https://contoso.com/,https://fabrikam.com/
SpellcheckLanguage Enable specific spellcheck languages
If you don't configure or disable this policy, there's no change to the user's spellcheck preferences.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\SpellcheckLanguage
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enables different languages for spellcheck. Any language that you specify that isn't recognized is ignored. If you enable this policy, spellcheck is enabled for the languages specified, and any languages the user enabled. If you don't configure or disable this policy, there's no change to the user's spellcheck preferences. If the 'SpellcheckEnabled' (Enable spellcheck) policy is disabled, this policy has no effect. If a language is included in both the 'SpellcheckLanguage' and the 'SpellcheckLanguageBlocklist' (Force disable spellcheck languages) policy, the spellcheck language is enabled. Example value: fr es
SpellcheckEnabled Enable spellcheck
If you enable or don't configure this policy, the user can use spellcheck.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SpellcheckEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
If you enable or don't configure this policy, the user can use spellcheck. If you disable this policy, the user can't use spellcheck and the 'SpellcheckLanguage' (Enable specific spellcheck languages) and 'SpellcheckLanguageBlocklist' (Force disable spellcheck languages) policies are also disabled.
SplitScreenEnabled Enable split screen feature in Microsoft Edge
If you enable or don't configure this policy, users can use the split screen feature in Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SplitScreenEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 117, Windows 7 or later
- Template
- msedge.admx
This policy lets you configure the split screen feature in Microsoft Edge. This feature lets a user open two web pages in one tab. If you enable or don't configure this policy, users can use the split screen feature in Microsoft Edge. If you disable this policy, users can't use the split screen feature in Microsoft Edge.
StandardizedBrowserZoomEnabled Enable Standardized Browser Zoom Behavior
When this policy is enabled or not configured, the CSS "zoom" property follows the current specification defined by the CSS Working Group: https://drafts.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- StandardizedBrowserZoomEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- In a future Microsoft Edge release, this policy will be removed and the standardized behavior will be enforced by default.
- Supported on
- Microsoft Edge version 146, Windows 7 or later
- Template
- msedge.admx
Configures whether the CSS "zoom" property follows the current CSS specification or legacy behavior. When this policy is enabled or not configured, the CSS "zoom" property follows the current specification defined by the CSS Working Group: https://drafts.csswg.org/css-viewport/#zoom-property When this policy is disabled, the CSS "zoom" property uses its legacy, pre-standardized behavior. This policy is temporary and is intended to provide time for organizations to migrate web content to the updated behavior. In a future Microsoft Edge release, this policy will be removed and the standardized behavior will be enforced by default.
StrictMimetypeCheckForWorkerScriptsEnabled Enable strict MIME type checking for worker scripts
If you enable or don't configure this policy, worker scripts use strict MIME type checking for JavaScript.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- StrictMimetypeCheckForWorkerScriptsEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- Microsoft Edge uses strict MIME type checking by default.
- Supported on
- Microsoft Edge version 150, Windows 7 or later
- Template
- msedge.admx
This policy controls whether strict MIME type checking is used for worker scripts. If you enable or don't configure this policy, worker scripts use strict MIME type checking for JavaScript. Worker scripts that use legacy MIME types are rejected. If you disable this policy, worker scripts use lax MIME type checking. This allows worker scripts that use legacy MIME types, such as text/ascii, to continue to load and run. Browsers traditionally used lax MIME type checking, which allowed JavaScript resources to load with several legacy MIME types. This behavior can create security risks by allowing resources to load as scripts when they weren't intended to be used that way. Microsoft Edge uses strict MIME type checking by default. Enabling this policy follows the default behavior. Disabling this policy lets admins temporarily retain the legacy behavior for compatibility. For more information about JavaScript and ECMAScript media types, see https://html.spec.whatwg.org/multipage/scripting.html#scriptingLanguage.
StricterMixedContentTreatmentEnabled Enable stricter treatment for mixed content (obsolete)
If you set this policy to true or not set, audio and video mixed content is automatically upgraded to HTTPS (that is, the URL will be rewritten as HTTPS, without a fallback if the resource isn't available over HTTPS), and a 'Not Secure' warning is shown in the URL bar for image mixed content.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- StricterMixedContentTreatmentEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 81-84, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 84. This policy doesn't work because it was only intended to be a short-term mechanism to give enterprises more time to update their web content if it was found to be incompatible with stricter mixed content treatment. This policy controls the treatment for mixed content (HTTP content in HTTPS sites) in the browser. If you set this policy to true or not set, audio and video mixed content is automatically upgraded to HTTPS (that is, the URL will be rewritten as HTTPS, without a fallback if the resource isn't available over HTTPS), and a 'Not Secure' warning is shown in the URL bar for image mixed content. If you set the policy to false, auto upgrades are disabled for audio and video, and no warning is shown for images. This policy doesn't affect other types of mixed content other than audio, video, and images.
WebRtcRespectOsRoutingTableEnabled Enable support for Windows OS routing table rules when making peer to peer connections via WebRTC
If you disable this policy or don't configure it, WebRTC won't consider the routing table and may make peer to peer connections over any available network.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebRtcRespectOsRoutingTableEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 94, Windows 7 or later
- Template
- msedge.admx
Controls whether WebRTC respects the Windows OS routing table rules when making peer-to-peer connections, thus enabling split tunnel VPNs. If you disable this policy or don't configure it, WebRTC won't consider the routing table and may make peer to peer connections over any available network. If you enable this policy, WebRTC will prefer to make peer to peer connections using the indicated network interface for the remote address as indicated in the routing table. This policy is only available on Windows.
TabServicesEnabled Enable tab organization suggestions
If you enable or don't configure this policy, when a user creates a tab group or activates certain "Group Similar Tabs" features Microsoft Edge sends tab data to its tab organization service.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- TabServicesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 113, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Microsoft Edge can use its tab organization service to help name or suggest tab groups to increase productivity. If you enable or don't configure this policy, when a user creates a tab group or activates certain "Group Similar Tabs" features Microsoft Edge sends tab data to its tab organization service. This data includes URLs, page titles, and existing group information. The service uses this data to return suggestions for better groupings and group names. If you disable this policy, no data is sent to the tab organization service. Microsoft Edge can't suggest group names when a group is created and certain "Group Similar Tabs" features that rely on the service aren't available.
ShowTabPreviewEnabled Enable tab preview on hover
If you enable or don't configure this policy, Microsoft Edge shows a tab preview when the user hovers over a tab.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ShowTabPreviewEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 141, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Microsoft Edge displays a preview of the tab content when the user hovers over a tab. If you enable or don't configure this policy, Microsoft Edge shows a tab preview when the user hovers over a tab. If you disable this policy, tab previews aren't shown on hover.
EdgeCollectionsEnabled Enable the Collections feature
If you enable or don't configure this policy, users can access and use the Collections feature in Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeCollectionsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 78, Windows 7 or later
- Template
- msedge.admx
Lets you allow users to access the Collections feature, where they can collect, organize, share, and export content more efficiently and with Office integration. If you enable or don't configure this policy, users can access and use the Collections feature in Microsoft Edge. If you disable this policy, users can't access and use Collections in Microsoft Edge.
CopilotNewTabPageEnabled Enable the Copilot new tab page
If you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy is not configured, users can turn it on via user settings.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- CopilotNewTabPageEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 148, Windows 7 or later
- Template
- msedge.admx
This policy configures the availability of the Copilot new tab page in Microsoft Edge for Business. The Copilot new tab page combines search and chat into a single input box and includes personalized cards that provide quick access to relevant files, calendar events, and suggested Copilot prompts. Users who do not have a Microsoft 365 Copilot license might experience limited relevance in Copilot prompt card content. Most policies that customize the New Tab Page are supported on the Copilot new tab page. For a complete list of supported and unsupported policies, see https://go.microsoft.com/fwlink/?linkid=2330462. This policy applies only to Microsoft Entra ID profiles and controls the Copilot new tab page experience in Microsoft Edge for Business. This policy does not apply to the Copilot new tab page on MSA profiles. If you enable this policy, the Copilot new tab page is turned on. If you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy is not configured, users can turn it on via user settings.
SharedWorkerExtendedLifetimeEnabled Enable the extended lifetime option for SharedWorkers
If you enable or don't configure this policy, SharedWorkers can use the extended lifetime option in the SharedWorker constructor.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SharedWorkerExtendedLifetimeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 148, Windows 7 or later
- Template
- msedge.admx
Controls whether Microsoft Edge allows SharedWorkers to use the extendedLifetime option. If you enable or don't configure this policy, SharedWorkers can use the extended lifetime option in the SharedWorker constructor. If you disable this policy, the extended lifetime option is ignored, even if it is requested by the page. This policy is temporary and will be removed in a future release.
NetworkServiceSandboxEnabled Enable the network service sandbox
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NetworkServiceSandboxEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 102, Windows 7 or later
- Template
- msedge.admx
This policy controls whether or not the network service process runs sandboxed. If this policy is enabled, the network service process runs sandboxed. If this policy is disabled, the network service process runs unsandboxed. This leaves users open to other security risks related to running the network service unsandboxed. If this policy isn't set, the default configuration for the network sandbox will be used. This may vary depending on Microsoft Edge release, currently running field trials, and platform. This policy is intended to give enterprises flexibility to disable the network sandbox if they use third party software that interferes with the network service sandbox.
WebCaptureEnabled Enable the Screenshot (previously named Web Capture) feature in Microsoft Edge
If you enable or don't configure this policy, the Screenshot option appears in the context menu, the Settings and more menu, and by using the keyboard shortcut, CTRL+SHIFT+S.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebCaptureEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 87, Windows 7 or later
- Template
- msedge.admx
Note: The web capture feature is rebranded to "Screenshot". Enables the Screenshot feature in Microsoft Edge. This feature lets users capture web and PDF content, and annotate captures using inking tools. Users can also do a visual image search based on the captured content. If you enable or don't configure this policy, the Screenshot option appears in the context menu, the Settings and more menu, and by using the keyboard shortcut, CTRL+SHIFT+S. If you disable this policy, users can't access this feature in Microsoft Edge.
SearchbarAllowed Enable the Search bar
If you enable or don't configure this policy, the following results can be seen: The search bar is automatically enabled for all profiles. If the 'SearchbarIsEnabledOnStartup' is disabled or not configured, the option to enable the search bar at startup is toggled off.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SearchbarAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 117, Windows 7 or later
- Template
- msedge.admx
Enables the search bar. When enabled, users can use the search bar to search the web from their desktop or from an application. The search bar provides a search box, powered by Microsoft Edge default search engine, that shows web suggestions and opens all web searches in Microsoft Edge. The search bar can be launched from the "More tools" menu or jump list in Microsoft Edge. If you enable or don't configure this policy, the following results can be seen: The search bar is automatically enabled for all profiles. The option to enable the search bar at startup is toggled on if the 'SearchbarIsEnabledOnStartup' (Allow the Search bar at Windows startup) policy is enabled. If the 'SearchbarIsEnabledOnStartup' is disabled or not configured, the option to enable the search bar at startup is toggled off. Users will see the menu item to launch the search bar from the Microsoft Edge "More tools" menu. Users can launch the search bar from "More tools". Users will see the menu item to launch the search bar from the Microsoft Edge jump list menu. Users can launch the search bar from the Microsoft Edge jump list menu. The search bar can be turned off by the "Quit" option in the System tray or by closing the search bar from the 3-dot menu. The search bar is restarted on system reboot if auto-start is enabled. If you disable this policy: The search bar will be disabled for all profiles. The option to launch the search bar from Microsoft Edge "More tools" menu will be disabled. The option to launch the search bar from Microsoft Edge jump list menu will be disabled.
WebWidgetAllowed Enable the Search bar (deprecated)
If you enable or don't configure this policy, the following results are seen: The search bar is automatically enabled for all profiles. If the 'WebWidgetIsEnabledOnStartup' is disabled or not configured, the option to enable the search bar at startup is toggled off.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebWidgetAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 88, Windows 7 or later
- Template
- msedge.admx
DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. Enables the search bar. When enabled, users can use the search bar to search the web from their desktop or from an application. The search bar provides a search box that shows web suggestions and opens all web searches in Microsoft Edge. The search box provides search (powered by Bing) and URL suggestions. The search bar can be launched from the "More tools" menu or jump list in Microsoft Edge. If you enable or don't configure this policy, the following results are seen: The search bar is automatically enabled for all profiles. The option to enable the search bar at startup is toggled on if the 'WebWidgetIsEnabledOnStartup' (Allow the Search bar at Windows startup) policy is enabled. If the 'WebWidgetIsEnabledOnStartup' is disabled or not configured, the option to enable the search bar at startup is toggled off. Users will see the menu item to launch the search bar from the Microsoft Edge "More tools" menu. Users can launch the search bar from "More tools". Users will see the menu item to launch the search bar from the Microsoft Edge jump list menu. Users can launch the search bar from the Microsoft Edge jump list menu. The search bar can be turned off by the "Quit" option in the System tray or by closing the search bar from the three-dot menu. The search bar is restarted on system reboot if auto-start is enabled. If you disable this policy, the following results are seen: The search bar is disabled for all profiles. The option to launch the search bar from Microsoft Edge "More tools" menu is disabled. The option to launch the search bar from Microsoft Edge jump list menu is disabled. This policy is deprecated due to the deprecation of the Web widget's vertical layout. This policy will be made obsolete in 119 release.
UserAgentClientHintsEnabled Enable the User-Agent Client Hints feature (obsolete)
If you enable or don't configure this policy, the User-Agent Client Hints feature is enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- UserAgentClientHintsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 86-93, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 93. This policy is obsolete because it was intended for short-term adaptation purposes only. It doesn't work in Microsoft Edge after version 93. When enabled the User-Agent Client Hints feature sends granular request headers that provide information about the user browser (for example, the browser version) and environment (for example, the system architecture). This is an additive feature, but the new headers may break some websites that restrict the characters that requests may contain. If you enable or don't configure this policy, the User-Agent Client Hints feature is enabled. If you disable this policy, this feature is unavailable.
TranslateEnabled Enable Translate
If you don't configure this policy, the policy is enabled by default.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- TranslateEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enables the integrated Microsoft translation service on Microsoft Edge. If you enable this policy, Microsoft Edge offers to translate a webpage by showing an integrated translate flyout when the language detected on a webpage isn't listed under preferred languages. A translate option is available on the right-click context menu. Users can also translate selected text on a webpage via the right-click context menu, or on a PDF via the PDF toolbar and the right-click context menu. If you don't configure this policy, the policy is enabled by default. Users can choose whether to use the translation functionality or not. You can disable this policy to disable all built-in translate features.
TravelAssistanceEnabled Enable travel assistance (obsolete)
If you enable or don't configure this setting, travel assistance is enabled for the users when they are performing travel-related tasks.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- TravelAssistanceEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 93-105, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 105. This policy is obsolete as the feature is now contained within the Edge Sidebar and can be managed using the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy. It doesn't work in Microsoft Edge after version 105. Configure this policy to allow/disallow travel assistance. The travel assistance feature gives helpful and relevant information to a user who performs a travel-related task within the browser. This feature provides trusted and validated suggestions/information to the users from across sources gathered by Microsoft. If you enable or don't configure this setting, travel assistance is enabled for the users when they are performing travel-related tasks. If you disable this setting, travel assistance will be disabled, and users won't be able to see any travel-related recommendations.
UploadFromPhoneEnabled Enable upload files from mobile in Microsoft Edge desktop
If you enable or don't configure this policy, you can use the Upload from mobile feature in Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- UploadFromPhoneEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 117, Windows 7 or later
- Template
- msedge.admx
This policy lets you configure the "Upload from mobile" feature in Microsoft Edge. Upload from mobile lets users select file from mobile devices to desktop when user upload file in a webpage in Microsoft Edge. If you enable or don't configure this policy, you can use the Upload from mobile feature in Microsoft Edge. If you disable this policy, you can't use the Upload from mobile feature in Microsoft Edge.
MetricsReportingEnabled Enable usage and crash-related data reporting (obsolete)
On Windows 10, if you don't configure this policy, Microsoft Edge defaults to the Windows diagnostic data setting. If you don't configure this policy, Microsoft Edge defaults to the user's preference.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- MetricsReportingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77-88, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 88. This policy is no longer supported. It's replaced by 'DiagnosticData' (Send required and optional diagnostic data about browser usage) (for Windows 7, Windows 8, and macOS) and Allow Telemetry on Win 10 (https://go.microsoft.com/fwlink/?linkid=2099569). This policy enables reporting of usage and crash-related data about Microsoft Edge to Microsoft. Enable this policy to send reporting of usage and crash-related data to Microsoft. Disable this policy to not send the data to Microsoft. In both cases, users can't change or override the setting. On Windows 10, if you don't configure this policy, Microsoft Edge defaults to the Windows diagnostic data setting. If you enable this policy, Microsoft Edge only sends usage data if the Windows Diagnostic data setting is set to Enhanced or Full. If you disable this policy, Microsoft Edge won't send usage data. Crash-related data is sent based on the Windows Diagnostic data setting. Learn more about Windows Diagnostic data settings at https://go.microsoft.com/fwlink/?linkid=2099569 On Windows 7, Windows 8, and macOS, this policy controls sending usage and crash-related data. If you don't configure this policy, Microsoft Edge defaults to the user's preference. To enable this policy,'SendSiteInfoToImproveServices' (Send site information to improve Microsoft services) must be set to Enabled. If 'MetricsReportingEnabled' (Enable usage and crash-related data reporting) or 'SendSiteInfoToImproveServices' is Not Configured or Disabled, this data won't be sent to Microsoft. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are managed via MDM or joined to a domain via MCX.
ForceEphemeralProfiles Enable use of ephemeral profiles
If you disable this policy or don't configure it, users get their regular profiles when they sign in to the browser.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ForceEphemeralProfiles
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Controls whether user profiles are switched to ephemeral mode. An ephemeral profile is created when a session begins, is deleted when the session ends, and is associated with the user's original profile. If you enable this policy, profiles run in ephemeral mode. This setting lets users work from their own devices without saving browsing data to those devices. If you enable this policy as an OS policy (by using GPO on Windows, for example), it applies to every profile on the system. If you disable this policy or don't configure it, users get their regular profiles when they sign in to the browser. In ephemeral mode, profile data is saved on disk only for the length of the user session. Features like browser history, extensions and their data, web data like cookies, and web databases aren't saved after the browser is closed. This setting doesn't prevent a user from manually downloading any data to disk, or from saving pages or printing them. If the user enabled sync, all data is preserved in their sync accounts just like with regular profiles. Users can also use InPrivate browsing in ephemeral mode unless you explicitly disable this setting.
WebAppInstallByUserEnabled Enable User Web App Install From Browser
Changes to this policy, whether enabled, disabled, or not configured, take effect only after the browser is restarted.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebAppInstallByUserEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 145, Windows 7 or later
- Template
- msedge.admx
This policy controls whether users can install web apps through Microsoft Edge. If you enable or don’t configure this policy, users can install web apps through the browser. If you disable this policy, users can’t install web apps through the browser, and the "apps" data type is excluded from synchronization. This policy doesn't support dynamic refresh. Changes to this policy, whether enabled, disabled, or not configured, take effect only after the browser is restarted. This policy doesn't affect the 'WebAppInstallForceList' policy. Web apps specified by that policy are installed regardless of this policy setting.
RoamingProfileSupportEnabled Enable using roaming copies for Microsoft Edge profile data
If you disable this policy or don't configure it, only the regular local profiles are used.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RoamingProfileSupportEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 85, Windows 7 or later
- Template
- msedge.admx
Enable this policy to use roaming profiles on Windows. The settings stored in Microsoft Edge profiles (favorites and preferences) are also saved to a file stored in the Roaming user profile folder (or the location specified by the administrator through the 'RoamingProfileLocation' (Set the roaming profile directory) policy). If you disable this policy or don't configure it, only the regular local profiles are used. The 'SyncDisabled' (Disable synchronization of data using Microsoft sync services) only disables cloud synchronization and has no effect on this policy. For more information on using roaming user profiles, see https://go.microsoft.com/fwlink/?linkid=2150058.
EdgeWalletCheckoutEnabled Enable Wallet Checkout feature
If you enable or don't configure this policy, users can choose whether to use wallet checkout while shopping on Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeWalletCheckoutEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 114, Windows 7 or later
- Template
- msedge.admx
Enables Wallet Checkout feature in Microsoft Edge. If you enable or don't configure this policy, users can choose whether to use wallet checkout while shopping on Microsoft Edge. If you disable this policy, users can't use wallet checkout while shopping on Microsoft Edge.
InsecureFormsWarningsEnabled Enable warnings for insecure forms (deprecated)
The feature is enabled by default since Edge 131.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InsecureFormsWarningsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. This policy controls the handling of insecure forms (forms submitted over HTTP) embedded in secure (HTTPS) sites in the browser. If you enable this policy or don't set it, a full page warning is shown when an insecure form is submitted. Additionally, a warning bubble is shown next to the form fields when they're focused, and autofill will be disabled for those forms. If you disable this policy, warnings won't be shown for insecure forms, and autofill works normally. This policy may be removed as soon as Edge 132. The feature is enabled by default since Edge 131.
WindowOcclusionEnabled Enable Window Occlusion
If you don't configure this policy, window hiding detection is enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WindowOcclusionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 89, Windows 7 or later
- Template
- msedge.admx
Enables window occlusion in Microsoft Edge. If you enable this setting, to reduce CPU and power consumption, Microsoft Edge detects when a window is covered by other windows, and suspends work painting pixels. If you disable this setting, Microsoft Edge doesn't detect when a window is covered by other windows. If you don't configure this policy, window hiding detection is enabled.
LocalBrowserDataShareEnabled Enable Windows to search local Microsoft Edge browsing data
If you enable this policy or don't configure it, Microsoft Edge publishes local browsing data to the Windows Indexer.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- LocalBrowserDataShareEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
Enables Windows to index Microsoft Edge browsing data stored locally on the user's device and allows users to find and launch previously stored browsing data directly from Windows features such as the search box on the taskbar in Windows. If you enable this policy or don't configure it, Microsoft Edge publishes local browsing data to the Windows Indexer. If you disable this policy, Microsoft Edge won't share data to the Windows Indexer. Note that if you disable this policy, Microsoft Edge removes the data shared with Windows on the device and stops sharing any new browsing data.
AddressBarWorkSearchResultsEnabled Enable Work Search suggestions in the address bar
If this policy is enabled or not configured, users can view internal work-related suggestions, such as bookmarks, files, and people results powered by Microsoft 365, in the Microsoft Edge address bar suggestion dropdown.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AddressBarWorkSearchResultsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 134, Windows 7 or later
- Template
- msedge.admx
Enables the display of relevant workplace suggestions in the address bar’s suggestion dropdown when users type a query in the address bar. If this policy is enabled or not configured, users can view internal work-related suggestions, such as bookmarks, files, and people results powered by Microsoft 365, in the Microsoft Edge address bar suggestion dropdown. To access these results, users must be signed into Microsoft Edge with their Entra ID account associated with that organization. If this policy is disabled, users can't see internal workplace results in the Microsoft Edge address bar suggestion dropdown.
BackgroundTemplateListUpdatesEnabled Enables background updates to the list of available templates for Collections and other features that use templates (deprecated)
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- BackgroundTemplateListUpdatesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 79, Windows 7 or later
- Template
- msedge.admx
DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. This policy is deprecated because we are moving to a new policy. It won't work in Microsoft Edge as soon as version 104. The new policy to use is 'EdgeAssetDeliveryServiceEnabled' (Allow features to download assets from the Asset Delivery Service). Lets you enable or disable background updates to the list of available templates for Collections and other features that use templates. Templates are used to extract rich metadata from a webpage when the page is saved to a collection. If you enable this setting or the setting is unconfigured, the list of available templates are downloaded in the background from a Microsoft service every 24 hours. If you disable this setting the list of available templates are downloaded on demand. This type of download might result in small performance penalties for Collections and other features.
AIGenThemesEnabled Enables DALL-E themes generation
If you enable or don't configure this policy, the AI generated themes are enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AIGenThemesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 122, Windows 7 or later
- Template
- msedge.admx
This policy lets you generate browser themes using DALL-E and apply them to Microsoft Edge. If you enable or don't configure this policy, the AI generated themes are enabled. If you disable this policy, the AI generated themes are disabled for your organization.
DefaultBrowserSettingsCampaignEnabled Enables default browser settings campaigns
If you enable or don't configure this policy, users will be prompted to set Microsoft Edge as the default browser and Microsoft Bing as the default search engine, if they don't have those browser settings.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultBrowserSettingsCampaignEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 113, Windows 7 or later
- Template
- msedge.admx
This policy enables the default browser settings campaign. If a user selects to accept the campaign, their default browser and/or default search engine will be changed to Microsoft Edge and Microsoft Bing, respectively. If the user dismisses the campaign, the user's browser settings remain unchanged. If you enable or don't configure this policy, users will be prompted to set Microsoft Edge as the default browser and Microsoft Bing as the default search engine, if they don't have those browser settings. If you disable this policy, users won't be prompted to set Microsoft Edge as the default browser, or to set Microsoft Bing as the default search engine.
QuickSearchShowMiniMenu Enables Microsoft Edge mini menu
If you enable or don't configure this policy, selecting text on websites or PDFs shows the mini menu.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- QuickSearchShowMiniMenu
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 104, Windows 7 or later
- Template
- msedge.admx
Enables the Microsoft Edge mini menu on websites and PDFs. The mini menu appears when users select text and provides basic actions like Copy and smart actions such as Definitions. If you enable or don't configure this policy, selecting text on websites or PDFs shows the mini menu. If you disable this policy, the mini menu doesn't appear when users select text on websites or PDFs. Note: Starting in Microsoft Edge for Mac version 143, this policy is obsolete because the mini menu feature is removed on Mac.
ForceBingSafeSearch Enforce Bing SafeSearch
If you disable this policy or don't configure it, SafeSearch in Bing search isn't enforced, and users can set the value they want on bing. Policy options mapping: * BingSafeSearchNoRestrictionsMode (0) = Don't configure search restrictions in Bing * BingSafeSearchModerateMode (1) = Configure moderate search restrictions in Bing * BingSafeSearchStrictMode (2) = Configure strict search restrictions in Bing Use the preceding information when configuring this policy.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ForceBingSafeSearch
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
0Don't configure search restrictions in Bing1Configure moderate search restrictions in Bing2Configure strict search restrictions in BingEnsure that queries in Bing web search are done with SafeSearch set to the value specified. Users can't change this setting. If you configure this policy to 'BingSafeSearchNoRestrictionsMode', SafeSearch in Bing search falls back to the bing.com value. If you configure this policy to 'BingSafeSearchModerateMode', the moderate setting is used in SafeSearch. The moderate setting filters adult videos and images but not text from search results. If you configure this policy to 'BingSafeSearchStrictMode', the strict setting in SafeSearch is used. The strict setting filters adult text, images, and videos. If you disable this policy or don't configure it, SafeSearch in Bing search isn't enforced, and users can set the value they want on bing.com. Policy options mapping: * BingSafeSearchNoRestrictionsMode (0) = Don't configure search restrictions in Bing * BingSafeSearchModerateMode (1) = Configure moderate search restrictions in Bing * BingSafeSearchStrictMode (2) = Configure strict search restrictions in Bing Use the preceding information when configuring this policy.
BrowserGuestModeEnforced Enforce Edge guest mode
If you disable or don't configure this policy, users can create and use profiles.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- BrowserGuestModeEnforced
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 147, Windows 7 or later
- Template
- msedge.admx
Controls whether Microsoft Edge enforces Guest-only browsing. If you enable this policy, Microsoft Edge enforces Guest sessions and prevents profile sign-in. Guest sessions run in InPrivate mode. If you disable or don't configure this policy, users can create and use profiles. Guest mode can also be controlled separately using the BrowserGuestModeEnabled policy.
ForceGoogleSafeSearch Enforce Google SafeSearch
If you disable this policy or don't configure it, SafeSearch in Google Search isn't enforced.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ForceGoogleSafeSearch
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Forces queries in Google Web Search to be performed with SafeSearch set to active, and prevents users from changing this setting. If you enable this policy, SafeSearch in Google Search is always active. If you disable this policy or don't configure it, SafeSearch in Google Search isn't enforced.
EdgeEnhanceImagesEnabled Enhance images enabled (obsolete)
If you enable this policy or don't configure the policy, Microsoft Edge automatically enhances images on specific web applications.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeEnhanceImagesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 97-121, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 121. The enhance images feature is deprecated and starting in Microsoft Edge version 122, this policy will be removed. Set whether Microsoft Edge can automatically enhance images to show you sharper images with better color, lighting, and contrast. If you enable this policy or don't configure the policy, Microsoft Edge automatically enhances images on specific web applications. If you disable this policy, Microsoft Edge doesn't enhance images.
EnhanceSecurityMode Enhance the security state in Microsoft Edge
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EnhanceSecurityMode
- Supported on
- Microsoft Edge version 98, Windows 7 or later
- Template
- msedge.admx
0Standard mode1Balanced mode2Strict mode3(Deprecated) Basic modeThis policy lets you enhance the security state in Microsoft Edge. If you set this policy to 'StandardMode', the enhanced mode is turned off, and Microsoft Edge falls back to its standard security mode. If you set this policy to 'BalancedMode', the security state is in balanced mode. If you set this policy to 'StrictMode', the security state is in strict mode. If you set this policy to 'BasicMode', the security state is in basic mode. Note: Sites that use WebAssembly (WASM) aren't supported on 32-bit systems when 'EnhanceSecurityMode' (Enhance the security state in Microsoft Edge) is enabled. If you require access to a site that uses WASM, consider adding it to your exception list as described in https://go.microsoft.com/fwlink/?linkid=2183321. Starting from Microsoft Edge version 113, 'BasicMode' is deprecated and is treated the same as 'BalancedMode'. It doesn't work in Microsoft Edge version 116. For detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895. Policy options mapping: * StandardMode (0) = Standard mode * BalancedMode (1) = Balanced mode * StrictMode (2) = Strict mode * BasicMode (3) = (Deprecated) Basic mode Use the preceding information when configuring this policy.
EnhanceSecurityModeBypassIntranet Enhanced Security Mode configuration for Intranet zone sites
If you disable or don't configure this policy, Microsoft Edge applies Enhanced Security Mode on Intranet zone sites.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EnhanceSecurityModeBypassIntranet
- Enabled / Disabled
- 1 / 0
- Stated default
- Microsoft Edge applies Enhanced Security Mode on Intranet zone sites by default.
- Supported on
- Microsoft Edge version 107, Windows 7 or later
- Template
- msedge.admx
Microsoft Edge applies Enhanced Security Mode on Intranet zone sites by default. This can lead to Intranet zone sites acting in an unexpected manner. If you enable this policy, Microsoft Edge can't apply Enhanced Security Mode on Intranet zone sites. If you disable or don't configure this policy, Microsoft Edge applies Enhanced Security Mode on Intranet zone sites. For detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895
ExplicitlyAllowedNetworkPorts Explicitly allowed network ports
Leaving the value empty or unset means that all restricted ports are blocked.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ExplicitlyAllowedNetworkPorts
- Supported on
- Microsoft Edge version 91, Windows 7 or later
- Template
- msedge.admx
There's a list of restricted ports built into Microsoft Edge. Connections to these ports fail. This policy allows bypassing that list. The set of ports is defined as a comma-separated list that outgoing connections should be permitted on. Ports are restricted to prevent Microsoft Edge from being used as a vector to exploit various network vulnerabilities. Setting this policy exposes your network to attacks. This policy is intended as a temporary workaround for error code "ERR_UNSAFE_PORT" while migrating a service running on a blocked port to a standard port (for example, port 80 or 443). Malicious websites can easily detect that this policy is set. They also detect the ports for which this policy is set, and then they use that information to target attacks. Each port listed in this policy is labeled with a date until which that port can be unblocked. After that date, the port is restricted, regardless of whether it's specified by the value of this policy. Leaving the value empty or unset means that all restricted ports are blocked. Invalid port values set through this policy are ignored while valid ones are still applied. This policy overrides the "--explicitly-allowed-ports" command-line option. Policy options mapping: * 554 (554) = port 554 (can be unblocked until 2021/10/15) * 10080 (10080) = port 10080 (can be unblocked until 2022/04/01) * 6566 (6566) = port 6566 (can be unblocked until 2021/10/15) * 989 (989) = port 989 (can be unblocked until 2022/02/01) * 990 (990) = port 990 (can be unblocked until 2022/02/01) Use the preceding information when configuring this policy. Example value: 10080
RunAllFlashInAllowMode Extend Adobe Flash content setting to all content (obsolete)
If you disable this policy or don't configure it, Adobe Flash content from other origins (sites that aren't specified in the preceding three policies) or small content might be blocked.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RunAllFlashInAllowMode
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77-88, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 88. This policy doesn't work because Flash is no longer supported by Microsoft Edge. If you enable this policy, all Adobe Flash content embedded in websites that are set to allow Adobe Flash in the content settings, either by the user or by enterprise policy, run. This includes content from other origins and/or small content. To control which websites are allowed to run Adobe Flash, see the specifications in the 'DefaultPluginsSetting' (Default Adobe Flash setting), 'PluginsAllowedForUrls' (Allow the Adobe Flash plug-in on specific sites), and 'PluginsBlockedForUrls' (Block the Adobe Flash plug-in on specific sites) policies. If you disable this policy or don't configure it, Adobe Flash content from other origins (sites that aren't specified in the preceding three policies) or small content might be blocked.
FetchKeepaliveDurationSecondsOnShutdown Fetch keepalive duration on shutdown
If you disable or don't configure this policy, the default value of 0 seconds is used, and the outstanding keepalive requests are immediately cancelled during browser shutdown.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- FetchKeepaliveDurationSecondsOnShutdown
- Supported on
- Microsoft Edge version 90, Windows 7 or later
- Template
- msedge.admx
Controls the duration (in seconds) that keepalive requests are allowed to prevent the browser from completing its shutdown. If you configure this policy, the browser blocks completing shutdown while it processes any outstanding keepalive requests (see https://fetch.spec.whatwg.org/#request-keepalive-flag) up to the maximum period of time specified by this policy. If you disable or don't configure this policy, the default value of 0 seconds is used, and the outstanding keepalive requests are immediately cancelled during browser shutdown.
GoToIntranetSiteForSingleWordEntryInAddressBar Force direct intranet site navigation instead of searching on single word entries in the Address Bar
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- GoToIntranetSiteForSingleWordEntryInAddressBar
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 78, Windows 7 or later
- Template
- msedge.admx
If you enable this policy, the top autosuggest result in the address bar suggestion list navigates to intranet sites if the text entered in the address bar is a single word without punctuation. Default navigation when typing a single word without punctuation conducts a navigation to an intranet site matching the entered text. If you enable this policy, the second autosuggest result in the address bar suggestion list conducts a web search exactly as it was entered, if this text is a single word without punctuation. The default search provider is used unless a policy to prevent web search is also enabled. Two effects of enabling this policy are: Navigation to sites in response to single word queries that would typically resolve to a history item will no longer happen. Instead, the browser will attempt navigate to internal sites that may not exist in an organization's intranet. This will result in a 404 error. Popular, single-word search terms will require manual selection of search suggestions to properly conduct a search.
SpellcheckLanguageBlocklist Force disable spellcheck languages
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\SpellcheckLanguageBlocklist
- Supported on
- Microsoft Edge version 78, Windows 7 or later
- Template
- msedge.admx
Force-disables spellcheck languages. Unrecognized languages in that list will be ignored. If you enable this policy, spellcheck will be disabled for the languages specified. The user can still enable or disable spellcheck for languages not in the list. If you don't set this policy, or disable it, there is no change to the user's spellcheck preferences. If the 'SpellcheckEnabled' (Enable spellcheck) policy is set to disabled, this policy has no effect. If a language is included in both the 'SpellcheckLanguage' (Enable specific spellcheck languages) and the 'SpellcheckLanguageBlocklist' policy, the spellcheck language is enabled. Example value: fr es
ForceForegroundPriorityForAllTabs Force foreground priority for all tabs
If you disable or don't configure this policy, the browser determines the priority of web content based on standard heuristics.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ForceForegroundPriorityForAllTabs
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, the browser optimizes resource usage by lowering the scheduling priority of content in background tabs.
- Supported on
- Microsoft Edge version 146, Windows 7 or later
- Template
- msedge.admx
This policy controls whether background web content runs at foreground priority. By default, the browser optimizes resource usage by lowering the scheduling priority of content in background tabs. This helps improve overall system responsiveness and performance for the active tab. If you enable this policy, background web content runs at the same foreground priority as the active tab, regardless of visibility state. If you disable or don't configure this policy, the browser determines the priority of web content based on standard heuristics. For example, content that is not visible, not playing audio, and not participating in video calls may be deprioritized.
ForceForegroundPriorityForUrls Force foreground priority for specific URLs
If the ForceForegroundPriorityForAllTabs policy is disabled or not configured, only background content that matches the URL patterns in this list is forced to run at foreground priority.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ForceForegroundPriorityForUrls
- Supported on
- Microsoft Edge version 149, Windows 7 or later
- Template
- msedge.admx
This policy allows you to specify a list of URL patterns for which background web content is forced to run at foreground priority. If the ForceForegroundPriorityForAllTabs policy is enabled, this policy is ignored because all tabs are already forced to run at foreground priority. If the ForceForegroundPriorityForAllTabs policy is disabled or not configured, only background content that matches the URL patterns in this list is forced to run at foreground priority. For more information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. If you don’t configure this policy or the list is empty, no background content is forced to run at foreground priority. Example value: https://www.example.com/path?query=val example.edu https://example.com:8080 *://example.org:*/
ForceYouTubeRestrict Force minimum YouTube Restricted Mode
Set to 'Off' or don't configure this policy to not enforce Restricted Mode on YouTube.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ForceYouTubeRestrict
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
0Do not enforce Restricted Mode on YouTube1Enforce at least Moderate Restricted Mode on YouTube2Enforce Strict Restricted Mode for YouTubeEnforces a minimum Restricted Mode on YouTube and prevents users from picking a less restricted mode. Set to 'Strict' to enforce Strict Restricted Mode on YouTube. Set to 'Moderate' to enforce the user to only use Moderate Restricted Mode and Strict Restricted Mode on YouTube. They can't disable Restricted Mode. Set to 'Off' or don't configure this policy to not enforce Restricted Mode on YouTube. External policies such as YouTube policies might still enforce Restricted Mode. Policy options mapping: * Off (0) = Do not enforce Restricted Mode on YouTube * Moderate (1) = Enforce at least Moderate Restricted Mode on YouTube * Strict (2) = Enforce Strict Restricted Mode for YouTube Use the preceding information when configuring this policy.
ForceNetworkInProcess Force networking code to run in the browser process (obsolete)
This policy is disabled by default.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ForceNetworkInProcess
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 78-83, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 83. This policy doesn't work because it was only intended to be a short-term mechanism to give enterprises more time to migrate to third party software that doesn't depend on hooking networking APIs. Proxy servers are recommended over Label-Switched Paths (LSPs) and Win32 API patching. This policy forces networking code to run in the browser process. This policy is disabled by default. If enabled, users are open to security issues when the networking process is sandboxed.
ForceSync Force synchronization of browser data and do not show the sync consent prompt
If you don't configure this policy, users can turn on or turn off sync.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ForceSync
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
Forces data synchronization in Microsoft Edge. This policy also prevents the user from turning off sync. If you don't configure this policy, users can turn on or turn off sync. If you enable this policy, users can't turn off sync. For this policy to work as intended, 'BrowserSignin' (Browser sign-in settings) policy must not be configured, or must be set to enabled. If 'BrowserSignin' is set to disabled, then 'ForceSync' (Force synchronization of browser data and do not show the sync consent prompt) doesn't take affect. 'SyncDisabled' (Disable synchronization of data using Microsoft sync services) must not be configured or must be set to False. If this policy is set to True, 'ForceSync' doesn't take affect. If you wish to ensure specific datatypes sync or don't sync, use the 'ForceSyncTypes' (Configure the list of types that are included for synchronization) policy and 'SyncTypesListDisabled' (Configure the list of types that are excluded from synchronization) policy, respectively. 0 = Do not automatically start sync and show the sync consent (default) 1 = Force sync to turn on for Azure AD/Azure AD-Degraded user profile and do not show the sync consent prompt
WebSQLNonSecureContextEnabled Force WebSQL in non-secure contexts to be enabled (obsolete)
If you disable or don't configure this policy, WebSQL in nonsecure contexts follows the default settings of the browser.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebSQLNonSecureContextEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- This policy doesn't work because WebSQL in nonsecure contexts is on by default as of Microsoft Edge 105.
- Supported on
- Microsoft Edge version 107-112, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 112. This policy doesn't work because WebSQL in nonsecure contexts is on by default as of Microsoft Edge 105. If you enable this policy, WebSQL in nonsecure contexts is enabled. If you disable or don't configure this policy, WebSQL in nonsecure contexts follows the default settings of the browser. This policy was removed in Microsoft Edge 113, and it's ignored if configured.
WebSQLInThirdPartyContextEnabled Force WebSQL in third-party contexts to be re-enabled (obsolete)
If you disable this policy or don't configure it, WebSQL in third-party contexts remains off.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebSQLInThirdPartyContextEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- WebSQL in third-party contexts (for example, cross-site iframes) is off by default as of Microsoft Edge version 97 and was fully removed in version 101.
- Supported on
- Microsoft Edge version 97-100, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 100. This policy is obsolete because it was intended to be a short-term mechanism to give enterprises more time to update their web content when it was incompatible with the change to disable WebSQL in third-party contexts. It doesn't work in Microsoft Edge after version 100. WebSQL in third-party contexts (for example, cross-site iframes) is off by default as of Microsoft Edge version 97 and was fully removed in version 101. If you enable this policy, WebSQL in third-party contexts is re-enabled. If you disable this policy or don't configure it, WebSQL in third-party contexts remains off.
WebSQLAccess Force WebSQL to be enabled (obsolete)
If you disable or don't configure this policy, WebSQL can be disabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebSQLAccess
- Enabled / Disabled
- 1 / 0
- Stated default
- WebSQL is on by default as of Microsoft Edge version 101, but can be disabled via a Microsoft Edge flag.
- Supported on
- Microsoft Edge version 107-123, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 123. This policy was removed in Microsoft Edge 124 and is ignored if set. WebSQL is on by default as of Microsoft Edge version 101, but can be disabled via a Microsoft Edge flag. If you enable this policy, WebSQL cannot be disabled. If you disable or don't configure this policy, WebSQL can be disabled.
NativeHostsExecutablesLaunchDirectly Force Windows executable Native Messaging hosts to launch directly
If you don't configure this policy, Microsoft Edge decides which approach to use based on a progressive rollout from the legacy behavior to the Launch Directly behavior, guided by ecosystem compatibility.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NativeHostsExecutablesLaunchDirectly
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 121, Windows 7 or later
- Template
- msedge.admx
This policy controls whether native host executables launch directly on Windows. If you enable this policy, Microsoft Edge is forced to launch native messaging hosts implemented as executables directly. If you disable this policy, Microsoft Edge launches hosts using cmd.exe as an intermediary process. If you don't configure this policy, Microsoft Edge decides which approach to use based on a progressive rollout from the legacy behavior to the Launch Directly behavior, guided by ecosystem compatibility.
ForceBuiltInPushMessagingClient Forces Microsoft Edge to use its built-in WNS push client to connect to the Windows Push Notification Service.
If disabled or not configured, Microsoft Edge uses the Windows OS client to connect to the Windows Push Notification Service.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ForceBuiltInPushMessagingClient
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 118, Windows 7 or later
- Template
- msedge.admx
In some environments, the Windows OS client can't connect to the Windows Push Notification Service (WNS). For these environments, you can use the Microsoft Edge built-in WNS push client, which can connect successfully. If enabled, Microsoft Edge uses its built-in WNS push client to connect to WNS. If disabled or not configured, Microsoft Edge uses the Windows OS client to connect to the Windows Push Notification Service. This is the default setting.
AskBeforeCloseEnabled Get user confirmation before closing a browser window with multiple tabs
If you disable or don't configure this policy, a browser window with multiple tabs will close immediately without user confirmation.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AskBeforeCloseEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 104, Windows 7 or later
- Template
- msedge.admx
This policy lets you configure whether users see a confirmation dialog before closing a browser window with multiple tabs. This dialog asks users to confirm that the browser window can be closed. If you enable this policy, users will be presented with a confirmation dialog when closing a browser window with multiple tabs. If you disable or don't configure this policy, a browser window with multiple tabs will close immediately without user confirmation.
HideRestoreDialogEnabled Hide restore pages dialog after browser crash
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- HideRestoreDialogEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 100, Windows 7 or later
- Template
- msedge.admx
This policy gives an option to hide the "Restore pages" dialog after Microsoft Edge has crashed. The "Restore pages" dialog gives users the option to restore the pages that were previously open before Microsoft Edge crashed. If you enable this policy, the "Restore pages" dialog isn't shown. In the event of a crash, Microsoft Edge doesn't restore previous tabs and starts the session with a new tab page. If you disable or don't set this policy, the "Restore pages" dialog is shown. If you set this policy, don't set the 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) or 'SavingBrowserHistoryDisabled' (Disable saving browser history) policy since that prevents history from being saved which also disables the dialog.
HideFirstRunExperience Hide the First-run experience and splash screen
If you disable or don't configure this policy, the First-run experience and the Splash screen will be shown.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- HideFirstRunExperience
- Enabled / Disabled
- 1 / 0
- Stated default
- -Sync won't be enabled by default and users will be prompted to choose whether they'd like to sync on browser startup.
- Supported on
- Microsoft Edge version 80, Windows 7 or later
- Template
- msedge.admx
If you enable this policy, the First-run experience and the splash screen won't be shown to users when they run Microsoft Edge for the first time. For the configuration options shown in the First Run Experience, the browser defaults to the following results: -On the New Tab Page, the feed type is set to MSN News and the layout to Inspirational. -The user is still automatically signed in to Microsoft Edge if the Windows account is of Azure AD or MSA type. -Sync won't be enabled by default and users will be prompted to choose whether they'd like to sync on browser startup. You can use the 'ForceSync' (Force synchronization of browser data and do not show the sync consent prompt) or the 'SyncDisabled' (Disable synchronization of data using Microsoft sync services) policy to configure sync and the sync consent prompt. If you disable or don't configure this policy, the First-run experience and the Splash screen will be shown. Note: The specific configuration options shown to the user in the First Run Experience, can also be managed by using other specific policies. You can use the HideFirstRunExperience policy in combination with these policies to configure a specific browser experience on your managed devices. Some of these other policies are: -'AutoImportAtFirstRun' (Automatically import another browser's data and settings at first run) -'NewTabPageLocation' (Configure the new tab page URL) -'NewTabPageSetFeedType' (Configure the Microsoft Edge new tab page experience) -'ForceSync' -'SyncDisabled' -'BrowserSignin' (Browser sign-in settings) -'NonRemovableProfileEnabled' (Configure whether a user always has a default profile automatically signed in with their work or school account)
HideInternetExplorerRedirectUXForIncompatibleSitesEnabled Hide the one-time redirection dialog and the banner on Microsoft Edge
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- HideInternetExplorerRedirectUXForIncompatibleSitesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 87, Windows 7 or later
- Template
- msedge.admx
This policy gives an option to disable one-time redirection dialog and the banner. If you enable this policy, users don't see both the one-time dialog and the banner. Users continue to be redirected to Microsoft Edge when they encounter an incompatible website on Internet Explorer; however, their browsing data isn't imported. - If you enable this policy, the one-time redirection dialog and banner are never shown to users. Users' browsing data isn't imported when a redirection happens. - If you disable or don't set this policy, the redirection dialog is shown on the first redirection, and the persistent redirection banner is shown to users on sessions that begin with a redirection. Users' browsing data will be imported every time user encounters such redirection (ONLY IF user consents to it on the one-time dialog).
HttpAllowlist HTTP Allowlist
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\HttpAllowlist
- Supported on
- Microsoft Edge version 123, Windows 7 or later
- Template
- msedge.admx
Setting the policy specifies a list of hostnames or hostname patterns (such as '[*.]example.com') that won't be upgraded to HTTPS. Organizations can use this policy to maintain access to servers that don't support HTTPS, without needing to disable 'HttpsUpgradesEnabled' (Enable automatic HTTPS upgrades). Supplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase. Blanket host wildcards (that is, "*" or "[*]") aren't allowed. Instead, HTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their specific policies. Note: This policy doesn't apply to HSTS upgrades. Example value: testserver.example.com [*.]example.org
InAppSupportEnabled In-app support Enabled
If you enable this policy or don't configure it, users can invoke in-app support.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InAppSupportEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- Microsoft Edge uses the in-app support feature (enabled by default) to allow users to contact our support agents directly from the browser. Also, by default, users can't disable (turn off) the in-app support feature.
- Supported on
- Microsoft Edge version 98, Windows 7 or later
- Template
- msedge.admx
Microsoft Edge uses the in-app support feature (enabled by default) to allow users to contact our support agents directly from the browser. Also, by default, users can't disable (turn off) the in-app support feature. If you enable this policy or don't configure it, users can invoke in-app support. If you disable this policy, users can't invoke in-app support.
IntranetRedirectBehavior Intranet Redirection Behavior
If this policy isn't configured, the browser uses the default behavior of DNS interception checks and intranet redirect suggestions.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- IntranetRedirectBehavior
- Stated default
- In M88, they're enabled by default but will be disabled by default in the future release.
- Supported on
- Microsoft Edge version 88, Windows 7 or later
- Template
- msedge.admx
0Use default browser behavior.1Disable DNS interception checks and did-you-mean "http://intranetsite/" infobars.2Disable DNS interception checks; allow did-you-mean "http://intranetsite/" infobars.3Allow DNS interception checks and did-you-mean "http://intranetsite/" infobars.This policy configures behavior for intranet redirection via DNS interception checks. The checks attempt to discover whether the browser is behind a proxy that redirects unknown host names. If this policy isn't configured, the browser uses the default behavior of DNS interception checks and intranet redirect suggestions. In M88, they're enabled by default but will be disabled by default in the future release. 'DNSInterceptionChecksEnabled' (DNS interception checks enabled) is a related policy that might also disable DNS interception checks. However, this policy is a more flexible version which might separately control intranet redirection infobars and might be expanded in the future. If either 'DNSInterceptionChecksEnabled' or this policy make a request to disable interception checks, the checks will be disabled. If DNS interception checks are disabled by this policy but 'GoToIntranetSiteForSingleWordEntryInAddressBar' (Force direct intranet site navigation instead of searching on single word entries in the Address Bar) is enabled, single word queries still result in intranet navigations. Policy options mapping: * Default (0) = Use default browser behavior. * DisableInterceptionChecksDisableInfobar (1) = Disable DNS interception checks and did-you-mean "http://intranetsite/" infobars. * DisableInterceptionChecksEnableInfobar (2) = Disable DNS interception checks; allow did-you-mean "http://intranetsite/" infobars. * EnableInterceptionChecksEnableInfobar (3) = Allow DNS interception checks and did-you-mean "http://intranetsite/" infobars. Use the preceding information when configuring this policy.
UnthrottledNestedTimeoutEnabled JavaScript setTimeout will not be clamped until a higher nesting threshold is set (deprecated)
If you disable or don't configure this policy, the JavaScript setTimeout and setInterval, with an interval smaller than 4 ms, are clamped.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- UnthrottledNestedTimeoutEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 105, Windows 7 or later
- Template
- msedge.admx
DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. This policy is deprecated because it's a temporary policy for web standards compliance. It doesn't work in Microsoft Edge version 107 onward. If you enable this policy, the JavaScript setTimeout and setInterval, with an interval smaller than 4 ms, aren't clamped. This improves short horizon performance; however, websites abusing the API still have their setTimeout usages clamped. If you disable or don't configure this policy, the JavaScript setTimeout and setInterval, with an interval smaller than 4 ms, are clamped. This is a web standards compliancy feature that changes task ordering on a webpage, leading to unexpected behavior on sites that are dependent on a certain ordering. It also affects sites with a lot of usage of a timeout of 0 ms for setTimeout, for example, increasing CPU load.
InternetExplorerSetForegroundWhenActive Keep the active Microsoft Edge window with an Internet Explorer mode tab always in the foreground.
If you disable or don't configure this policy, the active Microsoft Edge window with an Internet Explorer mode tab isn't kept in the foreground.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerSetForegroundWhenActive
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 126, Windows 7 or later
- Template
- msedge.admx
This policy controls whether to always keep the active Microsoft Edge window with an Internet Explorer mode tab in the foreground. If you enable this policy, the active Microsoft Edge window with an Internet Explorer mode tab remains in the foreground. If you disable or don't configure this policy, the active Microsoft Edge window with an Internet Explorer mode tab isn't kept in the foreground. To learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210
AccessibilityImageLabelsEnabled Let screen reader users get image descriptions from Microsoft
If you enable or don't configure this policy, users have the option of using an anonymous Microsoft service.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AccessibilityImageLabelsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 97, Windows 7 or later
- Template
- msedge.admx
Lets screen reader users get descriptions of unlabeled images on the web. If you enable or don't configure this policy, users have the option of using an anonymous Microsoft service. This service provides automatic descriptions for unlabeled images users encounter on the web when they're using a screen reader. If you disable this policy, users can't enable the Get Image Descriptions from Microsoft feature. When this feature is enabled, the content of images that need a generated description is sent to Microsoft servers to generate a description. No cookies or other user data is sent to Microsoft, and Microsoft doesn't save or log any image content.
MathSolverEnabled Let users snip a Math problem and get the solution with a step-by-step explanation in Microsoft Edge (obsolete)
If you enable or don't configure the policy, then a user can take a snip of the Math problem and get the solution including a step-by-step explanation of the solution in a Microsoft Edge side pane.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- MathSolverEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 91-125, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 125. This policy is obsoleted because Math Solver is deprecated from Microsoft Edge. This policy doesn't work in Microsoft Edge version 126. This policy lets you manage whether users can use the Math Solver tool in Microsoft Edge or not. If you enable or don't configure the policy, then a user can take a snip of the Math problem and get the solution including a step-by-step explanation of the solution in a Microsoft Edge side pane. If you disable the policy, the Math Solver tool is disabled and users can't use it. Note: Setting the 'ComponentUpdatesEnabled' (Enable component updates in Microsoft Edge) policy to disabled also disables the Math Solver component.
UserDataSnapshotRetentionLimit Limits the number of user data snapshots retained for use in case of emergency rollback
If you don't configure this policy, the default value of 3 snapshots is used.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- UserDataSnapshotRetentionLimit
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
Following each major version update, Microsoft Edge creates a snapshot of parts of the user's browsing data to use if there's a later emergency that requires a temporary version rollback. If a temporary rollback is performed to a version for which a user has a corresponding snapshot, the data in the snapshot is restored. This restoration lets users retain settings such as bookmarks and autofill data. If you don't configure this policy, the default value of 3 snapshots is used. If you configure this policy, old snapshots are deleted as needed to respect the limit you set. If you set this policy to 0, no snapshots are taken.
AutoOpenFileTypes List of file types that should be automatically opened on download
By default, these file types are automatically opened on all URLs.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\AutoOpenFileTypes
- Supported on
- Microsoft Edge version 85, Windows 7 or later
- Template
- msedge.admx
This policy sets a list of file types that should be automatically opened on download. Note: The leading separator shouldn't be included when listing the file type, so list "txt" instead of ".txt". By default, these file types are automatically opened on all URLs. You can use the 'AutoOpenAllowedForURLs' (URLs where AutoOpenFileTypes can apply) policy to restrict the URLs on which these file types are automatically opened. Files with types that should be automatically opened are still subject to the enabled Microsoft Defender SmartScreen checks and won't be opened if they fail those checks. File types that a user has already specified to automatically be opened continue to do so when downloaded. The user continues to be able to specify other file types to be automatically opened. If you don't set this policy, only file types that a user has already specified to automatically be opened will do so when downloaded. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory or instances that enrolled for device management. Example value: exe txt
DeveloperToolsAvailabilityAllowlist List of URL patterns for which developer tools are allowed to be opened
If you configure this policy and do not configure the 'DeveloperToolsAvailabilityBlocklist' (List of URL patterns for which developer tools are blocked) policy, developer tools are available only when every frame on the page matches a pattern in this allowlist. If you disable or do not configure this policy, developer tools availability is determined by the 'DeveloperToolsAvailabilityBlocklist' and 'DeveloperToolsAvailability' policies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\DeveloperToolsAvailabilityAllowlist
- Supported on
- Microsoft Edge version 148, Windows 7 or later
- Template
- msedge.admx
This policy controls where developer tools can be used in Microsoft Edge by specifying an allowlist of URL patterns. URL patterns are matched against the URL of every frame on the page being inspected. If you configure this policy and do not configure the 'DeveloperToolsAvailabilityBlocklist' (List of URL patterns for which developer tools are blocked) policy, developer tools are available only when every frame on the page matches a pattern in this allowlist. If any frame does not match, developer tools are blocked for the entire page. For information on the URL format, see https://go.microsoft.com/fwlink/?linkid=2095322 . If you configure both this policy and the 'DeveloperToolsAvailabilityBlocklist' policy, this allowlist takes precedence. URLs that match this allowlist are allowed even if they also match the blocklist. URLs that match the blocklist but not this allowlist are blocked. URLs that match neither are governed by the 'DeveloperToolsAvailability' (Control where developer tools can be used) policy. If you disable or do not configure this policy, developer tools availability is determined by the 'DeveloperToolsAvailabilityBlocklist' and 'DeveloperToolsAvailability' policies. This policy applies to developer tools opened for websites, extensions, and web applications. This policy supports up to 1,000 entries. Example value: contoso.com https://ssl.server.com contoso.com/good_path https://server.contoso.com:8080/path .exact.hostname.com file://*
DeveloperToolsAvailabilityBlocklist List of URL patterns for which developer tools are blocked
If you configure this policy and do not configure the 'DeveloperToolsAvailabilityAllowlist' (List of URL patterns for which developer tools are allowed to be opened) policy, developer tools are blocked when any frame matches a pattern in this policy. If you disable or do not configure this policy, developer tools availability is determined by the 'DeveloperToolsAvailabilityAllowlist' and 'DeveloperToolsAvailability' policies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\DeveloperToolsAvailabilityBlocklist
- Supported on
- Microsoft Edge version 148, Windows 7 or later
- Template
- msedge.admx
This policy specifies URL patterns where developer tools are blocked. For information on the URL format, see https://go.microsoft.com/fwlink/?linkid=2095322. URL patterns are evaluated against the URL of every frame on the page being inspected. If any frame matches a pattern in this policy, developer tools are blocked for the entire page. If you configure this policy and do not configure the 'DeveloperToolsAvailabilityAllowlist' (List of URL patterns for which developer tools are allowed to be opened) policy, developer tools are blocked when any frame matches a pattern in this policy. If no frames match, availability is determined by the 'DeveloperToolsAvailability' (Control where developer tools can be used) policy. If you configure both this policy and the 'DeveloperToolsAvailabilityAllowlist' policy, the allowlist takes precedence. URLs that match the allowlist are allowed, even if they also match this policy. URLs that match this policy (but not the allowlist) are blocked. If a URL matches neither, the 'DeveloperToolsAvailability' policy determines availability. If you disable or do not configure this policy, developer tools availability is determined by the 'DeveloperToolsAvailabilityAllowlist' and 'DeveloperToolsAvailability' policies. This policy supports up to 1,000 entries. Example value: https://contoso.com contoso.com https://ssl.server.com contoso.com/bad_path https://server.contoso.com:8080/path .exact.hostname.com * file://*
LiveCaptionsAllowed Live captions allowed
If you enable or don't configure this policy, users can turn on this feature or turn it off at edge://settings/accessibility.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- LiveCaptionsAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 103, Windows 7 or later
- Template
- msedge.admx
Allow users to turn the Live captions feature on or off. Live captions is an accessibility feature that converts speech from the audio that plays in Microsoft Edge into text and shows this text in a separate window. The entire process happens on the device and no audio or caption text ever leaves the device. Note: This feature isn't generally available. Clients that have the 'ExperimentationAndConfigurationServiceControl' (Control communication with the Experimentation and Configuration Service) policy set to 'FullMode' receive the feature before broad availability. Broad availability is announced via Microsoft Edge release notes. If you enable or don't configure this policy, users can turn on this feature or turn it off at edge://settings/accessibility. If you disable this policy, users can't turn on this accessibility feature. If speech recognition files were downloaded previously, they will be deleted from the device in 30 days. We recommend avoiding this option unless it's needed in your environment. If users choose to turn on Live captions, speech recognition files (approximately 100 megabytes) are downloaded to the device on first run and then periodically to improve performance and accuracy. These files will be deleted after 30 days.
EdgeAutofillMlEnabled Machine learning powered autofill suggestions
If you enable this policy or don't configure it, users can benefit from machine learning powered autofill suggestions, which improve efficiency by offering more accurate, context aware form recommendations based on historical autofill data.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeAutofillMlEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 132, Windows 7 or later
- Template
- msedge.admx
Allows ML technology to predict and fill in forms and text fields for better browsing. Your personal data is secure and isn't used elsewhere. If you enable this policy or don't configure it, users can benefit from machine learning powered autofill suggestions, which improve efficiency by offering more accurate, context aware form recommendations based on historical autofill data. If you disable this policy, machine learning-powered autofill suggestions aren't shown, and autofill no longer uses cloud-based machine learning models to enhance form filling with smarter, context aware suggestions. Instead, autofill will rely on basic form data without the benefits of machine learning. This policy will be disabled if you disable 'AutofillAddressEnabled' (Enable AutoFill for addresses).
SharedWorkerBlobURLFixEnabled Make SharedWorker blob URL behavior aligned with the specification
Enabled/Unset: Microsoft Edge inherits the controller for SharedWorker blob URLs, aligning with the specification.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SharedWorkerBlobURLFixEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 134, Windows 7 or later
- Template
- msedge.admx
According to Service Worker specification https://w3c.github.io/ServiceWorker/#control-and-use-worker-client, workers should inherit controllers for blob URLs. Currently, only DedicatedWorkers inherit the controller, while SharedWorkers do not. Enabled/Unset: Microsoft Edge inherits the controller for SharedWorker blob URLs, aligning with the specification. Disabled: Behavior remains unchanged, not aligning with the specification. This policy is temporary and will be removed in a future update.
WebRtcLocalIpsAllowedUrls Manage exposure of local IP addressess by WebRTC
If you disable or don't configure this policy, and edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Enabled, WebRTC will not expose local IP addresses. If you enable, disable, or don't configure this policy, and edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Disabled, WebRTC will expose local IP addresses.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\WebRtcLocalIpsAllowedUrls
- Supported on
- Microsoft Edge version 80, Windows 7 or later
- Template
- msedge.admx
Specifies a list of origins (URLs) or hostname patterns (like "*contoso.com*") for which local IP address should be exposed by WebRTC. If you enable this policy and set a list of origins (URLs) or hostname patterns, when edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Enabled, WebRTC will expose the local IP address for cases that match patterns in the list. If you disable or don't configure this policy, and edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Enabled, WebRTC will not expose local IP addresses. The local IP address is concealed with an mDNS hostname. If you enable, disable, or don't configure this policy, and edge://flags/#enable-webrtc-hide-local-ips-with-mdns is Disabled, WebRTC will expose local IP addresses. Please note that this policy weakens the protection of local IP addresses that might be needed by administrators. Example value: https://www.contoso.com *contoso.com*
EnhanceSecurityModeOptOutUXEnabled Manage opt-out user experience for Enhanced Security Mode (ESM) in Microsoft Edge (obsolete)
If you enable or don't configure this policy, the UI for the opt-out user experience is on.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EnhanceSecurityModeOptOutUXEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 115-135, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 135. This policy is obsolete because we determined that this experimental opt-out UX isn't required. This policy lets you manage whether the opt-out user experience for enhanced security mode is presented when ESM is turned on for Microsoft Edge. If you enable or don't configure this policy, the UI for the opt-out user experience is on. If you disable this policy, the UI for the opt-out user experience is off. Note: If this policy is used, only the User Interface for the opt-out experience is supressed - ESM is still turned on. For more information, see the 'EnhanceSecurityMode' (Enhance the security state in Microsoft Edge) policy. For detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895.
QuickViewOfficeFilesEnabled Manage QuickView Office files capability in Microsoft Edge
(For example: Word documents, PowerPoint presentations, and Excel spreadsheets) If you enable or don't configure this policy, these files can be viewed in Microsoft Edge using Office Viewer instead of downloading the files.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- QuickViewOfficeFilesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 90, Windows 7 or later
- Template
- msedge.admx
Allows you to set whether users can view publicly accessible Office files on the web that aren't on OneDrive or SharePoint. (For example: Word documents, PowerPoint presentations, and Excel spreadsheets) If you enable or don't configure this policy, these files can be viewed in Microsoft Edge using Office Viewer instead of downloading the files. If you disable this policy, these files are downloaded to be viewed.
ManagedSearchEngines Manage Search Engines
If you disable or don't configure this policy, users can modify the search engines list as desired.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ManagedSearchEngines
- Stated default
- If allow_search_engine_discovery isn't specified, search engine discovery is disabled by default.
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Lets you configure a list of up to 10 search engines, one of which must be marked as the default search engine. With Microsoft Edge version 100, you can configure up to 100 engines. You don't need to specify the encoding. With Microsoft Edge version 80, the suggest_url and image_search_url parameters are optional. The optional parameter, image_search_post_params (consists of comma-separated name/value pairs), is available starting in Microsoft Edge version 80. With Microsoft Edge version 83, you can enable search engine discovery with the optional allow_search_engine_discovery parameter. This parameter must be the first item in the list. If allow_search_engine_discovery isn't specified, search engine discovery is disabled by default. With Microsoft Edge version 84, you can set this policy as a recommended policy to allow search provider discovery. You don't need to add the optional allow_search_engine_discovery parameter. With Microsoft Edge version 100, setting this policy as a recommended policy also allows users to manually add new search engines from their Microsoft Edge settings. If you enable this policy, users can't add, remove, or change any search engine in the list. Users can set their default search engine to any search engine in the list. If you disable or don't configure this policy, users can modify the search engines list as desired. If the 'DefaultSearchProviderSearchURL' (Default search provider search URL) policy is set, this policy (ManagedSearchEngines) is ignored. The user must restart their browser to finish applying this policy. Example value: [ { "allow_search_engine_discovery": true }, { "is_default": true, "keyword": "example1.com", "name": "Example1", "search_url": "https://www.example1.com/search?q={searchTerms}", "suggest_url": "https://www.example1.com/qbox?query={searchTerms}" }, { "image_search_post_params": "content={imageThumbnail},url={imageURL},sbisrc={SearchSource}", "image_search_url": "https://www.example2.com/images/detail/search?iss=sbiupload", "keyword": "example2.com", "name": "Example2", "search_url": "https://www.example2.com/search?q={searchTerms}", "suggest_url": "https://www.example2.com/qbox?query={searchTerms}" }, { "encoding": "UTF-8", "image_search_url": "https://www.example3.com/images/detail/search?iss=sbiupload", "keyword": "example3.com", "name": "Example3", "search_url": "https://www.example3.com/search?q={searchTerms}", "suggest_url": "https://www.example3.com/qbox?query={searchTerms}" }, { "keyword": "example4.com", "name": "Example4", "search_url": "https://www.example4.com/search?q={searchTerms}" } ]
EnhanceSecurityModeIndicatorUIEnabled Manage the indicator UI of the Enhanced Security Mode (ESM) feature in Microsoft Edge
If you enable or don't configure this policy, the indicator UI is on.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EnhanceSecurityModeIndicatorUIEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 115, Windows 7 or later
- Template
- msedge.admx
This policy manages whether the indicator User Interface (UI) for enhanced security mode is shown or not when ESM is on. If you enable or don't configure this policy, the indicator UI is on. If you disable this policy, the indicator UI is off. Note: If this policy is used, only the indicator User Interface experience is supressed - ESM is still turned on. For more information, see the 'EnhanceSecurityMode' (Enhance the security state in Microsoft Edge) policy. For detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895
MaxConnectionsPerProxy Maximum number of concurrent connections to the proxy server for non-WebSocket requests
If you don't configure this policy, the default value of 128 is used.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- MaxConnectionsPerProxy
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
This policy configures the maximum number of simultaneous connections to a proxy server. Some web applications maintain multiple long-lived connections, such as hanging GET requests. Setting this policy to a value lower than the default might cause browser networking issues when many of these applications are open. To configure WebSocket request limits, use the 'MaxConnectionsPerProxyForWebSocket' (Maximum number of concurrent connections to the proxy server for WebSocket requests) policy. If you don't configure this policy, the default value of 128 is used. The value must be between 6 and 256: - Values lower than 6 are treated as 6. - Values higher than 256 are treated as 256. In Microsoft Edge version 148 and earlier, values higher than 99 are treated as 99. When the 'AllowSocketPoolSizeRandomizationForProxies' (Allow socket pool size randomization for proxies) policy is enabled, which is the default, the effective upper limit can be randomized up to two times the value specified by this policy as a security mechanism. We recommend changing this value from the default only when required by your proxy server configuration.
MaxConnectionsPerProxyForWebSocket Maximum number of concurrent connections to the proxy server for WebSocket requests
If you don't configure this policy, the default value of 128 is used.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- MaxConnectionsPerProxyForWebSocket
- Supported on
- Microsoft Edge version 148, Windows 7 or later
- Template
- msedge.admx
Specifies the maximum number of simultaneous connections to a proxy server for WebSocket requests. To configure limits for non-WebSocket requests, see the 'MaxConnectionsPerProxy' (Maximum number of concurrent connections to the proxy server for non-WebSocket requests) policy. If you don't configure this policy, the default value of 128 is used. Some web applications maintain multiple concurrent connections, such as long-lived or hanging requests. Setting a value lower than the default can cause networking delays when many of these applications are open. Some proxy servers can't handle a high number of concurrent connections per client. In these cases, reducing this value might improve reliability. The supported range is 6 to 256: - Values less than 6 are treated as 6. - Values greater than 256 are treated as 256. When the 'AllowSocketPoolSizeRandomizationForProxies' (Allow socket pool size randomization for proxies) policy is enabled, which is the default, the effective upper limit can be randomized up to 2x the value specified by this policy as a security mechanism. We recommend modifying this value only if required by your proxy server configuration or network environment.
NewPDFReaderEnabled Microsoft Edge built-in PDF reader powered by Adobe Acrobat enabled
If you disable or don't configure this policy, Microsoft Edge will use the existing PDF reader to open all PDF files.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NewPDFReaderEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 111, Windows 7 or later
- Template
- msedge.admx
The policy lets Microsoft Edge launch the new version of the built-in PDF reader that's powered by Adobe Acrobat's PDF rendering engine. The new PDF reader ensures that there's no loss of functionality and delivers an enhanced PDF experience. This experience includes richer rendering, improved performance, strong security for PDF handling, and greater accessibility. If you enable this policy, Microsoft Edge will use the new Adobe Acrobat powered built-in PDF reader to open all PDF files. If you disable or don't configure this policy, Microsoft Edge will use the existing PDF reader to open all PDF files.
MicrosoftEdgeInsiderPromotionEnabled Microsoft Edge Insider Promotion Enabled
If you enable or don't configure this policy, the Microsoft Edge Insider promotion content is shown on the About Microsoft Edge page.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- MicrosoftEdgeInsiderPromotionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 98, Windows 7 or later
- Template
- msedge.admx
Shows content promoting the Microsoft Edge Insider channels on the About Microsoft Edge settings page. If you enable or don't configure this policy, the Microsoft Edge Insider promotion content is shown on the About Microsoft Edge page. If you disable this policy, the Microsoft Edge Insider promotion content isn't shown on the About Microsoft Edge page.
SSLVersionMin Minimum TLS version enabled (obsolete)
If you don't configure this policy, Microsoft Edge still shows an error for TLS 1.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SSLVersionMin
- Supported on
- Microsoft Edge version 77-97, Windows 7 or later
- Template
- msedge.admx
TLS 1.0TLS 1.1TLS 1.2OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 97. This policy was removed in Microsoft Edge 98 and is ignored if configured. Sets the minimum supported version of TLS. If you set this policy to 'tls1.2', Microsoft Edge shows an error for TLS 1.0 and TLS 1.1, and the user won't be able to bypass the error. If you don't configure this policy, Microsoft Edge still shows an error for TLS 1.0 and TLS 1.1 but the user will be able to bypass it. Support for suppressing the TLS 1.0/1.1 warning was removed from Microsoft Edge starting in version 91. The 'tls1' and 'tls1.1' values are no longer supported. Policy options mapping: * TLSv1 (tls1) = TLS 1.0 * TLSv1.1 (tls1.1) = TLS 1.1 * TLSv1.2 (tls1.2) = TLS 1.2 Use the preceding information when configuring this policy. Example value: tls1
MouseGestureEnabled Mouse Gesture Enabled
If you enable or don't configure this policy, you can use the Mouse Gesture feature on Microsoft Edge to start using this feature.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- MouseGestureEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 112, Windows 7 or later
- Template
- msedge.admx
This policy lets you configure the Mouse Gesture feature in Microsoft Edge. This feature provides an easy way for users to complete tasks like scroll forward or backward, open new tab, refresh page, etc. They can finish a task by pressing and holding the mouse right button to draw certain patterns on a webpage, instead of clicking the buttons or using keyboard shortcuts. If you enable or don't configure this policy, you can use the Mouse Gesture feature on Microsoft Edge to start using this feature. If you disable this policy, you can't use the Mouse Gesture feature in Microsoft Edge.
RelaunchNotification Notify a user that a browser restart is recommended or required for pending updates
If you don't configure this policy, Microsoft Edge adds a recycle icon at the far right of the top menu bar to prompt users to restart the browser to apply the update.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RelaunchNotification
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
1Recommended - Show a recurring prompt to the user indicating that a restart is recommended2Required - Show a recurring prompt to the user indicating that a restart is requiredNotify users that they need to restart Microsoft Edge to apply a pending update. If you don't configure this policy, Microsoft Edge adds a recycle icon at the far right of the top menu bar to prompt users to restart the browser to apply the update. If you enable this policy and set it to 'Recommended', a recurring warning prompts users that a restart is recommended. Users can dismiss this warning and defer the restart. If you set the policy to 'Required', a recurring warning prompts users that the browser will be restarted automatically as soon as a notification period passes. The default period is seven days. You can configure this period with the 'RelaunchNotificationPeriod' (Set the time period for update notifications) policy. The user's session is restored when the browser restarts. Policy options mapping: * Recommended (1) = Recommended - Show a recurring prompt to the user indicating that a restart is recommended * Required (2) = Required - Show a recurring prompt to the user indicating that a restart is required Use the preceding information when configuring this policy.
InternetExplorerIntegrationLocalFileExtensionAllowList Open local files in Internet Explorer mode file extension allow list
If you set this policy to the special value "*" or don't configure it, all file extensions are allowed.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\InternetExplorerIntegrationLocalFileExtensionAllowList
- Supported on
- Microsoft Edge version 88, Windows 7 or later
- Template
- msedge.admx
This policy limits which file:// URLs are allowed to launch into Internet Explorer mode based on file extension. This setting works when 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'. When a file:// URL is requested to launch in Internet Explorer mode, the file extension of the URL must be present in this list for the URL to be allowed to launch in Internet Explorer mode. A URL that's blocked from opening in Internet Explorer mode is instead opened in Microsoft Edge mode. If you set this policy to the special value "*" or don't configure it, all file extensions are allowed. To learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210 Example value: .mht .pdf .vsdx
OriginAgentClusterDefaultEnabled Origin-keyed agent clustering enabled by default
If you enable or don't configure this policy, documents without the Origin-Agent-Cluster: header are assigned to origin-keyed agent clustering by default.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- OriginAgentClusterDefaultEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- If you enable or don't configure this policy, documents without the Origin-Agent-Cluster: header are assigned to origin-keyed agent clustering by default. If you disable this policy, documents without the Origin-Agent-Cluster: header are assigned to site-keyed agent clusters by default.
- Supported on
- Microsoft Edge version 103, Windows 7 or later
- Template
- msedge.admx
The Origin-Agent-Cluster: HTTP header controls whether a document is isolated in an origin-keyed agent cluster or in a site-keyed agent cluster. This functionality has security implications because an origin-keyed agent cluster allows isolating documents by origin. The consequence of this for developers is that the document.domain accessor can no longer be set when origin-keyed agent clustering is enabled. If you enable or don't configure this policy, documents without the Origin-Agent-Cluster: header are assigned to origin-keyed agent clustering by default. On these documents, the document.domain accessor isn't settable. If you disable this policy, documents without the Origin-Agent-Cluster: header are assigned to site-keyed agent clusters by default. On these documents, the document.domain accessor is settable. For more information, see https://go.microsoft.com/fwlink/?linkid=2191896.
CpuPerformanceTierOverride Override for the CPU performance tier
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- CpuPerformanceTierOverride
- Supported on
- Microsoft Edge version 149, Windows 7 or later
- Template
- msedge.admx
This policy allows you to override the value returned by the CPU Performance API (that is, navigator.cpuPerformance). If you enable this policy, the value of navigator.cpuPerformance is overridden with the specified value. If you don’t configure this policy, the default performance tier calculation is used. You can specify a value from 0 through 4. For more information, see https://github.com/WICG/cpu-performance.
PersonalizeTopSitesInCustomizeSidebarEnabled Personalize my top sites in Customize Sidebar enabled by default
If you don't configure this policy, the default behavior is to use the browsing history to personalize the top sites in the customize sidebar page.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PersonalizeTopSitesInCustomizeSidebarEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 132, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Microsoft Edge browser be allowed to use the browsing history to personalize the top sites in the customize sidebar page. If you enable this policy, Microsoft Edge uses the browsing history to personalize the top sites in the customize sidebar page. If you disable this policy, Microsoft Edge doesn't use the browsing history to personalize the top sites in the customize sidebar page. If you don't configure this policy, the default behavior is to use the browsing history to personalize the top sites in the customize sidebar page.
RedirectSitesFromInternetExplorerPreventBHOInstall Prevent install of the BHO to redirect incompatible sites from Internet Explorer to Microsoft Edge
If you disable or don't configure this policy, the BHO is installed.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RedirectSitesFromInternetExplorerPreventBHOInstall
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 87, Windows 7 or later
- Template
- msedge.admx
This setting lets you specify whether to block the installation of the Browser Helper Object (BHO) that enables redirecting incompatible sites from Internet Explorer to Microsoft Edge for sites that require a modern browser. If you enable this policy, the BHO isn't installed. If it's already installed, it will be uninstalled on the next Microsoft Edge update. If you disable or don't configure this policy, the BHO is installed. The BHO is required for incompatible site redirection to occur; however, whether redirection occurs or not is also controlled by 'RedirectSitesFromInternetExplorerRedirectMode' (Redirect incompatible sites from Internet Explorer to Microsoft Edge). For more information about this policy, see https://go.microsoft.com/fwlink/?linkid=2141715.
PromptOnMultipleMatchingCertificates Prompt the user to select a certificate when multiple certificates match
If this policy is set to False or not set, the user may only be prompted when no certificate matches the auto-selection.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PromptOnMultipleMatchingCertificates
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 100, Windows 7 or later
- Template
- msedge.admx
This policy controls whether the user is prompted to select a client certificate when more than one certificate matches 'AutoSelectCertificateForUrls' (Automatically select client certificates for these sites). If this policy is set to True, the user is prompted to select a client certificate whenever the auto-selection policy matches multiple certificates. If this policy is set to False or not set, the user may only be prompted when no certificate matches the auto-selection.
EnableDeprecatedWebPlatformFeatures Re-enable deprecated web platform features for a limited time (obsolete)
If you don't configure this policy, if the list is empty, or if a feature doesn't match one of the supported string tags, all deprecated web platform features remain disabled.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\EnableDeprecatedWebPlatformFeatures
- Supported on
- Microsoft Edge version 77-86, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 86. This policy is obsolete because dedicated web platform policies are now used to manage individual web platform feature deprecations. Specify a list of deprecated web platform features to temporarily re-enable. This policy lets you re-enable deprecated web platform features for a limited time. Features are identified by a string tag. If you don't configure this policy, if the list is empty, or if a feature doesn't match one of the supported string tags, all deprecated web platform features remain disabled. While the policy itself is supported on the above platforms, the feature it's enabling might not be available on all of those platforms. Not all deprecated Web Platform features can be re-enabled. Only the following explicitly listed features can be re-enabled, and only for a limited period of time, which differs per feature. You can review the intent behind the Web Platform feature changes at https://bit.ly/blinkintents. The general format of the string tag is [DeprecatedFeatureName]_EffectiveUntil[yyyymmdd]. Policy options mapping: * ExampleDeprecatedFeature (ExampleDeprecatedFeature_EffectiveUntil20080902) = Enable ExampleDeprecatedFeature API through 2008/09/02 Use the preceding information when configuring this policy. Example value: ExampleDeprecatedFeature_EffectiveUntil20080902
EventPathEnabled Re-enable the Event.path API until Microsoft Edge version 115 (obsolete)
If you don't configure this policy, the Event.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EventPathEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 107-115, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 115. Starting in Microsoft Edge version 109, the nonstandard API Event.path is removed to improve web compatibility. This policy re-enables the API until version 115. If you enable this policy, the Event.path API is available. If you disable this policy, the Event.path API is unavailable. If you don't configure this policy, the Event.path API is in the following default states: available before version 109, and unavailable in version 109 to version 114. This policy is made obsolete after Microsoft Edge version 115.
WebComponentsV0Enabled Re-enable Web Components v0 API until M84 (obsolete)
The Web Components v0 APIs (Shadow DOM v0, Custom Elements v0, and HTML Imports) were deprecated in 2018, and are disabled by default starting in Microsoft Edge version 80. If you set this policy to False or don't set this policy, the Web Components v0 features are disabled by default, starting in Microsoft Edge version 80.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebComponentsV0Enabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 80-84, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 84. This policy doesn't work because this policy allowed these features to be selectively re-enabled until Microsoft Edge version 85. The Web Components v0 APIs (Shadow DOM v0, Custom Elements v0, and HTML Imports) were deprecated in 2018, and are disabled by default starting in Microsoft Edge version 80. If you set this policy to True, the Web Components v0 features are enabled for all sites. If you set this policy to False or don't set this policy, the Web Components v0 features are disabled by default, starting in Microsoft Edge version 80.
RedirectSitesFromInternetExplorerRedirectMode Redirect incompatible sites from Internet Explorer to Microsoft Edge
If you don't configure this policy: - Starting with Microsoft Edge major release 87, you have the same experience as setting the policy to 'Sitelist': Internet Explorer redirects sites that require a modern browser to Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RedirectSitesFromInternetExplorerRedirectMode
- Supported on
- Microsoft Edge version 87, Windows 7 or later
- Template
- msedge.admx
0Prevent redirection1Redirect sites based on the incompatible sites sitelistThis setting lets you specify whether Internet Explorer redirects navigations to sites that require a modern browser to Microsoft Edge. If you set this policy to 'Disable' ('Prevent redirection', value 0), Internet Explorer doesn't redirect any traffic to Microsoft Edge. If you set this policy to 'Sitelist', starting with Microsoft Edge major release 87, Internet Explorer (IE) redirects sites that require a modern browser to Microsoft Edge. (Note: The Sitelist setting is 'Redirect sites based on the incompatible sites sitelist', value 1.) When a site is redirected from Internet Explorer to Microsoft Edge, the Internet Explorer tab that started loading the site is closed if it had no prior content. Otherwise, the user is taken to a Microsoft help page that explains why the site was redirected to Microsoft Edge. When Microsoft Edge is launched to load an IE site, an information bar explains that the site works best in a modern browser. If you want to redirect all navigations, configure the Disable Internet Explorer 11 policy, which redirects all navigations from IE11 to Microsoft Edge. It also hides the IE11 app icon from the user after the first launch. If you don't configure this policy: - Starting with Microsoft Edge major release 87, you have the same experience as setting the policy to 'Sitelist': Internet Explorer redirects sites that require a modern browser to Microsoft Edge. - In the future, the default for your organization changes to automatically redirect all navigations. If you don't want automatic redirection, set this policy to 'Disable' or 'Sitelist'. For more information about this policy, see https://go.microsoft.com/fwlink/?linkid=2141715. Policy options mapping: * Disable (0) = Prevent redirection * Sitelist (1) = Redirect sites based on the incompatible sites sitelist Use the preceding information when configuring this policy.
RelaunchFastIfOutdated Relaunch browser quickly when the current version is outdated
If not set, or if the release age can't be determined, the RelaunchNotificationPeriod policy is used for all updates.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RelaunchFastIfOutdated
- Supported on
- Microsoft Edge version 141, Windows 7 or later
- Template
- msedge.admx
This policy specifies the minimum release age after which relaunch notifications become more aggressive. The release age is calculated from the time the currently running version was last served to clients. If a browser relaunch is needed to finalize a pending update and the current version is outdated for more than the number of days specified by this setting, the RelaunchNotificationPeriod policy is overridden to 2 hours. If the RelaunchNotification policy is set to 1 ('Required'), a browser relaunch is forced at the end of the period. If not set, or if the release age can't be determined, the RelaunchNotificationPeriod policy is used for all updates.
DelayNavigationsForInitialSiteListDownload Require that the Enterprise Mode Site List is available before tab navigation
If you set this policy to 'None' or don't configure it and when Microsoft Edge doesn't have a cached version of the Enterprise Mode Site List, tabs navigate immediately and don't wait for the browser to download the Enterprise Mode Site List.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DelayNavigationsForInitialSiteListDownload
- Supported on
- Microsoft Edge version 84, Windows 7 or later
- Template
- msedge.admx
0None1All eligible navigationsLets you specify whether Microsoft Edge tabs wait to navigate until the browser downloaded the initial Enterprise Mode Site List. This setting is intended for the scenario where the browser home page should load in Internet Explorer (IE) mode, and it's important that it does so on browser first run after IE mode is enabled. If this scenario doesn't exist, we recommend not enabling this setting because it negatively impacts the performance of loading the home page. The setting only applies when Microsoft Edge doesn't have a cached Enterprise Mode Site List, such as on browser first run after IE mode is enabled. This setting works if 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode' and if either the 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) or the 'InternetExplorerIntegrationCloudSiteList' (Configure the Enterprise Mode Cloud Site List) policies be enabled, where the list has at least one entry. The timeout behavior of this policy is configured with the 'NavigationDelayForInitialSiteListDownloadTimeout' (Set a timeout for delay of tab navigation for the Enterprise Mode Site List) policy. If you set this policy to 'All' and when Microsoft Edge doesn't have a cached version of the Enterprise Mode Site List, tabs delay navigating until the browser downloaded the site list. Sites configured to open in Internet Explorer mode by the site list load in Internet Explorer mode, even during the initial navigation of the browser. Sites that can't be configured to open in Internet Explorer, such as any site with a scheme other than http:, https:, file:, or ftp: don't delay navigating and load immediately in Microsoft Edge mode. When used with the 'InternetExplorerIntegrationCloudSiteList' policy, during first launch of Microsoft Edge, there is a delay because implicit sign in needs to finish before Microsoft Edge attempts to download the site list from the Microsoft cloud since this requires authentication to the cloud service. If you set this policy to 'None' or don't configure it and when Microsoft Edge doesn't have a cached version of the Enterprise Mode Site List, tabs navigate immediately and don't wait for the browser to download the Enterprise Mode Site List. Sites configured to open in Internet Explorer mode by the site list open in Microsoft Edge mode until the browser finished downloading the Enterprise Mode Site List. Policy options mapping: * None (0) = None * All (1) = All eligible navigations Use the preceding information when configuring this policy.
RestorePdfView Restore PDF view
If you enable or don't configure this policy, Microsoft Edge recovers the last state of PDF view and lands users to the section where they ended reading in the last session.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RestorePdfView
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 113, Windows 7 or later
- Template
- msedge.admx
Enables PDF View Recovery in Microsoft Edge. If you enable or don't configure this policy, Microsoft Edge recovers the last state of PDF view and lands users to the section where they ended reading in the last session. If you disable this policy, Microsoft Edge recovers the last state of PDF view and lands users at the start of the PDF file.
RestrictBackgroundFetchFromServiceWorkerEnabled Restrict Background Fetch API when called from a Service Worker
If you enable this policy or don't configure it, the restriction is active, and background fetch requests from Service Worker contexts may be blocked.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RestrictBackgroundFetchFromServiceWorkerEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 149, Windows 7 or later
- Template
- msedge.admx
This policy controls whether background fetch requests from Service Workers are restricted. If a feature that downloads files in the background is affected, this policy may be relevant. If you enable this policy or don't configure it, the restriction is active, and background fetch requests from Service Worker contexts may be blocked. If you disable this policy, the restriction is bypassed, allowing Service Workers to make background fetch requests. This policy is temporary and will be removed after Microsoft Edge version 152.
RestrictCoreSharingOnRenderer Restrict CPU core sharing for renderer process
If you don't configure this policy, other processes can be scheduled on the same core as the renderer process.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RestrictCoreSharingOnRenderer
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 140, Windows 7 or later
- Template
- msedge.admx
This policy helps mitigate side-channel cross-process memory attacks by isolating the renderer process to a dedicated CPU core, preventing other processes from being scheduled on the same core. This mitigation is supported on Microsoft® Windows® 11 24H2 and later. If the operating system doesn't support the necessary scheduling features, this policy has no effect. Enabling this policy may reduce performance in demanding workloads, similar to the impact of disabling hyperthreading. For more information, refer https://learn.microsoft.com/windows/win32/api/winnt/ns-winnt-process_mitigation_side_channel_isolation_policy If you enable this policy, other processes can't be scheduled on the same CPU core as a renderer process. If you disable this policy, other processes can be scheduled on the same CPU core as a renderer process. If you don't configure this policy, other processes can be scheduled on the same core as the renderer process. Behavior can vary depending on Microsoft Edge version and platform.
WebRtcUdpPortRange Restrict the range of local UDP ports used by WebRTC
If you don't configure this policy, or if you set it to an empty string or invalid port range, WebRTC can use any available local UDP port.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebRtcUdpPortRange
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Restricts the UDP port range used by WebRTC to a specified port interval (endpoints included). By configuring this policy, you specify the range of local UDP ports that WebRTC can use. If you don't configure this policy, or if you set it to an empty string or invalid port range, WebRTC can use any available local UDP port. Example value: 10000-11999
RestrictSigninToPattern Restrict which accounts can be used to sign in to Microsoft Edge
If you don't configure this policy or leave it blank, users can use any account to sign in to Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RestrictSigninToPattern
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Determines which accounts can be used to sign in to the Microsoft Edge account that's chosen during the Sync opt-in flow. You can configure this policy to match multiple accounts using a Perl style regular expression for the pattern. If a user tries to sign in to the browser with an account whose username doesn't match this pattern, they're blocked and will get the appropriate error message. Pattern matches are case sensitive. For more information about the regular expression rules that are used, see https://go.microsoft.com/fwlink/p/?linkid=2133903. If you don't configure this policy or leave it blank, users can use any account to sign in to Microsoft Edge. Signed-in profiles with a username that doesn't match this pattern will be signed out after this policy is enabled. Example value: .*@contoso.com
AutofillMembershipsEnabled Save and fill memberships
If you don't configure this policy, users can choose whether to have their membership info automatically saved and used to fill form fields while using Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AutofillMembershipsEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, users can choose whether to enable it or not.
- Supported on
- Microsoft Edge version 110, Windows 7 or later
- Template
- msedge.admx
This policy lets you decide whether users can have their membership info (for example, program name and membership number) automatically saved and used to fill form fields while using Microsoft Edge. By default, users can choose whether to enable it or not. If you enable this policy, users can only have their membership info automatically saved and used to fill form fields while using Microsoft Edge. If you don't configure this policy, users can choose whether to have their membership info automatically saved and used to fill form fields while using Microsoft Edge. If you disable this policy, users can't have their membership info automatically saved and used to fill form fields while using Microsoft Edge.
SaveCookiesOnExit Save cookies when Microsoft Edge closes
If you disable or don't configure this policy, the user's personal configuration is used.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\SaveCookiesOnExit
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
When this policy is enabled, the specified set of cookies is exempt from deletion when the browser closes. This policy is only effective when: - The 'Cookies and other site data' toggle is configured in Settings/Privacy and services/Clear browsing data on close or - The policy 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) is enabled or - The policy 'DefaultCookiesSetting' (Configure cookies) is set to 'Keep cookies for the duration of the session'. You can define a list of sites, based on URL patterns, that have their cookies preserved across sessions. Note: Users can still edit the cookie site list to add or remove URLs. However, they can't remove URLs that are added by an Admin. If you enable this policy, the list of cookies aren't cleared when the browser closes. If you disable or don't configure this policy, the user's personal configuration is used. Example value: https://www.contoso.com [*.]contoso.edu
SearchFiltersEnabled Search Filters Enabled
If you enable or don't configure this policy, the autosuggestion dropdown defaults to displaying the ribbon of available filters.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SearchFiltersEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 109, Windows 7 or later
- Template
- msedge.admx
Lets you filter your autosuggestions by selecting a filter from the search filters ribbon. For example, if you select the "Favorites" filter, only favorites suggestions are shown. If you enable or don't configure this policy, the autosuggestion dropdown defaults to displaying the ribbon of available filters. If you disable this policy, the autosuggestion dropdown can't display the ribbon of available filters.
SearchForImageEnabled Search for image enabled
If you enable or don't configure this policy, then the "Search the web for image" option is visible in the context menu.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SearchForImageEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 115, Windows 7 or later
- Template
- msedge.admx
This policy lets you configure the Image Search feature in the right-click context menu. If you enable or don't configure this policy, then the "Search the web for image" option is visible in the context menu. If you disable this policy, then the "Search the web for image" won't be visible in the context menu.
SearchInSidebarEnabled Search in Sidebar enabled
If you configure this policy to 'EnableSearchInSidebar' or don't configure it, Search in sidebar is enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SearchInSidebarEnabled
- Supported on
- Microsoft Edge version 110, Windows 7 or later
- Template
- msedge.admx
0Enable search in sidebar1Disable search in sidebar for Kids Mode2Disable search in sidebarSearch in Sidebar allows users to open search result in sidebar (including sidebar search for Progressive Web Apps). If you configure this policy to 'EnableSearchInSidebar' or don't configure it, Search in sidebar is enabled. If you configure this policy to 'DisableSearchInSidebarForKidsMode', Search in sidebar is disabled when in Kids mode. Some methods that would normally invoke sidebar search will invoke a traditional search instead. If you configure this policy to 'DisableSearchInSidebar', Search in sidebar is disabled. Some methods that would invoke sidebar search invoke a traditional search instead. Policy options mapping: * EnableSearchInSidebar (0) = Enable search in sidebar * DisableSearchInSidebarForKidsMode (1) = Disable search in sidebar for Kids Mode * DisableSearchInSidebar (2) = Disable search in sidebar Use the preceding information when configuring this policy.
PDFSecureMode Secure mode and Certificate-based Digital Signature validation in native PDF reader
If you disable or don't configure this policy, the capability to view and verify the signature isn't available.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PDFSecureMode
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 100, Windows 7 or later
- Template
- msedge.admx
The policy enables Digital Signature validation for PDF files in a secure environment, which shows the correct validation status of the signatures. If you enable this policy, PDF files with Certificate-based digital signatures are opened with an option to view and verify the validity of the signatures with high security. If you disable or don't configure this policy, the capability to view and verify the signature isn't available.
SendIntranetToInternetExplorer Send all intranet sites to Internet Explorer
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SendIntranetToInternetExplorer
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210
DiagnosticData Send required and optional diagnostic data about browser usage
If you don't configure this policy or disable it, Microsoft Edge defaults to the user's preference.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DiagnosticData
- Supported on
- Microsoft Edge version 122, Windows 7 or later
- Template
- msedge.admx
0Off (Not recommended)1Required data2Optional dataThis policy controls sending required and optional diagnostic data about browser usage to Microsoft. Required diagnostic data is collected to keep Microsoft Edge secure, up to date and performing as expected. Optional diagnostic data includes data about how you use the browser, websites you visit, and crash reports to Microsoft for product and service improvement. Up to Microsoft Edge version 121, this policy isn't supported on Windows 10 devices. To control this data collection on Windows 10 for 121 and previous, IT admins must use the Windows diagnostic data group policy. This policy can either be 'Allow Telemetry' or 'Allow Diagnostic Data', depending on the version of Windows. Learn more about Windows 10 diagnostic data collection: https://go.microsoft.com/fwlink/?linkid=2099569 For Microsoft Edge version 122 and later, this policy is supported on Windows 10 devices to allow controlling Microsoft Edge data collection separately from Windows 10 diagnostics data collection. Use one of the following settings to configure this policy: 'Off' turns off required and optional diagnostic data collection. This option isn't recommended. 'RequiredData' sends required diagnostic data but turns off optional diagnostic data collection. Microsoft Edge sends required diagnostic data to keep Microsoft Edge secure, up to date and performing as expected. 'OptionalData' sends optional diagnostic data includes data about browser usage, websites that are visited, crash reports sent to Microsoft for product and service improvement. On Windows 7/macOS, this policy controls sending required and optional data to Microsoft. If you don't configure this policy or disable it, Microsoft Edge defaults to the user's preference. Policy options mapping: * Off (0) = Off (Not recommended) * RequiredData (1) = Required data * OptionalData (2) = Optional data Use the preceding information when configuring this policy.
SendSiteInfoToImproveServices Send site information to improve Microsoft services (obsolete)
On Windows 10, if you don't configure this policy, Microsoft Edge defaults to the Windows diagnostic data setting. If you don't configure this policy, Microsoft Edge defaults to the user's preference.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SendSiteInfoToImproveServices
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77-88, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 88. This policy is no longer supported. It's replaced by 'DiagnosticData' (Send required and optional diagnostic data about browser usage) (for Windows 7, Windows 8, and macOS) and Allow Telemetry on Win 10 ([https://go.microsoft.com/fwlink/?linkid=2099569](https://go.microsoft.com/fwlink/?linkid=2099569)). This policy enables sending info about websites visited in Microsoft Edge to Microsoft to improve services like search. Enable this policy to send info about websites visited in Microsoft Edge to Microsoft. Disable this policy to not send info about websites visited in Microsoft Edge to Microsoft. In both cases, users can't change or override the setting. On Windows 10, if you don't configure this policy, Microsoft Edge defaults to the Windows diagnostic data setting. If this policy is enabled Microsoft Edge only sends info about websites visited in Microsoft Edge if the Windows Diagnostic data setting is set to Full. If this policy is disabled Microsoft Edge won't send info about websites visited. Learn more about Windows Diagnostic data settings: ([https://go.microsoft.com/fwlink/?linkid=2099569](https://go.microsoft.com/fwlink/?linkid=2099569)). On Windows 7, windows 8, and macOS, this policy controls sending info about websites visited. If you don't configure this policy, Microsoft Edge defaults to the user's preference. To enable this policy, 'MetricsReportingEnabled' (Enable usage and crash-related data reporting) must be set to Enabled. If 'SendSiteInfoToImproveServices' (Send site information to improve Microsoft services) or 'MetricsReportingEnabled' is Not Configured or Disabled, this data won't be sent to Microsoft.
NavigationDelayForInitialSiteListDownloadTimeout Set a timeout for delay of tab navigation for the Enterprise Mode Site List
If you don't configure this policy, the default timeout of 4 seconds is used.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NavigationDelayForInitialSiteListDownloadTimeout
- Supported on
- Microsoft Edge version 84, Windows 7 or later
- Template
- msedge.admx
Allows you to set a timeout, in seconds, for Microsoft Edge tabs waiting to navigate until the browser has downloaded the initial Enterprise Mode Site List. This setting works in conjunction with: 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode' and 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy where the list has at least one entry and 'DelayNavigationsForInitialSiteListDownload' (Require that the Enterprise Mode Site List is available before tab navigation) is set to "All eligible navigations" (1). Tabs won't wait longer than this timeout for the Enterprise Mode Site List to download. If the browser hasn't finished downloading the Enterprise Mode Site List when the timeout expires, Microsoft Edge tabs continue navigating anyway. The value of the timeout should be no greater than 20 seconds and no fewer than 1 second. If you set the timeout in this policy to a value greater than 2 seconds, an information bar is shown to the user after 2 seconds. The information bar contains a button that allows the user to quit waiting for the Enterprise Mode Site List download to complete. If you don't configure this policy, the default timeout of 4 seconds is used. This default is subject to change in the future.
ApplicationLocaleValue Set application locale
If you disable or don't configure this setting, Microsoft Edge uses either the user-specified preferred locale (if configured) or the fallback locale 'en-US'.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ApplicationLocaleValue
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Configures the application locale in Microsoft Edge and prevents users from changing the locale. If you enable this policy, Microsoft Edge uses the specified locale. If the configured locale isn't supported, 'en-US' is used instead. If you disable or don't configure this setting, Microsoft Edge uses either the user-specified preferred locale (if configured) or the fallback locale 'en-US'. Example value: en
DiskCacheDir Set disk cache directory
To avoid data loss or other unexpected errors, don't configure this policy to a volume's root directory or to a directory used for other purposes, because Microsoft Edge manages its contents. If you don't configure this policy, the default cache directory is used, and users can override that default with the '--disk-cache-dir' command line flag.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DiskCacheDir
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Configures the directory to use to store cached files. If you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user has specified the '--disk-cache-dir' flag. To avoid data loss or other unexpected errors, don't configure this policy to a volume's root directory or to a directory used for other purposes, because Microsoft Edge manages its contents. See https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables you can use when specifying directories and paths. If you don't configure this policy, the default cache directory is used, and users can override that default with the '--disk-cache-dir' command line flag. Example value: ${user_home}/Edge_cache
DiskCacheSize Set disk cache size, in bytes
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DiskCacheSize
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
This policy configures the disk cache size in Microsoft Edge. If you enable this policy, Microsoft Edge uses the specified cache size, regardless of whether the user set the --disk-cache-size command-line flag. The value defined in this policy is treated as a suggestion to the caching system, not a strict limit. Values below a few megabytes are rounded up to a reasonable minimum. If you set the value to 0, the default cache size is used and users can't override it. It's recommended not to configure a custom value, as Microsoft Edge automatically manages the cache size for optimal performance. Setting a small value can degrade performance and increase network usage. If you don’t configure this policy, the default size is used, but users can override it with the --disk-cache-size flag. Note: The specified value is treated as a hint to multiple cache subsystems. The total disk usage of all caches can be larger than (but within the same order of magnitude as) the configured value.
DownloadDirectory Set download directory
If you disable or don't configure this policy, the default download directory is used, and the user can change it.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DownloadDirectory
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Configures the directory to use when downloading files. If you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user specified one or chose to be prompted for download location every time. See https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used. If you disable or don't configure this policy, the default download directory is used, and the user can change it. If you set an invalid path, Microsoft Edge defaults to the user's default download directory. If the folder specified by the path doesn't exist, the download triggers a prompt that asks the user where they want to save their download. Example value: Linux-based OSes (including Mac): /home/${user_name}/Downloads Windows: C:\Users\${user_name}\Downloads
TotalMemoryLimitMb Set limit on megabytes of memory a single Microsoft Edge instance can use
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- TotalMemoryLimitMb
- Supported on
- Microsoft Edge version 80, Windows 7 or later
- Template
- msedge.admx
Configures the amount of memory that a single Microsoft Edge instance can use before tabs start getting discarded to save memory. The memory used by the tab will be freed and the tab will have to be reloaded when switched to. If you enable this policy, the browser starts to discard tabs to save memory once the limitation is exceeded. However, there's no guarantee that the browser is always running under the limit. Any value under 1024 is rounded up to 1024. If you don't set this policy, the browser only attempts to save memory when it has detected that the amount of physical memory on its machine is low.
DefaultBrowserSettingEnabled Set Microsoft Edge as default browser
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultBrowserSettingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7
- Template
- msedge.admx
If you set this policy to True, Microsoft Edge always checks whether it's the default browser on startup and, if possible, automatically registers itself. If you set this policy to False, Microsoft Edge is stopped from ever checking if it's the default and turns user controls off for this option. If you don't set this policy, Microsoft Edge lets users control whether it's the default and, if not, whether user notifications should appear. Note for Windows administrators: This policy only works for PCs running Windows 7. For later versions of Windows, you have to deploy a "default application associations" file that makes Microsoft Edge the handler for the https and http protocols (and, optionally, the ftp protocol and file formats such as .html, .htm, .pdf, .svg, .webp). See https://go.microsoft.com/fwlink/?linkid=2094932 for more information.
DefaultShareAdditionalOSRegionSetting Set the default "share additional operating system region" setting
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultShareAdditionalOSRegionSetting
- Supported on
- Microsoft Edge version 108, Windows 7 or later
- Template
- msedge.admx
0Limited1Always share the OS Regional format2Never share the OS Regional formatThis policy controls the default value for the "share additional operating system region" setting in Microsoft Edge. The "share additional operating system region" Microsoft Edge setting controls whether the OS Regional format setting is shared with the web through the default JavaScript locale. If shared, websites can query the OS Regional format using JavaScript code, for example; "Intl.DateTimeFormat().resolvedOptions().locale". The default value for the setting is "Limited". If you set this policy to "Limited", the OS Regional format is shared only if its language part matches the Microsoft Edge display language. If you set this policy to "Always", the OS Regional format is always shared. This value could cause unexpected website behavior if the OS Regional format language is different from the Microsoft Edge display language. For example, if a website uses the JavaScript default locale to format dates, the names of the days and months are displayed in one language while the surrounding text is displayed in another language. If you set this policy to "Never", the OS Regional format is never shared. Example 1: In this example the OS Regional format is set to "en-GB", and the browser display language is set to "en-US". Then the OS Regional format is shared if the policy is set to "Limited", or "Always". Example 2: In this example the OS Regional format is set to "es-MX", and the browser display language is set to "en-US". Then the OS Regional format is shared if the policy is set to "Always"; however, the OS Regional format isn't shared if the policy is set to "Limited". For more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2222282. Policy options mapping: * Limited (0) = Limited * Always (1) = Always share the OS Regional format * Never (2) = Never share the OS Regional format Use the preceding information when configuring this policy.
RoamingProfileLocation Set the roaming profile directory
If you disable the 'RoamingProfileSupportEnabled' policy or don't configure it, the value stored in this policy isn't used. If you don't configure this policy, the default roaming profile path is used.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RoamingProfileLocation
- Supported on
- Microsoft Edge version 85, Windows 7 or later
- Template
- msedge.admx
Configures the directory to use to store the roaming copy of profiles. If you enable this policy, Microsoft Edge uses the provided directory to store a roaming copy of the profiles, as long as you've also enabled the 'RoamingProfileSupportEnabled' (Enable using roaming copies for Microsoft Edge profile data) policy. If you disable the 'RoamingProfileSupportEnabled' policy or don't configure it, the value stored in this policy isn't used. See https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables you can use. If you don't configure this policy, the default roaming profile path is used. Example value: ${roaming_app_data}\edge-profile
RelaunchWindow Set the time interval for relaunch
If you don't configure this policy, the default target time window is the whole day (that is, the end of the notification period is never deferred).
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RelaunchWindow
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
Specifies a target time window for the end of the relaunch notification period. Users are notified of the need for a browser relaunch or device restart based on the 'RelaunchNotification' (Notify a user that a browser restart is recommended or required for pending updates) and 'RelaunchNotificationPeriod' (Set the time period for update notifications) policy settings. Browsers and devices are forcibly restarted at the end of the notification period when the 'RelaunchNotification' policy is set to Required. This RelaunchWindow policy can be used to defer the end of the notification period so that it falls within a specific time window. If you don't configure this policy, the default target time window is the whole day (that is, the end of the notification period is never deferred). Note: Though the policy can accept multiple items in entries, all items except the first are ignored. Warning: Setting this policy can delay application of software updates. Example value: { "entries": [ { "duration_mins": 240, "start": { "hour": 2, "minute": 15 } } ] } Compact example value: {"entries": [{"duration_mins": 240, "start": {"hour": 2, "minute": 15}}]}
RelaunchNotificationPeriod Set the time period for update notifications
If not set, the default period of 604800000 milliseconds (one week) is used.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RelaunchNotificationPeriod
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows you to set the time period, in milliseconds, over which users are notified that Microsoft Edge must be relaunched to apply a pending update. Over this time period, the user is repeatedly informed of the need for an update. In Microsoft Edge the app menu changes to indicate that a relaunch is needed once one third of the notification period passes. This notification changes color once two thirds of the notification period passes, and again once the full notification period is passed. The additional notifications enabled by the 'RelaunchNotification' (Notify a user that a browser restart is recommended or required for pending updates) policy follow this same schedule. If not set, the default period of 604800000 milliseconds (one week) is used.
UserDataDir Set the user data directory
To avoid data loss or other errors, don't configure this policy to a volume's root directory or to a directory that's used for other purposes, because Microsoft Edge manages its contents.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- UserDataDir
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Set the directory to use for storing user data. If you enable this policy, Microsoft Edge uses the specified directory regardless of whether the user has set the '--user-data-dir' command-line flag. If you don't enable this policy, the default profile path is used, but the user can override it by using the '--user-data-dir' flag. Users can find the directory for the profile at edge://version/ under profile path. To avoid data loss or other errors, don't configure this policy to a volume's root directory or to a directory that's used for other purposes, because Microsoft Edge manages its contents. See https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used. Example value: ${users}/${user_name}/Edge
WPADQuickCheckEnabled Set WPAD optimization
If you enable or don't configure the policy, WPAD optimization is enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WPADQuickCheckEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows you to turn off WPAD (Web Proxy Auto-Discovery) optimization in Microsoft Edge. If you disable this policy, WPAD optimization is disabled, which makes the browser wait longer for DNS-based WPAD servers. If you enable or don't configure the policy, WPAD optimization is enabled. Independent of whether or how this policy is enabled, the WPAD optimization setting can't be changed by users.
ManagedConfigurationPerOrigin Sets managed configuration values for websites to specific origins
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ManagedConfigurationPerOrigin
- Supported on
- Microsoft Edge version 90, Windows 7 or later
- Template
- msedge.admx
Setting this policy defines the return value of Managed Configuration API for given origin. Managed Configuration API is a key-value configuration that can be accessed via navigator.device.getManagedConfiguration() javascript call. This API is only available to origins, which correspond to force-installed web applications via 'WebAppInstallForceList' (Configure list of force-installed Web Apps). Example value: [ { "managed_configuration_hash": "asd891jedasd12ue9h", "managed_configuration_url": "https://static.contoso.com/configuration.json", "origin": "https://www.contoso.com" }, { "managed_configuration_hash": "djio12easd89u12aws", "managed_configuration_url": "https://static.contoso.com/configuration2.json", "origin": "https://www.example.com" } ]
EdgeShoppingAssistantEnabled Shopping in Microsoft Edge Enabled
If you enable or don't configure this policy, shopping features such as price comparison, coupons, rebates, and express checkout are automatically applied for retail domains.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeShoppingAssistantEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 87, Windows 7 or later
- Template
- msedge.admx
This policy lets users compare the prices of a product they're looking at, get coupons or rebates from the website they're on, autoapply coupons, and help checkout faster using autofill data. If you enable or don't configure this policy, shopping features such as price comparison, coupons, rebates, and express checkout are automatically applied for retail domains. Coupons for the current retailer and prices from other retailers are fetched from a server. If you disable this policy, shopping features such as price comparison, coupons, rebates, and express checkout aren't automatically found for retail domains. Starting from version 90.0.818.56, the behavior of the messaging letting users know that there's a coupon, rebate, price comparison, or price history available on shopping domains is also done through a horizontal banner below the address bar. Previously, this messaging was done on the address bar.
ExternalProtocolDialogShowAlwaysOpenCheckbox Show an "Always open" checkbox in external protocol dialog
Prior to Microsoft Edge 83, if you don't configure this policy, the "Always allow" checkbox isn't displayed. On Microsoft Edge 83, if you don't configure this policy, the checkbox visibility is controlled by the "Enable remembering protocol launch prompting preferences" flag in edge://flags As of Microsoft Edge 84, if you don't configure this policy, when an external protocol confirmation prompt is shown, the user can select "Always allow" to skip all future confirmation prompts for the protocol on this site.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ExternalProtocolDialogShowAlwaysOpenCheckbox
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 79, Windows 7 or later
- Template
- msedge.admx
This policy controls whether the "Always allow this site to open links of this type" checkbox is shown on external protocol launch confirmation prompts. This policy only applies to https:// links. If you enable this policy, when an external protocol confirmation prompt is shown, the user can select "Always allow" to skip all future confirmation prompts for the protocol on this site. If you disable this policy, the "Always allow" checkbox isn't displayed. The user is prompted for confirmation every time an external protocol is invoked. Prior to Microsoft Edge 83, if you don't configure this policy, the "Always allow" checkbox isn't displayed. The user is prompted for confirmation every time an external protocol is invoked. On Microsoft Edge 83, if you don't configure this policy, the checkbox visibility is controlled by the "Enable remembering protocol launch prompting preferences" flag in edge://flags As of Microsoft Edge 84, if you don't configure this policy, when an external protocol confirmation prompt is shown, the user can select "Always allow" to skip all future confirmation prompts for the protocol on this site.
InternetExplorerIntegrationLocalFileShowContextMenu Show context menu to open a file:// link in Internet Explorer mode
If you disable or don't configure this policy, the context menu item won't be added. If you disable or don't configure this policy, the policy has no effect.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerIntegrationLocalFileShowContextMenu
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 88, Windows 7 or later
- Template
- msedge.admx
This policy controls the visibility of the 'Open link in new Internet Explorer mode tab' option on the context menu for file:// links. This setting works in conjunction with: 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration), which is set to 'IEMode'. If you enable this policy, the 'Open link in new Internet Explorer mode tab' context menu item is available for file:// links. If you disable or don't configure this policy, the context menu item won't be added. If the 'InternetExplorerIntegrationReloadInIEModeAllowed' (Allow unconfigured sites to be reloaded in Internet Explorer mode) policy allows users to reload sites in Internet Explorer mode, then the 'Open link in new Internet Explorer mode tab' context menu item is available for all links, except links to sites explicitly configured by the site list to use Microsoft Edge mode. In this case, if you enable this policy, the context menu item is available for file:// links even for sites configured to use Microsoft Edge mode. If you disable or don't configure this policy, the policy has no effect. To learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210
ShowDownloadsToolbarButton Show Downloads button on the toolbar
If you disable or don't configure the policy, the Downloads button isn't shown on the toolbar by default.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ShowDownloadsToolbarButton
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 114, Windows 7 or later
- Template
- msedge.admx
Set this policy to always show the Downloads button on the toolbar. If you enable this policy, the Downloads button is pinned to the toolbar. If you disable or don't configure the policy, the Downloads button isn't shown on the toolbar by default. Users can toggle the Downloads button in edge://settings/appearance.
HubsSidebarEnabled Show Hubs Sidebar
If you don't configure this policy, the Sidebar's visibility follows the user's Microsoft Edge settings.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- HubsSidebarEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 99, Windows 7 or later
- Template
- msedge.admx
The Sidebar is a launcher bar located on the right side of Microsoft Edge. If you enable this policy, the Sidebar is always visible. If you disable this policy, the Sidebar is never shown. If you don't configure this policy, the Sidebar's visibility follows the user's Microsoft Edge settings. As of Microsoft Edge version 141, the 'Microsoft365CopilotChatIconEnabled' (Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar) policy is the only means of controlling the display of Copilot in the toolbar. Note: The recommended version of this policy-also known as the "Default Settings (users can override)" policy-is obsolete. This policy has never supported the recommended capability.
SharedLinksEnabled Show links shared from Microsoft 365 apps in History
If you enable or don't configure this policy, Microsoft Edge displays links recently shared by or shared with the user from Microsoft 365 apps in History.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SharedLinksEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 96, Windows 7 or later
- Template
- msedge.admx
Allows Microsoft Edge to display links recently shared by or shared with the user from Microsoft 365 apps in History. If you enable or don't configure this policy, Microsoft Edge displays links recently shared by or shared with the user from Microsoft 365 apps in History. If you disable this policy, Microsoft Edge does not display links recently shared by or shared with the user from Microsoft 365 apps in History. The control in Microsoft Edge settings is disabled and set to off. This policy only applies for Microsoft Edge local user profiles and profiles signed in using Azure Active Directory.
ShowOfficeShortcutInFavoritesBar Show Microsoft Office shortcut in favorites bar (deprecated)
If you enable or don't configure this policy, users can choose whether to see the shortcut by changing the toggle in the favorites bar context menu.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ShowOfficeShortcutInFavoritesBar
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. This policy didn't work as expected due to changes in operational requirements. Therefore, the policy is deprecated and shouldn't be used. Specifies whether to include a shortcut to Office.com in the favorites bar. For users signed into Microsoft Edge, the shortcut takes users to their Microsoft Office apps and docs. If you enable or don't configure this policy, users can choose whether to see the shortcut by changing the toggle in the favorites bar context menu. If you disable this policy, the shortcut isn't shown.
ShowMicrosoftRewards Show Microsoft Rewards experiences
If you don't configure this policy: - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets see the Microsoft Rewards experience in their Microsoft Edge user profile.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ShowMicrosoftRewards
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 88, Windows 7 or later
- Template
- msedge.admx
Show Microsoft Rewards experience and notifications. If you enable this policy: - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets see the Microsoft Rewards experience in their Microsoft Edge user profile. - The setting to enable Microsoft Rewards in Microsoft Edge settings is enabled and toggled on. If you disable this policy: - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets won't see the Microsoft Rewards experience in their Microsoft Edge user profile. - The setting to enable Microsoft Rewards in Microsoft Edge settings is disabled and toggled off. If you don't configure this policy: - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets see the Microsoft Rewards experience in their Microsoft Edge user profile. - The setting to enable Microsoft Rewards in Microsoft Edge settings is enabled and toggled on.
InternetExplorerModeToolbarButtonEnabled Show the Reload in Internet Explorer mode button in the toolbar
If you disable or don't configure this policy, the Reload in Internet Explorer mode button isn't shown in the toolbar by default.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerModeToolbarButtonEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 96, Windows 7 or later
- Template
- msedge.admx
Microsoft Security BaselineInternetExplorerModeToolbarButtonEnabled = 0
Set this policy to show the Reload in Internet Explorer mode button in the toolbar. Users can hide the button in the toolbar through edge://settings/appearance. The button is only shown on the toolbar when the 'InternetExplorerIntegrationReloadInIEModeAllowed' (Allow unconfigured sites to be reloaded in Internet Explorer mode) policy is enabled or if the user chose to enable "Allow sites to be reloaded in Internet Explorer mode". If you enable this policy, the Reload in Internet mode button is pinned to the toolbar. If you disable or don't configure this policy, the Reload in Internet Explorer mode button isn't shown in the toolbar by default. Users can toggle the Show Internet Explorer mode button in edge://settings/appearance.
ShowHistoryThumbnails Show thumbnail images for browsing history
If you don't configure this policy, the thumbnail feature is turned on after a user visits the history hub twice in the past seven days.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ShowHistoryThumbnails
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 117, Windows 7 or later
- Template
- msedge.admx
This policy lets you configure whether the history thumbnail feature collects and saves images for the sites you visit. When enabled, this feature makes it easier to identify sites when you hover over your history results. If you don't configure this policy, the thumbnail feature is turned on after a user visits the history hub twice in the past seven days. If you enable this policy, the history thumbnail collects and saves images for visited sites. If you disable this policy, the history thumbnail doesn't collect and save images for visited sites. When the feature is disabled, existing images are deleted on a per user basis, and the feature no longer collects or saves images when a site is visited.
ShowAcrobatSubscriptionButton Shows button on native PDF viewer in Microsoft Edge that allows users to sign up for Adobe Acrobat subscription
If you enable or don't configure this policy, the button shows up on the native PDF viewer in Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ShowAcrobatSubscriptionButton
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 111, Windows 7 or later
- Template
- msedge.admx
This policy lets the native PDF viewer in Microsoft Edge show a button that lets a user looking for advanced digital document features to discover and subscribe to premium offerings. This is done via the Acrobat extension. If you enable or don't configure this policy, the button shows up on the native PDF viewer in Microsoft Edge. A user can buy Adobe subscription to access their premium offerings. If you disable this policy, the button isn't visible on the native PDF viewer in Microsoft Edge. A user can't discover Adobe's advanced PDF tools or buy their subscriptions.
AADWebSiteSSOUsingThisProfileEnabled Single sign-on for work or school sites using this profile enabled
If you don't configure this policy, users can control whether to use SSO using other credentials present on the machine in edge://settings/profiles/multiProfileSettings.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AADWebSiteSSOUsingThisProfileEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 92, Windows 7 or later
- Template
- msedge.admx
'Allow single sign-on for work or school sites using this profile' option allows non-AAD profiles to be able to use single sign-on for work or school sites using work or school credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-AAD profiles only. If you enable or disable this policy, 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' will be turned off. If you don't configure this policy, users can control whether to use SSO using other credentials present on the machine in edge://settings/profiles/multiProfileSettings.
AudioCaptureAllowedUrls Sites that can access audio capture devices without requesting permission
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\AudioCaptureAllowedUrls
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specify websites, based on URL patterns, that can use audio capture devices without asking the user for permission. Patterns in this list are matched against the security origin of the requesting URL. If they match, the site is automatically granted access to audio capture devices. Note, however, that the pattern "*", which matches any URL, isn't supported by this policy. Example value: https://www.contoso.com/ https://[*.]contoso.edu/
VideoCaptureAllowedUrls Sites that can access video capture devices without requesting permission
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\VideoCaptureAllowedUrls
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specify websites, based on URL patterns, that can use video capture devices without asking the user for permission. Patterns in this list are matched against the security origin of the requesting URL. If they match, the site is automatically granted access to video capture devices. However, the pattern "*", which matches any URL, isn't supported by this policy. Example value: https://www.contoso.com/ https://[*.]contoso.edu/
SharedArrayBufferUnrestrictedAccessAllowed Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context
If you disable or don't configure this policy, sites are allowed to use SharedArrayBuffers only when cross-origin isolated.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SharedArrayBufferUnrestrictedAccessAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 92, Windows 7 or later
- Template
- msedge.admx
Microsoft Security BaselineSharedArrayBufferUnrestrictedAccessAllowed = 0
Specifies whether SharedArrayBuffers can be used in a non-cross-origin-isolated context. A SharedArrayBuffer is a binary data buffer that's used to create views on shared memory. SharedArrayBuffers have a memory access vulnerability in several popular CPUs. If you enable this policy, sites are allowed to use SharedArrayBuffers with no restrictions. If you disable or don't configure this policy, sites are allowed to use SharedArrayBuffers only when cross-origin isolated. Microsoft Edge requires cross-origin isolation when using SharedArrayBuffers from Microsoft Edge version 91 onward for Web Compatibility reasons.
DisplayCapturePermissionsPolicyEnabled Specifies whether the display-capture permissions-policy is checked or skipped (obsolete)
If you enable or don't configure this policy, sites can only call getDisplayMedia() from contexts that are allowlisted by the display-capture permissions-policy.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DisplayCapturePermissionsPolicyEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 95-109, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 109. This policy is obsolete. The policy was a temporary workaround for non-spec-compliant enterprise applications. This policy stopped working in Microsoft Edge version 107 and was obsoleted in Microsoft Edge 110. The display-capture permissions-policy gates access to getDisplayMedia(), as per this spec: https://www.w3.org/TR/screen-capture/#feature-policy-integration However, if this policy is Disabled, this requirement isn't enforced, and getDisplayMedia() is allowed from contexts that would otherwise be forbidden. If you enable or don't configure this policy, sites can only call getDisplayMedia() from contexts that are allowlisted by the display-capture permissions-policy. If you disable this policy, sites can call getDisplayMedia() even from contexts which are not allowlisted by the display-capture permissions policy. Other restrictions may still apply.
CrossOriginWebAssemblyModuleSharingEnabled Specifies whether WebAssembly modules can be sent cross-origin (obsolete)
If you disable or don't configure this policy, sites can only send WebAssembly modules to windows and workers in the same origin.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- CrossOriginWebAssemblyModuleSharingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 95-98, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 98. Specifies whether WebAssembly modules can be sent to another window or worker cross-origin. Cross-origin WebAssembly module sharing was deprecated as part of the efforts to deprecate document.domain, see https://github.com/mikewest/deprecating-document-domain. This policy allowed re-enabling of cross-origin WebAssembly module sharing. This policy is obsolete because it was intended to offer a longer transition period in the deprecation process. If you enable this policy, sites can send WebAssembly modules cross-origin without restrictions. If you disable or don't configure this policy, sites can only send WebAssembly modules to windows and workers in the same origin.
CustomHelpLink Specify custom help link
If you disable or don't configure this policy, the default link for the Help menu or the F1 key is used.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- CustomHelpLink
- Supported on
- Microsoft Edge version 79, Windows 7 or later
- Template
- msedge.admx
Specify a link for the Help menu or the F1 key. If you enable this policy, an admin can specify a link for the Help menu or the F1 key. If you disable or don't configure this policy, the default link for the Help menu or the F1 key is used. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX. Example value: https://go.microsoft.com/fwlink/?linkid=2080734
InternetExplorerIntegrationSiteRedirect Specify how "in-page" navigations to unconfigured sites behave when started from Internet Explorer mode pages
If you disable or don't configure this policy, only sites configured to open in Internet Explorer mode open in that mode. Any site not configured to open in Internet Explorer mode is redirected back to Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerIntegrationSiteRedirect
- Supported on
- Microsoft Edge version 81, Windows 7 or later
- Template
- msedge.admx
0Default1Keep only automatic navigations in Internet Explorer mode2Keep all in-page navigations in Internet Explorer modeAn "in-page" navigation is started from a link, a script, or a form on the current page. It can also be a server-side redirect of a previous "in-page" navigation attempt. Conversely, a user can start a navigation that isn't "in-page" and that's independent of the current page in several ways by using the browser controls, for example, using the address bar, the back button, or a favorite link. This setting lets you specify whether navigations from pages loaded in Internet Explorer mode to unconfigured sites (that aren't configured in the Enterprise Mode Site List) switch back to Microsoft Edge or remain in Internet Explorer mode. This setting works in conjunction with 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) policy that's set to 'IEMode', and with 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy where the list has at least one entry. If you disable or don't configure this policy, only sites configured to open in Internet Explorer mode open in that mode. Any site not configured to open in Internet Explorer mode is redirected back to Microsoft Edge. If you set this policy to 'Default', only sites configured to open in Internet Explorer mode open in that mode. Any site not configured to open in Internet Explorer mode is redirected back to Microsoft Edge. If you set this policy to 'AutomaticNavigationsOnly', you get the default experience except that all automatic navigations (such as 302 redirects) to unconfigured sites are kept in Internet Explorer mode. If you set this policy to 'AllInPageNavigations', all navigations from pages loaded in IE mode to unconfigured sites are kept in Internet Explorer mode (Least Recommended). If the 'InternetExplorerIntegrationReloadInIEModeAllowed' (Allow unconfigured sites to be reloaded in Internet Explorer mode) policy allows users to reload sites in Internet Explorer mode, then all in-page navigations from unconfigured sites that users have chosen to reload in Internet Explorer mode are kept in Internet Explorer mode, regardless of how this policy is configured. To learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2105106. Policy options mapping: * Default (0) = Default * AutomaticNavigationsOnly (1) = Keep only automatic navigations in Internet Explorer mode * AllInPageNavigations (2) = Keep all in-page navigations in Internet Explorer mode Use the preceding information when configuring this policy.
RequireOnlineRevocationChecksForLocalAnchors Specify if online OCSP/CRL checks are required for local trust anchors
If you don't configure or disable this policy, then Microsoft Edge uses the existing online revocation checking settings.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RequireOnlineRevocationChecksForLocalAnchors
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 123, Windows 7 or later
- Template
- msedge.admx
Control whether online revocation checks (OCSP/CRL checks) are required. If Microsoft Edge can't get revocation status information, these certificates are treated as revoked ("hard-fail"). If you enable this policy, Microsoft Edge always performs revocation checking for server certificates that successfully validate and are signed by locally installed CA certificates. If you don't configure or disable this policy, then Microsoft Edge uses the existing online revocation checking settings. On macOS, this policy has no effect if the 'MicrosoftRootStoreEnabled' (Determines whether the Microsoft Root Store and built-in certificate verifier will be used to verify server certificates) policy is set to False.
InternetExplorerIntegrationLocalSiteListExpirationDays Specify the number of days that a site remains on the local IE mode site list
If the 'InternetExplorerIntegrationReloadInIEModeAllowed' (Allow unconfigured sites to be reloaded in Internet Explorer mode) policy is enabled or not configured, users will be able to tell Microsoft Edge to load specific pages in Internet Explorer mode for a limited number of days. If you disable or don't configure this policy, the default value of 30 days is used.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerIntegrationLocalSiteListExpirationDays
- Supported on
- Microsoft Edge version 92, Windows 7 or later
- Template
- msedge.admx
If the 'InternetExplorerIntegrationReloadInIEModeAllowed' (Allow unconfigured sites to be reloaded in Internet Explorer mode) policy is enabled or not configured, users will be able to tell Microsoft Edge to load specific pages in Internet Explorer mode for a limited number of days. You can use this setting to determine how many days that configuration is remembered in the browser. After this period has elapsed, the individual page will no longer automatically load in IE mode. If you disable the 'InternetExplorerIntegrationReloadInIEModeAllowed' policy, this policy has no effect. If you disable or don't configure this policy, the default value of 30 days is used. If you enable this policy, you must enter the number of days for which the sites are retained on the user's local site list in Microsoft Edge. The value can be from 0 to 90 days. To learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210
TLSCipherSuiteDenyList Specify the TLS cipher suites to disable
If you don't configure this policy, the browser chooses which TLS cipher suites to use.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\TLSCipherSuiteDenyList
- Supported on
- Microsoft Edge version 85, Windows 7 or later
- Template
- msedge.admx
Configure the list of cipher suites that are disabled for TLS connections. If you configure this policy, the list of configured cipher suites won't be used when establishing TLS connections. If you don't configure this policy, the browser chooses which TLS cipher suites to use. Cipher suite values to be disabled are specified as 16-bit hexadecimal values. The values are assigned by the Internet Assigned Numbers Authority (IANA) registry. The TLS 1.3 cipher suite TLS_AES_128_GCM_SHA256 (0x1301) is required for TLS 1.3 and can't be disabled by this policy. This policy does not affect QUIC-based connections. QUIC can be turned off via the 'QuicAllowed' (Allow QUIC protocol) policy. Example value: 0x1303 0xcca8 0xcca9
DnsOverHttpsTemplates Specify URI template of desired DNS-over-HTTPS resolver
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DnsOverHttpsTemplates
- Supported on
- Microsoft Edge version 83, Windows 7 or later
- Template
- msedge.admx
The URI template of the desired DNS-over-HTTPS resolver. To specify multiple DNS-over-HTTPS resolvers, separate the corresponding URI templates with spaces. If you set 'DnsOverHttpsMode' (Control the mode of DNS-over-HTTPS) to "secure", then this policy must be set and can't be empty. If you set 'DnsOverHttpsMode' to "automatic" and this policy is set, then the URI templates specified are used. If you don't set this policy, then hardcoded mappings are used to attempt to upgrade the user's current DNS resolver to a DoH resolver operated by the same provider. If the URI template contains a dns variable, requests to the resolver use GET; otherwise, requests use POST. Incorrectly formatted templates will be ignored. Example value: https://dns.example.net/dns-query{?dns}
MicrosoftEditorProofingEnabled Spell checking provided by Microsoft Editor
If you enable or don't configure this policy, Microsoft Editor spell check can be used for eligible text fields.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- MicrosoftEditorProofingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 105, Windows 7 or later
- Template
- msedge.admx
The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages. If you enable or don't configure this policy, Microsoft Editor spell check can be used for eligible text fields. If you disable this policy, spell check can only be provided by local engines that use platform or Hunspell services. The results from these engines might be less informative than the results Microsoft Editor can provide. If the 'SpellcheckEnabled' (Enable spellcheck) policy is set to disabled, or the user disables spell checking in the settings page, this policy will have no effect.
StandaloneHubsSidebarEnabled Standalone Sidebar Enabled
If you enable or don't configure this policy, users can activate the Standalone Sidebar.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- StandaloneHubsSidebarEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 114, Windows 7 or later
- Template
- msedge.admx
Standalone Sidebar is an optional mode for the Sidebar in Microsoft Edge. When this mode is activated by a user, the Sidebar appears in a fixed position on the Microsoft Windows desktop, and is hidden from the browser application frame. If you enable or don't configure this policy, users can activate the Standalone Sidebar. If you disable this policy, options to activate Standalone Sidebar can be hidden or made unavailable. Blocking 'HubsSidebarEnabled' (Show Hubs Sidebar) also prevents users from accessing Standalone Sidebar.
AlternateErrorPagesEnabled Suggest similar pages when a webpage can't be found
If you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AlternateErrorPagesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 80, Windows 7 or later
- Template
- msedge.admx
Allow Microsoft Edge to issue a connection to a web service to generate URL and search suggestions for connectivity issues such as DNS errors. If you enable this policy, a web service is used to generate url and search suggestions for network errors. If you disable this policy, no calls to the web service are made and a standard error page is shown. If you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy. Specifically, there's a **Suggest similar pages when a webpage can't be found** toggle, which the user can switch on or off. If you enable this policy (AlternateErrorPagesEnabled), the **Suggest similar pages when a webpage can't be found** setting is turned on, but the user can't change the setting by using the toggle. If you disable this policy, the **Suggest similar pages when a webpage can't be found** setting is turned off, and the user can't change the setting by using the toggle.
SuperDragDropEnabled Super Drag Drop Enabled
If you enable or don't configure this policy, you can use the Super Drag Drop feature on Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SuperDragDropEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 122, Windows 7 or later
- Template
- msedge.admx
This policy lets you configure the Super Drag Drop feature in Microsoft Edge. With this feature, users can drag a link or text from a webpage and drop it onto the same page. They can then either open the URL in a new tab or search the text using the default search engine. If you enable or don't configure this policy, you can use the Super Drag Drop feature on Microsoft Edge. If you disable this policy, you can't use the Super Drag Drop feature in Microsoft Edge.
SuppressUnsupportedOSWarning Suppress the unsupported OS warning
If this policy is false or unset, the warnings will appear on such unsupported computers or operating systems.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SuppressUnsupportedOSWarning
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Suppresses the warning that appears when Microsoft Edge is running on a computer or operating system that is no longer supported. If this policy is false or unset, the warnings will appear on such unsupported computers or operating systems.
MicrosoftEditorSynonymsEnabled Synonyms are provided when using Microsoft Editor spell checker
If you disable or don't configure this policy, Microsoft Editor spell checker won't provide synonyms for suggestions for misspelled words.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- MicrosoftEditorSynonymsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 105, Windows 7 or later
- Template
- msedge.admx
The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages, and synonyms can be suggested as an integrated feature. If you enable this policy, Microsoft Editor spell checker provides synonyms for suggestions for misspelled words. If you disable or don't configure this policy, Microsoft Editor spell checker won't provide synonyms for suggestions for misspelled words. If the 'SpellcheckEnabled' (Enable spellcheck) policy or the 'MicrosoftEditorProofingEnabled' (Spell checking provided by Microsoft Editor) policy are set to disabled, or the user disables spell checking or chooses not to use Microsoft Editor spell checker in the settings page, this policy will have no effect.
TextPredictionEnabled Text prediction enabled by default
If you enable or don't configure this policy, text predictions are provided for eligible text fields.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- TextPredictionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 104, Windows 7 or later
- Template
- msedge.admx
The Microsoft Turing service uses natural language processing to generate predictions for long-form editable text fields on web pages. If you enable or don't configure this policy, text predictions are provided for eligible text fields. If you disable this policy, text predictions aren't provided in eligible text fields. Sites may still provide their own text predictions.
EncryptedClientHelloEnabled TLS Encrypted ClientHello Enabled
If you enable or don't configure this policy, Microsoft Edge follows the default rollout process for ECH.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EncryptedClientHelloEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 108, Windows 7 or later
- Template
- msedge.admx
Encrypted ClientHello (ECH) is an extension to TLS that encrypts the sensitive fields of ClientHello to improve privacy. If ECH is enabled, Microsoft Edge might or might not use ECH depending on server support, the availability of the HTTPS DNS record, or the rollout status. If you enable or don't configure this policy, Microsoft Edge follows the default rollout process for ECH. If this policy is disabled, Microsoft Edge won't enable ECH. Because ECH is an evolving protocol, Microsoft Edge's implementation is subject to change. As such, this policy is a temporary measure to control the initial experimental implementation. It will be replaced with final controls as the protocol finalizes.
UrlDiagnosticDataEnabled URL reporting in Edge diagnostic data enabled
If you enable or don't configure this setting, URLs are provided in optional diagnostic data.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- UrlDiagnosticDataEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 122, Windows 7 or later
- Template
- msedge.admx
Controls sending URLs of pages visited and per-page usage in the Microsoft Edge optional diagnostics data to Microsoft to help make browsing and search better. This also includes identifiers and usage diagnostics of other browser components that can modify or provide content, such as extensions. This policy is applicable only if the 'DiagnosticData' (Send required and optional diagnostic data about browser usage) setting is set to 'OptionalData'. For more information on how Microsoft Edge diagnostic data levels are set, see the description of 'DiagnosticData'. If you enable or don't configure this setting, URLs are provided in optional diagnostic data. If you disable this setting, URLs aren't reported in optional diagnostic data.
AutoOpenAllowedForURLs URLs where AutoOpenFileTypes can apply
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\AutoOpenAllowedForURLs
- Supported on
- Microsoft Edge version 85, Windows 7 or later
- Template
- msedge.admx
A list of URLs to which 'AutoOpenFileTypes' (List of file types that should be automatically opened on download) applies to. This policy has no impact on automatically open values set by users via the download shelf ... > "Always open files of this type" menu entry. If you set URLs in this policy, files will only automatically open by policy if the URL is part of this set and the file type is listed in 'AutoOpenFileTypes'. If either condition is false, the download won't automatically open by policy. If you don't set this policy, all downloads where the file type is in 'AutoOpenFileTypes' automatically opens. A URL pattern has to be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322. This policy doesn't work as expected with file://* wildcards. Example value: example.com https://ssl.server.com hosting.com/good_path https://server:8080/path .exact.hostname.com
ForceLegacyDefaultReferrerPolicy Use a default referrer policy of no-referrer-when-downgrade (obsolete)
This enterprise policy is disabled by default.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ForceLegacyDefaultReferrerPolicy
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 81-88, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 88. This policy doesn't work because it was only intended to be a short-term mechanism to give enterprises more time to update their web content if it was found to be incompatible with the new default referrer policy. Microsoft Edge's default referrer policy was strengthened from the value of no-referrer-when-downgrade to the more secure strict-origin-when-cross-origin. When this enterprise policy is enabled, Microsoft Edge's default referrer policy will be set to its old value of no-referrer-when-downgrade. This enterprise policy is disabled by default.
BuiltInDnsClientEnabled Use built-in DNS client
If you enable this policy or you don't configure this policy, the built-in DNS client is used.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- BuiltInDnsClientEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Controls whether to use the built-in DNS client. This policy controls which software stack is used to communicate with the DNS server: the operating system DNS client, or Microsoft Edge's built-in DNS client. This policy doesn't affect which DNS servers are used: if, for example, the operating system is configured to use an enterprise DNS server, that same server would be used by the built-in DNS client. It also does not control if DNS-over-HTTPS is used; Microsoft Edge always uses the built-in resolver for DNS-over-HTTPS requests. See the 'DnsOverHttpsMode' (Control the mode of DNS-over-HTTPS) policy for information on controlling DNS-over-HTTPS. If you enable this policy or you don't configure this policy, the built-in DNS client is used. If you disable this policy, the built-in DNS client is only used when DNS-over-HTTPS is in use.
HardwareAccelerationModeEnabled Use graphics acceleration when available
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- HardwareAccelerationModeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
If you enable this policy, or leave it unconfigured, graphics acceleration is utilized if it’s available. If you disable this policy, turns off graphics acceleration.
PdfViewerOutOfProcessIframeEnabled Use out-of-process iframe PDF Viewer
If you enable this policy or don't configure it, Microsoft Edge uses the OOPIF PDF viewer architecture.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PdfViewerOutOfProcessIframeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 133, Windows 7 or later
- Template
- msedge.admx
Determines whether the PDF viewer in Microsoft Edge uses an out-of-process iframe (OOPIF). This is the new PDF viewer architecture going forward, as it's simpler in design and makes adding new features easier. The current GuestView PDF viewer, which relies on an outdated and overly complex architecture, is being deprecated. If you enable this policy or don't configure it, Microsoft Edge uses the OOPIF PDF viewer architecture. The default behavior will be decided by Microsoft Edge. If you disable this policy, Microsoft Edge strictly uses the existing GuestView PDF viewer. This approach embeds a web page with its own separate frame tree into another web page. This policy will be removed in the future, after the OOPIF PDF viewer feature has fully rolled out.
WinHttpProxyResolverEnabled Use Windows proxy resolver
If you disable or don't configure this policy, the Microsoft Edge proxy resolver is used.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WinHttpProxyResolverEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 84, Windows 7 or later
- Template
- msedge.admx
This policy will be superseded by a similar feature in a future release. For more information, see https://crbug.com/1032820. Use Windows to resolve proxies for all browser networking instead of the proxy resolver built into Microsoft Edge. The Windows proxy resolver enables Windows proxy features such as DirectAccess/NRPT. This policy comes with the problems described by https://crbug.com/644030. It causes PAC files to be fetched and executed by Windows code, including PAC files set via the 'ProxyPacUrl' (Set the proxy .pac file URL) policy. Since network fetches for the PAC file happen via Windows instead of Microsoft Edge code, network policies such as 'DnsOverHttpsMode' (Control the mode of DNS-over-HTTPS) won't apply to network fetches for a PAC file. If you enable this policy, the Windows proxy resolver is used. If you disable or don't configure this policy, the Microsoft Edge proxy resolver is used.
VisualSearchEnabled Visual search enabled
If you enable or don't configure this policy, visual search is enabled via image hover, context menu, and search in sidebar.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- VisualSearchEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 95, Windows 7 or later
- Template
- msedge.admx
Visual search lets you quickly explore more related content about entities in an image. If you enable or don't configure this policy, visual search is enabled via image hover, context menu, and search in sidebar. If you disable this policy, visual search is disabled and you can't get more info about images via hover, context menu, and search in sidebar. Note: Visual Search in Web Capture is still managed by 'WebCaptureEnabled' (Enable the Screenshot (previously named Web Capture) feature in Microsoft Edge) policy.
InternetExplorerIntegrationAlwaysWaitForUnload Wait for Internet Explorer mode tabs to completely unload before ending the browser session
If you disable or don't configure this policy, Microsoft Edge won't always wait for Internet Explorer mode tabs to fully unload before ending the browser session.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InternetExplorerIntegrationAlwaysWaitForUnload
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 105, Windows 7 or later
- Template
- msedge.admx
This policy causes Microsoft Edge to continue running until all Internet Explorer tabs have completely finished unloading. This allows Internet Explorer plugins like ActiveX controls to perform other critical work even after the browser has been closed. However, this can cause stability and performance issues, and Microsoft Edge processes may remain active in the background with no visible windows if the webpage or plugin prevents Internet Explorer from unloading. This policy should only be used if your organization depends on a plugin that requires this behavior. If you enable this policy, Microsoft Edge always waits for Internet Explorer mode tabs to fully unload before ending the browser session. If you disable or don't configure this policy, Microsoft Edge won't always wait for Internet Explorer mode tabs to fully unload before ending the browser session. To learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2174004
WalletDonationEnabled Wallet Donation Enabled (deprecated)
If you enable or don't configure this policy, users can use the Wallet Donation feature.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WalletDonationEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 115, Windows 7 or later
- Template
- msedge.admx
DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. The Wallet Donation feature in Microsoft Edge allows users to view their donation summary, explore Nonprofit organizations (NPOs), donate to an NPO, manage their monthly donations, and view their donation history. If you enable or don't configure this policy, users can use the Wallet Donation feature. If you disable this policy, users can't use the Wallet Donation feature. This policy is deprecated because the Wallet Donation feature has been removed from Microsoft Edge.
WebAppSettings Web App management settings
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebAppSettings
- Supported on
- Microsoft Edge version 120, Windows 7 or later
- Template
- msedge.admx
This policy allows an admin to specify settings for installed web apps. This policy maps a Web App ID to its specific setting. A default configuration can be set using the special ID *, which applies to all web apps without a custom configuration in this policy. - The manifest_id field is the Manifest ID for the Web App. See https://developer.chrome.com/blog/pwa-manifest-id/ for instructions on how to determine the Manifest ID for an installed web app. - The run_on_os_login field specifies if a web app can be run during OS sign in. If you set this field to blocked, the web app doesn't run during OS sign in, and the user can't enable this later. If you set this field to run_windowed, the web app runs during OS sign in, and the user can't disable this later. If you set this field to allowed, the user configures the web app to run at OS sign in. The default policy configuration only allows the allowed and blocked values. - (Starting with Microsoft Edge version 120) The prevent_close_after_run_on_os_login field specifies if a web app can be prevented from closing in any way. For example, by the user, by task manager, or by web APIs. This behavior can only be enabled if run_on_os_login is set to run_windowed. If the app is already running, this setting will only take effect after the app is restarted. If this field isn't defined, users can close the app. (This is currently not supported in Microsoft Edge.) - (Since version 118) The force_unregister_os_integration field specifies if all OS integration for a web app, that is, shortcuts, file handlers, protocol handlers and so on, will be removed or not. If an app is already running, this property comes into effect after the app restarts. This should be used with caution, since it can override any OS integration that is set automatically during the startup of the web applications system. This currently only works on Windows, Mac and Linux platforms. Example value: [ { "manifest_id": "https://foo.example/index.html", "run_on_os_login": "allowed" }, { "manifest_id": "https://bar.example/index.html", "run_on_os_login": "allowed" }, { "manifest_id": "https://foobar.example/index.html", "run_on_os_login": "run_windowed", "prevent_close_after_run_on_os_login": true }, { "manifest_id": "*", "run_on_os_login": "blocked" }, { "manifest_id": "https://foo.example/index.html", "force_unregister_os_integration": true } ]
WebSelectEnabled Web Select Enabled (obsolete)
If you enable or don't configure this policy, Web select is available in Web Capture and can be accessed directly using the CTRL+SHIFT+X keyboard shortcut.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebSelectEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 107-116, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 116. This policy is obsoleted because Web Select is part of Web Capture and can be controlled by 'WebCaptureEnabled' (Enable the Screenshot (previously named Web Capture) feature in Microsoft Edge). This policy doesn't work in Microsoft Edge version 117. If Web Capture is disabled by 'WebCaptureEnabled', Web select won't be available in Web Capture. Web select lets users select and copy web content while preserving its formatting when pasted in most cases. It also allows more targeted selection on some web elements, such as copying a single column in a table. If you enable or don't configure this policy, Web select is available in Web Capture and can be accessed directly using the CTRL+SHIFT+X keyboard shortcut. If you disable this policy, Web select won't be available in Web Capture and the CTRL+SHIFT+X keyboard shortcut will also not work.
SecurityKeyPermitAttestation Websites or domains that don't need permission to use direct Security Key attestation
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\SecurityKeyPermitAttestation
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specifies the WebAuthn RP IDs that don't need explicit user permission when attestation certificates from security keys are requested. Additionally, a signal is sent to the security key indicating that it can use enterprise attestation. Without this policy, users are prompted each time a site requests attestation of security keys. Example value: contoso.com
PDFXFAEnabled XFA support in native PDF reader enabled
If you disable or don't configure this policy, Microsoft Edge won't enable XFA support in the native PDF reader.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PDFXFAEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 104, Windows 7 or later
- Template
- msedge.admx
Lets the Microsoft Edge browser enable XFA (XML Forms Architecture) support in the native PDF reader and allows users to open XFA PDF files in the browser. If you enable this policy, XFA support in the native PDF reader is enabled. If you disable or don't configure this policy, Microsoft Edge won't enable XFA support in the native PDF reader.
Microsoft Edge - Default Settings (users can override)
DownloadRestrictions Allow download restrictions
If you don't configure this policy or set the 'DefaultDownloadSecurity' option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- DownloadRestrictions
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
0No special restrictions1Block malicious downloads and dangerous file types2Block potentially dangerous or unwanted downloads and dangerous file types3Block all downloads4Block malicious downloadsConfigures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision. Set 'BlockDangerousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of known dangerous downloads or that have dangerous file type extensions. Set 'BlockPotentiallyDangerousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous or unwanted downloads or that have dangerous file type extensions. Set 'BlockAllDownloads' to block all downloads. Set 'BlockMaliciousDownloads' to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of known malicious downloads. If you don't configure this policy or set the 'DefaultDownloadSecurity' option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results. Note that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options. See https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen. Policy options mapping: * DefaultDownloadSecurity (0) = No special restrictions * BlockDangerousDownloads (1) = Block malicious downloads and dangerous file types * BlockPotentiallyDangerousDownloads (2) = Block potentially dangerous or unwanted downloads and dangerous file types * BlockAllDownloads (3) = Block all downloads * BlockMaliciousDownloads (4) = Block malicious downloads Use the preceding information when configuring this policy.
EdgeAssetDeliveryServiceEnabled Allow features to download assets from the Asset Delivery Service
If you enable or don't configure this policy, features can download assets from the Asset Delivery Service.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- EdgeAssetDeliveryServiceEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 101, Windows 7 or later
- Template
- msedge.admx
The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients. These assets can be config files or Machine Learning models that power the features that use this service. If you enable or don't configure this policy, features can download assets from the Asset Delivery Service. If you disable this policy, features won't be able to download assets needed for them to run correctly.
HttpsOnlyMode Allow HTTPS-Only Mode to be enabled
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- HttpsOnlyMode
- Supported on
- Microsoft Edge version 140, Windows 7 or later
- Template
- msedge.admx
Don't restrict users' HTTPS-Only Mode settingDisable HTTPS-Only ModeForce enable HTTPS-Only Mode in Strict modeForce enable HTTPS-Only Mode in Balanced ModeThis policy controls whether users can enable HTTPS-Only Mode (Always Use Secure Connections) in Settings. HTTPS-Only Mode attempts to upgrade all navigation to HTTPS. If this setting isn't set or is set to Allowed, users are able to enable HTTPS-Only Mode. If this setting is set to Disallowed, HTTPS-Only Mode will be disabled. If this setting is set to Force Enabled, HTTPS-Only Mode is enabled in Strict mode. If this setting is set to Force Balance Enabled, HTTPS-Only Mode is enabled in Balanced mode. The settings Force Enabled and Force Enabled can be recommended to users. HTTPS-Only Mode will be set to Strict or Balanced initially, but users are allowed to change it. If you set this policy to a value that isn't supported by the version of Microsoft Edge that receives the policy, Microsoft Edge defaults to the Allowed setting. The separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature. Policy options mapping: * allowed (allowed) = Don't restrict users' HTTPS-Only Mode setting * disallowed (disallowed) = Disable HTTPS-Only Mode * force_enabled (force_enabled) = Force enable HTTPS-Only Mode in Strict mode * force_balanced_enabled (force_balanced_enabled) = Force enable HTTPS-Only Mode in Balanced Mode Use the preceding information when configuring this policy. Example value: disallowed
ImportAutofillFormData Allow importing of autofill form data
If you don't configure this policy, autofill data is imported at first run, and users can choose whether to import this data manually during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ImportAutofillFormData
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows users to import autofill form data from another browser into Microsoft Edge. If you enable this policy, the option to manually import autofill data is automatically selected. If you disable this policy, autofill form data isn't imported at first run, and users can't import it manually. If you don't configure this policy, autofill data is imported at first run, and users can choose whether to import this data manually during later browsing sessions. You can set this policy as a recommendation. This means that Microsoft Edge imports autofill data on first run, but users can select or clear autofill data option during manual import. Note: This policy currently manages import from Google Chrome (on Windows 7, 8, and 10 and on macOS) and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.
ImportBrowserSettings Allow importing of browser settings
If you don't configure this policy, browser settings are imported at first run, and users can choose whether to import them manually during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ImportBrowserSettings
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 78, Windows 7 or later
- Template
- msedge.admx
Allows users to import browser settings from another browser into Microsoft Edge. If you enable this policy, the **Browser settings** check box is automatically selected in the **Import browser data** dialog box. If you disable this policy, browser settings aren't imported at first run, and users can't import them manually. If you don't configure this policy, browser settings are imported at first run, and users can choose whether to import them manually during later browsing sessions. You can also set this policy as a recommendation. This option means that Microsoft Edge imports the settings on first run, but users can select or clear the **browser settings** option during manual import. **Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).
ImportHistory Allow importing of browsing history
If you don't configure this policy, browsing history data is imported at first run, and users can choose whether to import it manually during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ImportHistory
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows users to import their browsing history from another browser into Microsoft Edge. If you enable this policy, the Browsing history check box is automatically selected in the Import browser data dialog box. If you disable this policy, browsing history data isn't imported at first run, and users can't import this data manually. If you don't configure this policy, browsing history data is imported at first run, and users can choose whether to import it manually during later browsing sessions. You can also set this policy as a recommendation. This means that Microsoft Edge imports browsing history on first run, but users can select or clear the **history** option during manual import. Note: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (macOS) browsers.
ImportCookies Allow importing of Cookies
If you don't configure this policy, Cookies are imported on first run.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ImportCookies
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 81, Windows 7 or later
- Template
- msedge.admx
Allows users to import Cookies from another browser into Microsoft Edge. If you disable this policy, Cookies aren't imported on first run. If you don't configure this policy, Cookies are imported on first run. You can also set this policy as a recommendation. This means that Microsoft Edge imports Cookies on first run. Note: This policy currently manages Google Chrome import (on Windows 7, 8, and 10 and on macOS).
ImportExtensions Allow importing of extensions
If you don't configure this policy, extensions are imported at first run, and users can choose whether to import them manually during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ImportExtensions
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 81, Windows 7 or later
- Template
- msedge.admx
Allows users to import extensions from another browser into Microsoft Edge. If you enable this policy, the **Extensions** check box is automatically selected in the **Import browser data** dialog box. If you disable this policy, extensions aren't imported at first run, and users can't import them manually. If you don't configure this policy, extensions are imported at first run, and users can choose whether to import them manually during later browsing sessions. You can also set this policy as a recommendation. This means that Microsoft Edge imports extensions on first run, but users can select or clear the **extensions** option during manual import. **Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).
ImportFavorites Allow importing of favorites
If you don't configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ImportFavorites
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows users to import favorites from another browser into Microsoft Edge. If you enable this policy, the Favorites check box is automatically selected in the Import browser data dialog box. If you disable this policy, favorites aren't imported at first run, and users can't import them manually. If you don't configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions. You can also set this policy as a recommendation. This means that Microsoft Edge imports favorites on first run, but users can select or clear the **favorites** option during manual import. Note: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (on macOS) browsers.
ImportOpenTabs Allow importing of open tabs
If you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ImportOpenTabs
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 79, Windows 7 or later
- Template
- msedge.admx
Allows users to import open and pinned tabs from another browser into Microsoft Edge. If you enable this policy, the **Open tabs** check box is automatically selected in the **Import browser data** dialog box. If you disable this policy, open tabs aren't imported at first run, and users can't import them manually. If you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions. You can also set this policy as a recommendation. This means that Microsoft Edge imports open tabs on first run, but users can select or clear the **Open tabs** option during manual import. **Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).
ImportPaymentInfo Allow importing of payment info
If you don't configure this policy, payment info is imported at first run, and users can choose whether to import it manually during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ImportPaymentInfo
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows users to import payment info from another browser into Microsoft Edge. If you enable this policy, the **payment info** check box is automatically selected in the **Import browser data** dialog box. If you disable this policy, payment info isn't imported at first run, and users can't import it manually. If you don't configure this policy, payment info is imported at first run, and users can choose whether to import it manually during later browsing sessions. You can also set this policy as a recommendation. This option means that Microsoft Edge imports payment info on first run, but users can select or clear the **payment info** option during manual import. **Note:** This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).
ImportSavedPasswords Allow importing of saved passwords
If you don't configure this policy, no passwords are imported at first run, and users can choose whether to import them manually during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ImportSavedPasswords
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows users to import saved passwords from another browser into Microsoft Edge. If you enable this policy, the option to manually import saved passwords is automatically selected. If you disable this policy, saved passwords aren't imported on first run, and users can't import them manually. If you don't configure this policy, no passwords are imported at first run, and users can choose whether to import them manually during later browsing sessions. You can set this policy as a recommendation. This means that Microsoft Edge imports passwords on first run, but users can select or clear the **passwords** option during manual import. Note: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.
ImportSearchEngine Allow importing of search engine settings
If you don't configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ImportSearchEngine
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows users to import search engine settings from another browser into Microsoft Edge. If you enable, this policy, the option to import search engine settings is automatically selected. If you disable this policy, search engine settings aren't imported at first run, and users can't import them manually. If you don't configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions. You can set this policy as a recommendation. This option means that Microsoft Edge imports search engine settings on first run, but users can select or clear the **search engine** option during manual import. **Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).
ImportShortcuts Allow importing of shortcuts
If you don't configure this policy, Shortcuts are imported on first run.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ImportShortcuts
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 81, Windows 7 or later
- Template
- msedge.admx
Allows users to import Shortcuts from another browser into Microsoft Edge. If you disable this policy, Shortcuts aren't imported on first run. If you don't configure this policy, Shortcuts are imported on first run. You can also set this policy as a recommendation. This means that Microsoft Edge imports Shortcuts on first run. Note: This policy currently manages import from Google Chrome (on Windows 7, 8, and 10 and on macOS).
ImportStartupPageSettings Allow importing of startup page settings
If you don't configure this policy, startup settings are imported at first run, and users can choose whether to import this data manually by selecting browser settings option during later browsing sessions.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ImportStartupPageSettings
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 91, Windows 7 or later
- Template
- msedge.admx
Allows users to import Startup settings from another browser into Microsoft Edge. If you enable this policy, the Startup settings are always imported. If you disable this policy, startup settings aren't imported at first run or at manual import. If you don't configure this policy, startup settings are imported at first run, and users can choose whether to import this data manually by selecting browser settings option during later browsing sessions. You can set this policy as a recommendation. This means that Microsoft Edge will import startup settings on first run, but users can select or clear **browser settings** option during manual import. **Note**: This policy currently manages importing from Microsoft Edge Legacy and Google Chrome (on Windows 7, 8, and 10) browsers.
MSAWebSiteSSOUsingThisProfileAllowed Allow single sign-on for Microsoft personal sites using this profile
If you enable this policy or don't configure it, users can use the Settings option to ensure non-MSA profiles are able to use single sign-on for Microsoft sites using MSA credentials present on the machine provided only a single MSA account exists on the machine.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- MSAWebSiteSSOUsingThisProfileAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
'Allow single sign-on for Microsoft personal sites using this profile' option allows non-MSA profiles to be able to use single sign-on for Microsoft sites using MSA credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-MSA profiles only. If you disable this policy, non-MSA profiles can't use single sign-on for Microsoft sites using MSA credentials present on the machine. If you enable this policy or don't configure it, users can use the Settings option to ensure non-MSA profiles are able to use single sign-on for Microsoft sites using MSA credentials present on the machine provided only a single MSA account exists on the machine.
LocalProvidersEnabled Allow suggestions from local providers
If you don't configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- LocalProvidersEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 83, Windows 7 or later
- Template
- msedge.admx
Allow suggestions from suggestion providers on the device (local providers), for example, Favorites and Browsing History, in Microsoft Edge's Address Bar and Auto-Suggest List. If you enable this policy, suggestions from local providers are used. If you disable this policy, suggestions from local providers are never used. Local history and local favorites suggestions won't appear. If you don't configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle. Some features may not be available if a policy to disable this feature has been applied. For example, Browsing History suggestions will not be available if you enable the 'SavingBrowserHistoryDisabled' (Disable saving browser history) policy. This policy requires a browser restart to finish applying.
OrganizationalBrandingOnWorkProfileUIEnabled Allow the use of your organization's branding assets from Microsoft Entra on the profile-related UI of a work or school profile
If you disable or don't configure this policy, your organization's branding assets from Entra aren't used.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- OrganizationalBrandingOnWorkProfileUIEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 119, Windows 7 or later
- Template
- msedge.admx
Allow the use of your organization's branding assets from Entra, if any, on the profile-related UI of a profile that's signed in with an Entra ID (formerly known as Azure Active Directory) account. This requires a browser restart to take effect. If you enable this policy, your organization's branding assets from Entra are used. If you disable or don't configure this policy, your organization's branding assets from Entra aren't used. For more information about configuring your organization's branding assets on Entra, visit https://go.microsoft.com/fwlink/?linkid=2254514.
InternetExplorerIntegrationReloadInIEModeAllowed Allow unconfigured sites to be reloaded in Internet Explorer mode
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- InternetExplorerIntegrationReloadInIEModeAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 92, Windows 7 or later
- Template
- msedge.admx
This policy allows users to reload unconfigured sites (ones that aren't configured in the Enterprise Mode Site List) in Internet Explorer mode when browsing in Microsoft Edge, and a site requires Internet Explorer for compatibility. After a site is reloaded in Internet Explorer mode, "in-page" navigation stays in Internet Explorer mode (for example, a link, script, or form on the page, or a server-side redirect from another "in-page" navigation). Users can choose to exit from Internet Explorer mode, or Microsoft Edge automatically exits from Internet Explorer mode when a navigation that isn't "in-page" occurs (for example, using the address bar, the back button, or a favorite link). Users can also optionally tell Microsoft Edge to use Internet Explorer mode for the site in the future. This choice is remembered for a length of time managed by the 'InternetExplorerIntegrationLocalSiteListExpirationDays' (Specify the number of days that a site remains on the local IE mode site list) policy. If the 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) policy is set to 'IEMode', then sites explicitly configured by the 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy's site list to use Microsoft Edge aren't reloaded in Internet Explorer mode, and sites configured by the site list or by the 'SendIntranetToInternetExplorer' (Send all intranet sites to Internet Explorer) policy to use Internet Explorer mode can't exit from Internet Explorer mode. If you enable this policy, users are allowed to reload unconfigured sites in Internet Explorer mode. If you disable this policy, users aren't allowed to reload unconfigured sites in Internet Explorer mode. If you enable this policy, it takes precedence over how you configured the 'InternetExplorerIntegrationTestingAllowed' (Allow Internet Explorer mode testing) policy, and that policy is disabled. For more information about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210
OutlookHubMenuEnabled Allow users to access the Outlook menu (obsolete)
If you enable or don't configure this policy, users can access the Outlook menu.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- OutlookHubMenuEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 102-105, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 105. This policy doesn't work because the Outlook menu is now contained within the Edge Sidebar and can be managed using the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy. This policy is used to manage access to the Outlook menu from Microsoft Edge. If you enable or don't configure this policy, users can access the Outlook menu. If you disable this policy, users can't access the Outlook menu.
SiteSafetyServicesEnabled Allow users to configure Site safety services (obsolete)
If you enable this policy or don't configure it, the top site info will be shown.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- SiteSafetyServicesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 101-127, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 127. This policy is obsolete as the feature is being removed after Microsoft Edge version 127. This policy disables site safety services from showing top site info in the page info dialog. If you enable this policy or don't configure it, the top site info will be shown. If you disable this policy, the top site info won't be shown.
OrganizationLogoOverlayOnAppIconEnabled Allow your organization's logo from Microsoft Entra to be overlaid on the Microsoft Edge app icon of a work or school profile
If you disable or don't configure this policy, your organization's logo from Entra won't be used.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- OrganizationLogoOverlayOnAppIconEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 120, Windows 7 or later
- Template
- msedge.admx
Allows your organization's logo from Entra, if any, to be overlaid on the Microsoft Edge app icon of a profile that's signed in with an Entra ID (formerly known as Azure Active Directory) account. This requires a browser restart to take effect. If you enable this policy, your organization's logo from Entra is used. If you disable or don't configure this policy, your organization's logo from Entra won't be used. For more information about configuring your organization's logo on Entra, visit https://go.microsoft.com/fwlink/?linkid=2254514.
SmartActionsBlockList_recommended Block smart actions for a list of services
If you disable or don't configure this policy: - The smart action in the mini and full context menu is enabled for all profiles.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- List subkey
- Software\Policies\Microsoft\Edge\Recommended\SmartActionsBlockList
- Supported on
- Microsoft Edge version 89, Windows 7 or later
- Template
- msedge.admx
List specific services, such as PDFs, and websites that don't show smart actions. (Smart actions are actions like "define" which are available in full and mini context menus in Microsoft Edge.) If you enable the policy: - The smart action in the mini and full context menu is disabled for all profiles for services that match the given list. - Users won't see the smart action in the mini and full context menu on text selection for services that match the given list. - In Microsoft Edge settings, the smart action in the mini and full context menu is disabled for services that match the given list. If you disable or don't configure this policy: - The smart action in the mini and full context menu is enabled for all profiles. - Users will see the smart action in the mini and full context menu on text selection. - In Microsoft Edge settings, the smart action in the mini and full context menu is enabled. Policy options mapping: * smart_actions (smart_actions) = Smart actions in pdfs and on websites * smart_actions_website (smart_actions_website) = Smart actions on websites * smart_actions_pdf (smart_actions_pdf) = Smart actions in PDF Use the preceding information when configuring this policy. Example value: smart_actions smart_actions_website smart_actions_pdf
BlockThirdPartyCookies Block third party cookies
If you don't configure this policy, third-party cookies are allowed by default, but users can change this setting.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- BlockThirdPartyCookies
- Enabled / Disabled
- 1 / 0
- Stated default
- If you don't configure this policy, third-party cookies are allowed by default, but users can change this setting. In InPrivate, third-party cookies are blocked by default and can only be allowed at the site level using the CookiesAllowedForUrls policy.
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
This policy controls whether third-party cookies are blocked in regular browsing sessions. If you enable this policy, web page elements that are not from the domain shown in the address bar can't set cookies. If you disable this policy, third-party cookies are allowed, including from domains other than the one shown in the address bar. If you don't configure this policy, third-party cookies are allowed by default, but users can change this setting. Note: This policy doesn't apply in InPrivate mode. In InPrivate, third-party cookies are blocked by default and can only be allowed at the site level using the CookiesAllowedForUrls policy.
ClearBrowsingDataOnExit Clear browsing data when Microsoft Edge closes
Note that if you enable this policy, it takes precedence over how you configured 'DefaultCookiesSetting' (Configure cookies) If you disable or don't configure this policy, users can configure the Clear browsing data option in Settings. If you enable this policy, don't configure the 'AllowDeletingBrowserHistory' (Enable deleting browser and download history) or the 'ClearCachedImagesAndFilesOnExit' (Clear cached images and files when Microsoft Edge closes) policy, because they all deal with deleting browsing data.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ClearBrowsingDataOnExit
- Enabled / Disabled
- 1 / 0
- Stated default
- Microsoft Edge doesn't clear the browsing data by default when it closes.
- Supported on
- Microsoft Edge version 78, Windows 7 or later
- Template
- msedge.admx
Microsoft Edge doesn't clear the browsing data by default when it closes. Browsing data includes information entered in forms, passwords, and even the websites visited. If you enable this policy, all browsing data is deleted each time Microsoft Edge closes. Note that if you enable this policy, it takes precedence over how you configured 'DefaultCookiesSetting' (Configure cookies) If you disable or don't configure this policy, users can configure the Clear browsing data option in Settings. If you enable this policy, don't configure the 'AllowDeletingBrowserHistory' (Enable deleting browser and download history) or the 'ClearCachedImagesAndFilesOnExit' (Clear cached images and files when Microsoft Edge closes) policy, because they all deal with deleting browsing data. If you configure the preceding policies and this policy, all browsing data is deleted when Microsoft Edge closes, regardless of how you configured 'AllowDeletingBrowserHistory' or 'ClearCachedImagesAndFilesOnExit'. To exclude cookies from being deleted on exit, configure the 'SaveCookiesOnExit' (Save cookies when Microsoft Edge closes) policy. To exclude passwords from being deleted on exit, configure the 'PasswordDeleteOnBrowserCloseEnabled' (Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes) policy.
ClearCachedImagesAndFilesOnExit Clear cached images and files when Microsoft Edge closes
If you don't configure this policy, users can choose whether cached images and files are cleared on exit.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ClearCachedImagesAndFilesOnExit
- Enabled / Disabled
- 1 / 0
- Stated default
- Microsoft Edge doesn't clear cached images and files by default when it closes.
- Supported on
- Microsoft Edge version 83, Windows 7 or later
- Template
- msedge.admx
Microsoft Edge doesn't clear cached images and files by default when it closes. If you enable this policy, cached images and files are deleted each time Microsoft Edge closes. If you disable this policy, users can't configure the cached images and files option in edge://settings/clearBrowsingDataOnClose. If you don't configure this policy, users can choose whether cached images and files are cleared on exit. If you disable this policy, don't enable the 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) policy, because they both deal with deleting data. If you configure both, the 'ClearBrowsingDataOnExit' policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured 'ClearCachedImagesAndFilesOnExit' (Clear cached images and files when Microsoft Edge closes).
AutomaticHttpsDefault Configure Automatic HTTPS (obsolete)
If set to "AlwaysUpgrade" or left unset, this feature is enabled by default.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- AutomaticHttpsDefault
- Supported on
- Microsoft Edge version 92-139, Windows 7 or later
- Template
- msedge.admx
0Automatic HTTPS functionality is disabled.1(Deprecated) Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.2All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 139. This policy lets you manage settings for 'AutomaticHttpsDefault' (Configure Automatic HTTPS), which switches connections from HTTP to HTTPS. This feature helps protect against man-in-the-middle attacks by enforcing more secure connections, but users might experience more connection errors. Microsoft Edge attempts to upgrade some navigations from HTTP to HTTPS, when possible. This policy can be used to disable this behavior. If set to "AlwaysUpgrade" or left unset, this feature is enabled by default. The separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature. This policy is obsolete, and is replaced with the policy 'HttpsUpgradesEnabled' (Enable automatic HTTPS upgrades). Policy options mapping: * DisableAutomaticHttps (0) = Automatic HTTPS functionality is disabled. * UpgradeCapableDomains (1) = (Deprecated) Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS. * AlwaysUpgrade (2) = All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often. Use the preceding information when configuring this policy.
ConfigureFriendlyURLFormat Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users
* Not configured = The users are able to choose their preferred paste format.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ConfigureFriendlyURLFormat
- Stated default
- By default, this is set to the friendly URL format.
- Supported on
- Microsoft Edge version 87, Windows 7 or later
- Template
- msedge.admx
1The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.3Titled Hyperlink: A hyperlink that points to the copied URL but whose visible text is the title of the destination page. This is the Friendly URL format.4Coming soon. If set, behaves the same as 'Plain URL'.If FriendlyURLs are enabled, Microsoft Edge computes more representations of the URL and places them on the clipboard. This policy configures what format is pasted when the user pastes in external applications or inside Microsoft Edge without the 'Paste as' context menu item. If you configure this policy, it makes a choice on behalf of the user. The options in edge://settings/shareCopyPaste will be grayed out, and the options in the 'Paste As' context menu won't be available. * Not configured = The users are able to choose their preferred paste format. By default, this is set to the friendly URL format. The 'Paste As' menu will be available in Microsoft Edge. * 1 = No additional formats are stored on the clipboard. There will be no 'Paste as' context menu item in Microsoft Edge, and the only format available to paste will be the plain text URL format. Effectively, the friendly URL feature is disabled. * 3 = The user gets a friendly URL whenever they paste into surfaces that accept rich text. The plain URL is still available for nonrich surfaces. There will be no 'Paste As' menu in Microsoft Edge. * 4 = (Not currently used) The richer formats may not be supported in some paste destinations and/or websites. In these scenarios, the plain URL option is recommended when configuring this policy. The recommended policy is available in Microsoft Edge 105 or later. Policy options mapping: * PlainText (1) = The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description. * TitledHyperlink (3) = Titled Hyperlink: A hyperlink that points to the copied URL but whose visible text is the title of the destination page. This is the Friendly URL format. * WebPreview (4) = Coming soon. If set, behaves the same as 'Plain URL'. Use the preceding information when configuring this policy.
BackgroundModeEnabled Continue running background apps after Microsoft Edge closes
If you don't configure this policy, background mode is initially turned off, and the user can configure its behavior in edge://settings/system.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- BackgroundModeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows Microsoft Edge processes to start at OS sign-in and keep running after the last browser window is closed. In this scenario, background apps and the current browsing session remain active, including any session cookies. An open background process displays an icon in the system tray and can always be closed from there. If you enable this policy, background mode is turned on. If you disable this policy, background mode is turned off. If you don't configure this policy, background mode is initially turned off, and the user can configure its behavior in edge://settings/system.
Microsoft365CopilotChatIconEnabled Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar
If the policy isn't configured: Otherwise, Copilot shows in the toolbar and users can enable or disable Copilot from showing by using the Show Copilot toggle in settings.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- Microsoft365CopilotChatIconEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 139, Windows 7 or later
- Template
- msedge.admx
For users in an Entra ID Microsoft Edge profile, this policy controls whether the Microsoft 365 Copilot Chat icon is shown in the Microsoft Edge for Business toolbar for Microsoft 365 Copilot licensed and unlicensed users. This policy only applies when users are accessing Copilot in the sidepane. If the policy is enabled: Copilot appears in the toolbar. If the policy is disabled: Copilot doesn't appear in the toolbar. If the policy isn't configured: Otherwise, Copilot shows in the toolbar and users can enable or disable Copilot from showing by using the Show Copilot toggle in settings.
AllowBrowsingWithCopilot Controls the availability of browsing with Copilot in Microsoft Edge.
If you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- AllowBrowsingWithCopilot
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 148, Windows 7 or later
- Template
- msedge.admx
When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically. Browsing with Copilot is available only on domains specified in the 'BrowsingWithCopilotAllowList' (Browsing with Copilot Allowed URLs) policy and is blocked on domains specified in the 'BrowsingWithCopilotBlockList' (Browsing with Copilot Blocked URLs) policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled. This feature is available only to users with an active Microsoft 365 Copilot subscription. For more information about configuring browsing with Copilot, see https://go.microsoft.com/fwlink/?LinkId=2341535. If you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off. If you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on. If you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.
SyncDisabled Disable synchronization of data using Microsoft sync services
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- SyncDisabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing. This policy disables cloud synchronization only and has no impact on the 'RoamingProfileSupportEnabled' (Enable using roaming copies for Microsoft Edge profile data) policy. If you don't set this policy or apply it as recommended, users can turn on or turn off sync. If you apply this policy as mandatory, users won't be able to turn on sync.
EdgeDiscoverEnabled Discover feature In Microsoft Edge (obsolete)
If you enable or don't configure this policy, you can use the Discover button on Microsoft Edge to start using this feature.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- EdgeDiscoverEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 97-105, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 105. This policy doesn't work because Discover is now contained within the Edge Sidebar and can be managed using the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy. This policy lets you configure the Discover feature in Microsoft Edge. Working in the background when enabled, this feature sends URLs to Microsoft Bing to search for related recommendations. If you enable or don't configure this policy, you can use the Discover button on Microsoft Edge to start using this feature. If you disable this policy, you can't use the Discover feature in Microsoft Edge.
Edge3PSerpTelemetryEnabled Edge 3P SERP Telemetry Enabled
If you enable or don't configure this policy, Edge 3P SERP Telemetry feature is enabled.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- Edge3PSerpTelemetryEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 120, Windows 7 or later
- Template
- msedge.admx
Edge3P Telemetry in Microsoft Edge captures the searches that a user does on third-party search providers without identifying the person or the device only if the user has consented to this collection of data. User can turn off the collection at any time in the browser settings. If you enable or don't configure this policy, Edge 3P SERP Telemetry feature is enabled. If you disable this policy, Edge 3P SERP Telemetry feature is disabled.
EdgeWalletEtreeEnabled Edge Wallet E-Tree Enabled (deprecated)
If you enable or don't configure this policy, users can use the Edge Wallet E-Tree feature.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- EdgeWalletEtreeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 117, Windows 7 or later
- Template
- msedge.admx
DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. This policy is deprecated because the E-Tree feature has been removed from Microsoft Edge. If you enable or don't configure this policy, users can use the Edge Wallet E-Tree feature. If you disable this policy, users can't use the Edge Wallet E-Tree feature.
AutofillAddressEnabled Enable AutoFill for addresses
If you have enabled or not configured this policy, users manage AutoFill for addresses in Microsoft Edge settings.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- AutofillAddressEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enables the AutoFill feature and allows users to autocomplete address information in web forms through previously stored information. If you have enabled or not configured this policy, users manage AutoFill for addresses in Microsoft Edge settings. AutoFill allows users to complete address fields in web forms using previously saved information. If you have disabled this policy, Microsoft Edge doesn't suggest, fill in, or save address information. AutoFill is also disabled for all web forms except payment and password fields, and previously saved addresses aren't available. If you disable this policy, then 'EdgeAutofillMlEnabled' (Machine learning powered autofill suggestions) is turned off. If you disable this policy, all activities for all web forms are stopped, except payment and password forms. No further entries are saved, and Microsoft Edge doesn't suggest or AutoFill any previous entries.
AutofillCreditCardEnabled Enable AutoFill for payment instruments
If you enable this policy or don't configure it, users can control AutoFill for payment instruments.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- AutofillCreditCardEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enables Microsoft Edge's AutoFill feature and lets users auto complete payment instruments like credit or debit cards in web forms using previously stored information. Includes suggesting new payment instruments like Buy Now Pay Later (BNPL) in web forms and Express Checkout. If you enable this policy or don't configure it, users can control AutoFill for payment instruments. If you disable this policy, AutoFill never suggests, fills, or recommends new payment Instruments. Additionally, it won't save any payment instrument information that users submit while browsing the web.
AddressBarClipboardSuggestEnabled Enable clipboard suggestions in the address bar
If you enable this policy or don't configure it, Microsoft Edge may show suggestions based on clipboard content in the address bar suggestion dropdown.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- AddressBarClipboardSuggestEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 151, Windows 7 or later
- Template
- msedge.admx
This policy controls whether suggestions based on clipboard content are shown in the address bar suggestion dropdown. If you enable this policy or don't configure it, Microsoft Edge may show suggestions based on clipboard content in the address bar suggestion dropdown. If you disable this policy, Microsoft Edge doesn't show suggestions based on clipboard content in the address bar suggestion dropdown.
FavoritesBarEnabled Enable favorites bar
If this policy is not configured, then the user can decide to use the favorites bar or not.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- FavoritesBarEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enables or disables the favorites bar. If you enable this policy, users will see the favorites bar. If you disable this policy, users won't see the favorites bar. If this policy is not configured, then the user can decide to use the favorites bar or not.
NetworkPredictionOptions Enable network prediction
If you don't configure this policy, network prediction is enabled but the user can change it.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- NetworkPredictionOptions
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
0Predict network actions on any network connection1Not supported, if this value is used it will be treated as if 'Predict network actions on any network connection' (0) was set2Don't predict network actions on any network connectionEnables network prediction and prevents users from changing this setting. This controls DNS prefetching, TCP and SSL preconnection, and prerendering of web pages. If you don't configure this policy, network prediction is enabled but the user can change it. Policy options mapping: * NetworkPredictionAlways (0) = Predict network actions on any network connection * NetworkPredictionWifiOnly (1) = Not supported, if this value is used it will be treated as if 'Predict network actions on any network connection' (0) was set * NetworkPredictionNever (2) = Don't predict network actions on any network connection Use the preceding information when configuring this policy.
OriginKeyedProcessesEnabled Enable origin-keyed process isolation for improved security
By default, this feature is disabled.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- OriginKeyedProcessesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 141, Windows 7 or later
- Template
- msedge.admx
This policy enables origin-keyed process isolation for most pages, which improves security by separating content from different origins into distinct processes. This can increase the number of processes created. Users can override this setting by using command-line flags or edge://flags to turn the feature on or off. If you enable this policy, most origins are isolated, even from other origins within the same site. For related configuration, see the IsolateOrigins and SitePerProcess policies. If you disable this policy, origins can't be isolated from the rest of their site unless the origin explicitly requests isolation. If you don’t configure this policy, the browser decides which origins to isolate and when. By default, this feature is disabled. The default state can change in the future.
ResolveNavigationErrorsUseWebService Enable resolution of navigation errors using a web service
If you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ResolveNavigationErrorsUseWebService
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allow Microsoft Edge to issue a dataless connection to a web service to probe networks for connectivity in cases like hotel and airport Wi-Fi. If you enable this policy, a web service is used for network connectivity tests. If you disable this policy, Microsoft Edge uses native APIs to try to resolve network connectivity and navigation issues. **Note**: Except on Windows 8 and later versions of Windows, Microsoft Edge *always* uses native APIs to resolve connectivity issues. If you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy. Specifically, there's a **Use a web service to help resolve navigation errors** toggle, which the user can switch on or off. Be aware that if you have enabled this policy (ResolveNavigationErrorsUseWebService), the **Use a web service to help resolve navigation errors** setting is turned on, but the user can't change the setting by using the toggle. If you have disabled this policy, the **Use a web service to help resolve navigation errors** setting is turned off, and the user can't change the setting by using the toggle.
SearchSuggestEnabled Enable search suggestions
If this policy is left not set, search suggestions are enabled but the user can change that.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- SearchSuggestEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enables web search suggestions in Microsoft Edge's Address Bar and Auto-Suggest List and prevents users from changing this policy. If you enable this policy, web search suggestions are used. If you disable this policy, web search suggestions are never used, however local history and local favorites suggestions still appear. If you disable this policy, neither the typed characters, nor the URLs visited will be included in telemetry to Microsoft. If this policy is left not set, search suggestions are enabled but the user can change that.
ShowTabPreviewEnabled Enable tab preview on hover
If you enable or don't configure this policy, Microsoft Edge shows a tab preview when the user hovers over a tab.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ShowTabPreviewEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 141, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Microsoft Edge displays a preview of the tab content when the user hovers over a tab. If you enable or don't configure this policy, Microsoft Edge shows a tab preview when the user hovers over a tab. If you disable this policy, tab previews aren't shown on hover.
CopilotNewTabPageEnabled Enable the Copilot new tab page
If you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy is not configured, users can turn it on via user settings.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- CopilotNewTabPageEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 148, Windows 7 or later
- Template
- msedge.admx
This policy configures the availability of the Copilot new tab page in Microsoft Edge for Business. The Copilot new tab page combines search and chat into a single input box and includes personalized cards that provide quick access to relevant files, calendar events, and suggested Copilot prompts. Users who do not have a Microsoft 365 Copilot license might experience limited relevance in Copilot prompt card content. Most policies that customize the New Tab Page are supported on the Copilot new tab page. For a complete list of supported and unsupported policies, see https://go.microsoft.com/fwlink/?linkid=2330462. This policy applies only to Microsoft Entra ID profiles and controls the Copilot new tab page experience in Microsoft Edge for Business. This policy does not apply to the Copilot new tab page on MSA profiles. If you enable this policy, the Copilot new tab page is turned on. If you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy is not configured, users can turn it on via user settings.
TranslateEnabled Enable Translate
If you don't configure this policy, the policy is enabled by default.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- TranslateEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enables the integrated Microsoft translation service on Microsoft Edge. If you enable this policy, Microsoft Edge offers to translate a webpage by showing an integrated translate flyout when the language detected on a webpage isn't listed under preferred languages. A translate option is available on the right-click context menu. Users can also translate selected text on a webpage via the right-click context menu, or on a PDF via the PDF toolbar and the right-click context menu. If you don't configure this policy, the policy is enabled by default. Users can choose whether to use the translation functionality or not. You can disable this policy to disable all built-in translate features.
TravelAssistanceEnabled Enable travel assistance (obsolete)
If you enable or don't configure this setting, travel assistance is enabled for the users when they are performing travel-related tasks.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- TravelAssistanceEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 93-105, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 105. This policy is obsolete as the feature is now contained within the Edge Sidebar and can be managed using the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy. It doesn't work in Microsoft Edge after version 105. Configure this policy to allow/disallow travel assistance. The travel assistance feature gives helpful and relevant information to a user who performs a travel-related task within the browser. This feature provides trusted and validated suggestions/information to the users from across sources gathered by Microsoft. If you enable or don't configure this setting, travel assistance is enabled for the users when they are performing travel-related tasks. If you disable this setting, travel assistance will be disabled, and users won't be able to see any travel-related recommendations.
EdgeWalletCheckoutEnabled Enable Wallet Checkout feature
If you enable or don't configure this policy, users can choose whether to use wallet checkout while shopping on Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- EdgeWalletCheckoutEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 114, Windows 7 or later
- Template
- msedge.admx
Enables Wallet Checkout feature in Microsoft Edge. If you enable or don't configure this policy, users can choose whether to use wallet checkout while shopping on Microsoft Edge. If you disable this policy, users can't use wallet checkout while shopping on Microsoft Edge.
LocalBrowserDataShareEnabled Enable Windows to search local Microsoft Edge browsing data
If you enable this policy or don't configure it, Microsoft Edge publishes local browsing data to the Windows Indexer.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- LocalBrowserDataShareEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
Enables Windows to index Microsoft Edge browsing data stored locally on the user's device and allows users to find and launch previously stored browsing data directly from Windows features such as the search box on the taskbar in Windows. If you enable this policy or don't configure it, Microsoft Edge publishes local browsing data to the Windows Indexer. If you disable this policy, Microsoft Edge won't share data to the Windows Indexer. Note that if you disable this policy, Microsoft Edge removes the data shared with Windows on the device and stops sharing any new browsing data.
QuickSearchShowMiniMenu Enables Microsoft Edge mini menu
If you enable or don't configure this policy, selecting text on websites or PDFs shows the mini menu.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- QuickSearchShowMiniMenu
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 104, Windows 7 or later
- Template
- msedge.admx
Enables the Microsoft Edge mini menu on websites and PDFs. The mini menu appears when users select text and provides basic actions like Copy and smart actions such as Definitions. If you enable or don't configure this policy, selecting text on websites or PDFs shows the mini menu. If you disable this policy, the mini menu doesn't appear when users select text on websites or PDFs. Note: Starting in Microsoft Edge for Mac version 143, this policy is obsolete because the mini menu feature is removed on Mac.
AskBeforeCloseEnabled Get user confirmation before closing a browser window with multiple tabs
If you disable or don't configure this policy, a browser window with multiple tabs will close immediately without user confirmation.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- AskBeforeCloseEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 104, Windows 7 or later
- Template
- msedge.admx
This policy lets you configure whether users see a confirmation dialog before closing a browser window with multiple tabs. This dialog asks users to confirm that the browser window can be closed. If you enable this policy, users will be presented with a confirmation dialog when closing a browser window with multiple tabs. If you disable or don't configure this policy, a browser window with multiple tabs will close immediately without user confirmation.
EdgeAutofillMlEnabled Machine learning powered autofill suggestions
If you enable this policy or don't configure it, users can benefit from machine learning powered autofill suggestions, which improve efficiency by offering more accurate, context aware form recommendations based on historical autofill data.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- EdgeAutofillMlEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 132, Windows 7 or later
- Template
- msedge.admx
Allows ML technology to predict and fill in forms and text fields for better browsing. Your personal data is secure and isn't used elsewhere. If you enable this policy or don't configure it, users can benefit from machine learning powered autofill suggestions, which improve efficiency by offering more accurate, context aware form recommendations based on historical autofill data. If you disable this policy, machine learning-powered autofill suggestions aren't shown, and autofill no longer uses cloud-based machine learning models to enhance form filling with smarter, context aware suggestions. Instead, autofill will rely on basic form data without the benefits of machine learning. This policy will be disabled if you disable 'AutofillAddressEnabled' (Enable AutoFill for addresses).
ManagedSearchEngines Manage Search Engines
If you disable or don't configure this policy, users can modify the search engines list as desired.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ManagedSearchEngines
- Stated default
- If allow_search_engine_discovery isn't specified, search engine discovery is disabled by default.
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Lets you configure a list of up to 10 search engines, one of which must be marked as the default search engine. With Microsoft Edge version 100, you can configure up to 100 engines. You don't need to specify the encoding. With Microsoft Edge version 80, the suggest_url and image_search_url parameters are optional. The optional parameter, image_search_post_params (consists of comma-separated name/value pairs), is available starting in Microsoft Edge version 80. With Microsoft Edge version 83, you can enable search engine discovery with the optional allow_search_engine_discovery parameter. This parameter must be the first item in the list. If allow_search_engine_discovery isn't specified, search engine discovery is disabled by default. With Microsoft Edge version 84, you can set this policy as a recommended policy to allow search provider discovery. You don't need to add the optional allow_search_engine_discovery parameter. With Microsoft Edge version 100, setting this policy as a recommended policy also allows users to manually add new search engines from their Microsoft Edge settings. If you enable this policy, users can't add, remove, or change any search engine in the list. Users can set their default search engine to any search engine in the list. If you disable or don't configure this policy, users can modify the search engines list as desired. If the 'DefaultSearchProviderSearchURL' (Default search provider search URL) policy is set, this policy (ManagedSearchEngines) is ignored. The user must restart their browser to finish applying this policy. Example value: [ { "allow_search_engine_discovery": true }, { "is_default": true, "keyword": "example1.com", "name": "Example1", "search_url": "https://www.example1.com/search?q={searchTerms}", "suggest_url": "https://www.example1.com/qbox?query={searchTerms}" }, { "image_search_post_params": "content={imageThumbnail},url={imageURL},sbisrc={SearchSource}", "image_search_url": "https://www.example2.com/images/detail/search?iss=sbiupload", "keyword": "example2.com", "name": "Example2", "search_url": "https://www.example2.com/search?q={searchTerms}", "suggest_url": "https://www.example2.com/qbox?query={searchTerms}" }, { "encoding": "UTF-8", "image_search_url": "https://www.example3.com/images/detail/search?iss=sbiupload", "keyword": "example3.com", "name": "Example3", "search_url": "https://www.example3.com/search?q={searchTerms}", "suggest_url": "https://www.example3.com/qbox?query={searchTerms}" }, { "keyword": "example4.com", "name": "Example4", "search_url": "https://www.example4.com/search?q={searchTerms}" } ]
NewPDFReaderEnabled Microsoft Edge built-in PDF reader powered by Adobe Acrobat enabled
If you disable or don't configure this policy, Microsoft Edge will use the existing PDF reader to open all PDF files.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- NewPDFReaderEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 111, Windows 7 or later
- Template
- msedge.admx
The policy lets Microsoft Edge launch the new version of the built-in PDF reader that's powered by Adobe Acrobat's PDF rendering engine. The new PDF reader ensures that there's no loss of functionality and delivers an enhanced PDF experience. This experience includes richer rendering, improved performance, strong security for PDF handling, and greater accessibility. If you enable this policy, Microsoft Edge will use the new Adobe Acrobat powered built-in PDF reader to open all PDF files. If you disable or don't configure this policy, Microsoft Edge will use the existing PDF reader to open all PDF files.
RedirectSitesFromInternetExplorerRedirectMode Redirect incompatible sites from Internet Explorer to Microsoft Edge
If you don't configure this policy: - Starting with Microsoft Edge major release 87, you have the same experience as setting the policy to 'Sitelist': Internet Explorer redirects sites that require a modern browser to Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- RedirectSitesFromInternetExplorerRedirectMode
- Supported on
- Microsoft Edge version 87, Windows 7 or later
- Template
- msedge.admx
0Prevent redirection1Redirect sites based on the incompatible sites sitelistThis setting lets you specify whether Internet Explorer redirects navigations to sites that require a modern browser to Microsoft Edge. If you set this policy to 'Disable' ('Prevent redirection', value 0), Internet Explorer doesn't redirect any traffic to Microsoft Edge. If you set this policy to 'Sitelist', starting with Microsoft Edge major release 87, Internet Explorer (IE) redirects sites that require a modern browser to Microsoft Edge. (Note: The Sitelist setting is 'Redirect sites based on the incompatible sites sitelist', value 1.) When a site is redirected from Internet Explorer to Microsoft Edge, the Internet Explorer tab that started loading the site is closed if it had no prior content. Otherwise, the user is taken to a Microsoft help page that explains why the site was redirected to Microsoft Edge. When Microsoft Edge is launched to load an IE site, an information bar explains that the site works best in a modern browser. If you want to redirect all navigations, configure the Disable Internet Explorer 11 policy, which redirects all navigations from IE11 to Microsoft Edge. It also hides the IE11 app icon from the user after the first launch. If you don't configure this policy: - Starting with Microsoft Edge major release 87, you have the same experience as setting the policy to 'Sitelist': Internet Explorer redirects sites that require a modern browser to Microsoft Edge. - In the future, the default for your organization changes to automatically redirect all navigations. If you don't want automatic redirection, set this policy to 'Disable' or 'Sitelist'. For more information about this policy, see https://go.microsoft.com/fwlink/?linkid=2141715. Policy options mapping: * Disable (0) = Prevent redirection * Sitelist (1) = Redirect sites based on the incompatible sites sitelist Use the preceding information when configuring this policy.
AutofillMembershipsEnabled Save and fill memberships
If you don't configure this policy, users can choose whether to have their membership info automatically saved and used to fill form fields while using Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- AutofillMembershipsEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, users can choose whether to enable it or not.
- Supported on
- Microsoft Edge version 110, Windows 7 or later
- Template
- msedge.admx
This policy lets you decide whether users can have their membership info (for example, program name and membership number) automatically saved and used to fill form fields while using Microsoft Edge. By default, users can choose whether to enable it or not. If you enable this policy, users can only have their membership info automatically saved and used to fill form fields while using Microsoft Edge. If you don't configure this policy, users can choose whether to have their membership info automatically saved and used to fill form fields while using Microsoft Edge. If you disable this policy, users can't have their membership info automatically saved and used to fill form fields while using Microsoft Edge.
SearchFiltersEnabled Search Filters Enabled
If you enable or don't configure this policy, the autosuggestion dropdown defaults to displaying the ribbon of available filters.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- SearchFiltersEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 109, Windows 7 or later
- Template
- msedge.admx
Lets you filter your autosuggestions by selecting a filter from the search filters ribbon. For example, if you select the "Favorites" filter, only favorites suggestions are shown. If you enable or don't configure this policy, the autosuggestion dropdown defaults to displaying the ribbon of available filters. If you disable this policy, the autosuggestion dropdown can't display the ribbon of available filters.
ApplicationLocaleValue Set application locale
If you disable or don't configure this setting, Microsoft Edge uses either the user-specified preferred locale (if configured) or the fallback locale 'en-US'.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ApplicationLocaleValue
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Configures the application locale in Microsoft Edge and prevents users from changing the locale. If you enable this policy, Microsoft Edge uses the specified locale. If the configured locale isn't supported, 'en-US' is used instead. If you disable or don't configure this setting, Microsoft Edge uses either the user-specified preferred locale (if configured) or the fallback locale 'en-US'. Example value: en
DownloadDirectory Set download directory
If you disable or don't configure this policy, the default download directory is used, and the user can change it.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- DownloadDirectory
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Configures the directory to use when downloading files. If you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user specified one or chose to be prompted for download location every time. See https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used. If you disable or don't configure this policy, the default download directory is used, and the user can change it. If you set an invalid path, Microsoft Edge defaults to the user's default download directory. If the folder specified by the path doesn't exist, the download triggers a prompt that asks the user where they want to save their download. Example value: Linux-based OSes (including Mac): /home/${user_name}/Downloads Windows: C:\Users\${user_name}\Downloads
DefaultShareAdditionalOSRegionSetting Set the default "share additional operating system region" setting
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- DefaultShareAdditionalOSRegionSetting
- Supported on
- Microsoft Edge version 108, Windows 7 or later
- Template
- msedge.admx
0Limited1Always share the OS Regional format2Never share the OS Regional formatThis policy controls the default value for the "share additional operating system region" setting in Microsoft Edge. The "share additional operating system region" Microsoft Edge setting controls whether the OS Regional format setting is shared with the web through the default JavaScript locale. If shared, websites can query the OS Regional format using JavaScript code, for example; "Intl.DateTimeFormat().resolvedOptions().locale". The default value for the setting is "Limited". If you set this policy to "Limited", the OS Regional format is shared only if its language part matches the Microsoft Edge display language. If you set this policy to "Always", the OS Regional format is always shared. This value could cause unexpected website behavior if the OS Regional format language is different from the Microsoft Edge display language. For example, if a website uses the JavaScript default locale to format dates, the names of the days and months are displayed in one language while the surrounding text is displayed in another language. If you set this policy to "Never", the OS Regional format is never shared. Example 1: In this example the OS Regional format is set to "en-GB", and the browser display language is set to "en-US". Then the OS Regional format is shared if the policy is set to "Limited", or "Always". Example 2: In this example the OS Regional format is set to "es-MX", and the browser display language is set to "en-US". Then the OS Regional format is shared if the policy is set to "Always"; however, the OS Regional format isn't shared if the policy is set to "Limited". For more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2222282. Policy options mapping: * Limited (0) = Limited * Always (1) = Always share the OS Regional format * Never (2) = Never share the OS Regional format Use the preceding information when configuring this policy.
EdgeShoppingAssistantEnabled Shopping in Microsoft Edge Enabled
If you enable or don't configure this policy, shopping features such as price comparison, coupons, rebates, and express checkout are automatically applied for retail domains.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- EdgeShoppingAssistantEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 87, Windows 7 or later
- Template
- msedge.admx
This policy lets users compare the prices of a product they're looking at, get coupons or rebates from the website they're on, autoapply coupons, and help checkout faster using autofill data. If you enable or don't configure this policy, shopping features such as price comparison, coupons, rebates, and express checkout are automatically applied for retail domains. Coupons for the current retailer and prices from other retailers are fetched from a server. If you disable this policy, shopping features such as price comparison, coupons, rebates, and express checkout aren't automatically found for retail domains. Starting from version 90.0.818.56, the behavior of the messaging letting users know that there's a coupon, rebate, price comparison, or price history available on shopping domains is also done through a horizontal banner below the address bar. Previously, this messaging was done on the address bar.
HubsSidebarEnabled Show Hubs Sidebar
If you don't configure this policy, the Sidebar's visibility follows the user's Microsoft Edge settings.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- HubsSidebarEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 99, Windows 7 or later
- Template
- msedge.admx
The Sidebar is a launcher bar located on the right side of Microsoft Edge. If you enable this policy, the Sidebar is always visible. If you disable this policy, the Sidebar is never shown. If you don't configure this policy, the Sidebar's visibility follows the user's Microsoft Edge settings. As of Microsoft Edge version 141, the 'Microsoft365CopilotChatIconEnabled' (Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar) policy is the only means of controlling the display of Copilot in the toolbar. Note: The recommended version of this policy-also known as the "Default Settings (users can override)" policy-is obsolete. This policy has never supported the recommended capability.
ShowMicrosoftRewards Show Microsoft Rewards experiences
If you don't configure this policy: - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets see the Microsoft Rewards experience in their Microsoft Edge user profile.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ShowMicrosoftRewards
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 88, Windows 7 or later
- Template
- msedge.admx
Show Microsoft Rewards experience and notifications. If you enable this policy: - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets see the Microsoft Rewards experience in their Microsoft Edge user profile. - The setting to enable Microsoft Rewards in Microsoft Edge settings is enabled and toggled on. If you disable this policy: - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets won't see the Microsoft Rewards experience in their Microsoft Edge user profile. - The setting to enable Microsoft Rewards in Microsoft Edge settings is disabled and toggled off. If you don't configure this policy: - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets see the Microsoft Rewards experience in their Microsoft Edge user profile. - The setting to enable Microsoft Rewards in Microsoft Edge settings is enabled and toggled on.
InternetExplorerModeToolbarButtonEnabled Show the Reload in Internet Explorer mode button in the toolbar
If you disable or don't configure this policy, the Reload in Internet Explorer mode button isn't shown in the toolbar by default.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- InternetExplorerModeToolbarButtonEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 96, Windows 7 or later
- Template
- msedge.admx
Set this policy to show the Reload in Internet Explorer mode button in the toolbar. Users can hide the button in the toolbar through edge://settings/appearance. The button is only shown on the toolbar when the 'InternetExplorerIntegrationReloadInIEModeAllowed' (Allow unconfigured sites to be reloaded in Internet Explorer mode) policy is enabled or if the user chose to enable "Allow sites to be reloaded in Internet Explorer mode". If you enable this policy, the Reload in Internet mode button is pinned to the toolbar. If you disable or don't configure this policy, the Reload in Internet Explorer mode button isn't shown in the toolbar by default. Users can toggle the Show Internet Explorer mode button in edge://settings/appearance.
AADWebSiteSSOUsingThisProfileEnabled Single sign-on for work or school sites using this profile enabled
If you don't configure this policy, users can control whether to use SSO using other credentials present on the machine in edge://settings/profiles/multiProfileSettings.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- AADWebSiteSSOUsingThisProfileEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 92, Windows 7 or later
- Template
- msedge.admx
'Allow single sign-on for work or school sites using this profile' option allows non-AAD profiles to be able to use single sign-on for work or school sites using work or school credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-AAD profiles only. If you enable or disable this policy, 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' will be turned off. If you don't configure this policy, users can control whether to use SSO using other credentials present on the machine in edge://settings/profiles/multiProfileSettings.
AlternateErrorPagesEnabled Suggest similar pages when a webpage can't be found
If you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- AlternateErrorPagesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 80, Windows 7 or later
- Template
- msedge.admx
Allow Microsoft Edge to issue a connection to a web service to generate URL and search suggestions for connectivity issues such as DNS errors. If you enable this policy, a web service is used to generate url and search suggestions for network errors. If you disable this policy, no calls to the web service are made and a standard error page is shown. If you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy. Specifically, there's a **Suggest similar pages when a webpage can't be found** toggle, which the user can switch on or off. If you enable this policy (AlternateErrorPagesEnabled), the **Suggest similar pages when a webpage can't be found** setting is turned on, but the user can't change the setting by using the toggle. If you disable this policy, the **Suggest similar pages when a webpage can't be found** setting is turned off, and the user can't change the setting by using the toggle.
VisualSearchEnabled Visual search enabled
If you enable or don't configure this policy, visual search is enabled via image hover, context menu, and search in sidebar.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- VisualSearchEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 95, Windows 7 or later
- Template
- msedge.admx
Visual search lets you quickly explore more related content about entities in an image. If you enable or don't configure this policy, visual search is enabled via image hover, context menu, and search in sidebar. If you disable this policy, visual search is disabled and you can't get more info about images via hover, context menu, and search in sidebar. Note: Visual Search in Web Capture is still managed by 'WebCaptureEnabled' (Enable the Screenshot (previously named Web Capture) feature in Microsoft Edge) policy.
WalletDonationEnabled Wallet Donation Enabled (deprecated)
If you enable or don't configure this policy, users can use the Wallet Donation feature.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- WalletDonationEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 115, Windows 7 or later
- Template
- msedge.admx
DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. The Wallet Donation feature in Microsoft Edge allows users to view their donation summary, explore Nonprofit organizations (NPOs), donate to an NPO, manage their monthly donations, and view their donation history. If you enable or don't configure this policy, users can use the Wallet Donation feature. If you disable this policy, users can't use the Wallet Donation feature. This policy is deprecated because the Wallet Donation feature has been removed from Microsoft Edge.
Microsoft Edge - Default Settings (users can override) / Content settings
RegisteredProtocolHandlers Register protocol handlers
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- RegisteredProtocolHandlers
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Set this policy (recommended only) to register a list of protocol handlers. This list is merged with ones registered by the user and both are available to use. To register a protocol handler: - Set the protocol property to the scheme (for example, "mailto") - Set the URL property to the URL property of the application that handlers the scheme specified in the "protocol" field. The pattern can include a "%s" placeholder, which the handled URL replaces. Users can't remove a protocol handler registered by this policy. However, they can install a new default protocol handler to override the existing protocol handlers. In the examples in this section, the URL points to the Outlook on the Web (OWA) endpoint used in Exchange Online. If you're targeting Exchange Server (on-premises), use the following URL and replace mail.contoso.com with your organization's OWA endpoint: https://mail.contoso.com/?path=/mail/action/compose&mailtouri=%s Example value: [ { "default": true, "protocol": "mailto", "url": "https://outlook.office.com/mail/deeplink/compose?to=%s" } ]
Microsoft Edge - Default Settings (users can override) / Default search provider
NewTabPageSearchBox Configure the new tab page search box experience
If you disable or don't configure this policy and: - If the address bar default search engine is Bing, the new tab page uses the search box to search on new tabs.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- NewTabPageSearchBox
- Supported on
- Microsoft Edge version 85, Windows 7 or later
- Template
- msedge.admx
Search box (Recommended)Address barYou can configure the new tab page search box to use "Search box (Recommended)" or "Address bar" to search on new tabs. This policy only works if you set the search engine to a value other than Bing by setting the following two policies: 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL). If you disable or don't configure this policy and: - If the address bar default search engine is Bing, the new tab page uses the search box to search on new tabs. - If the address bar default search engine isn't Bing, users are offered an additional choice (use "Address bar") when searching on new tabs. If you enable this policy and set it to: - "Search box (Recommended)" ('bing'), the new tab page uses the search box to search on new tabs. - "Address bar" ('redirect'), the new tab page search box uses the address bar to search on new tabs. Policy options mapping: * bing (bing) = Search box (Recommended) * redirect (redirect) = Address bar Use the preceding information when configuring this policy. Example value: bing
DefaultSearchProviderEncodings_recommended Default search provider encodings
If not configured, the default, UTF-8, is used.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- List subkey
- Software\Policies\Microsoft\Edge\Recommended\DefaultSearchProviderEncodings
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specify the character encodings supported by the search provider. Encodings are code page names like UTF-8, GB2312, and ISO-8859-1. They're tried in the order provided. This policy is optional. If not configured, the default, UTF-8, is used. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies. Starting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy won't be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy. Example value: UTF-8 UTF-16 GB2312 ISO-8859-1
DefaultSearchProviderKeyword Default search provider keyword
If you don't configure it, no keyword activates the search provider.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- DefaultSearchProviderKeyword
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specifies the keyword, which is the shortcut used in the Address Bar to trigger the search for this provider. This policy is optional. If you don't configure it, no keyword activates the search provider. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies. Starting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy. Example value: mis
DefaultSearchProviderName Default search provider name
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- DefaultSearchProviderName
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specifies the name of the default search provider. If you enable this policy, you set the name of the default search provider. If you don't enable this policy or if you leave it empty, the host name specified by the search URL is used. 'DefaultSearchProviderName' should be set to an organization-approved encrypted search provider that corresponds to the encrypted search provider set in DTBC-0008. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies. Starting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy isn't be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy. Example value: My Intranet Search
DefaultSearchProviderSearchURL Default search provider search URL
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- DefaultSearchProviderSearchURL
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specifies the URL of the search engine used for a default search. The URL contains the string '{searchTerms}', which is replaced at query time by the terms the user is searching for. Specify Bing's search URL as: '{bing:baseURL}search?q={searchTerms}'. Specify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'. This policy is required when you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) policy; if you don't enable the latter policy, this policy is ignored. Starting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy won't be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy. Example value: https://search.contoso.com/search?q={searchTerms}
DefaultSearchProviderSuggestURL Default search provider URL for suggestions
If you don't configure it, users can't see search suggestions; they see suggestions from their browsing history and favorites.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- DefaultSearchProviderSuggestURL
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specifies the URL for the search engine used to provide search suggestions. The URL contains the string '{searchTerms}', which is replaced at query time by the text the user entered so far. This policy is optional. If you don't configure it, users can't see search suggestions; they see suggestions from their browsing history and favorites. Bing's suggest URL can be specified as: '{bing:baseURL}qbox?query={searchTerms}'. Google's suggest URL can be specified as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies. Starting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy isn't added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy. Example value: https://search.contoso.com/suggest?q={searchTerms}
DefaultSearchProviderEnabled Enable the default search provider
If these are left empty (not configured) or configured incorrectly, the user can choose the default provider. If you don't configure this policy, the default search provider is enabled, and the user can choose the default search provider and set the search provider list.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- DefaultSearchProviderEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enables the ability to use a default search provider. If you enable this policy, a user can search for a term by typing in the address bar (as long as what they type isn't a URL). You can specify the default search provider to use by enabling the rest of the default search policies. If these are left empty (not configured) or configured incorrectly, the user can choose the default provider. If you disable this policy, the user can't search from the address bar. If you enable or disable this policy, users can't change or override it. If you don't configure this policy, the default search provider is enabled, and the user can choose the default search provider and set the search provider list. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX. Starting in Microsoft Edge 84, you can set this policy as a recommended policy.
DefaultSearchProviderImageURLPostParams Parameters for an image URL that uses POST
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- DefaultSearchProviderImageURLPostParams
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
If you enable this policy, it specifies the parameters used when an image search that uses POST is performed. The policy consists of comma-separated name/value pairs. If a value is a template parameter, like {imageThumbnail} in the preceding example, it's replaced with real image thumbnail data. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies. Specify Bing's Image Search URL Post Params as: 'imageBin={google:imageThumbnailBase64}'. Specify Google's Image Search URL Post Params as: 'encoded_image={google:imageThumbnail},image_url={google:imageURL},sbisrc={google:imageSearchSource},original_width={google:imageOriginalWidth},original_height={google:imageOriginalHeight}'. If you don't set this policy, image search requests are sent using the GET method. Starting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy. Example value: content={imageThumbnail},url={imageURL},sbisrc={SearchSource}
DefaultSearchProviderImageURL Specifies the search-by-image feature for the default search provider
If you don't configure it, image search isn't available.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- DefaultSearchProviderImageURL
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specifies the URL to the search engine used for image search. Search requests are sent using the GET method. This policy is optional. If you don't configure it, image search isn't available. Specify Bing's Image Search URL as: '{bing:baseURL}images/detail/search?iss=sbiupload&FORM=ANCMS1#enterInsights'. Specify Google's Image Search URL as: '{google:baseURL}searchbyimage/upload'. See 'DefaultSearchProviderImageURLPostParams' (Parameters for an image URL that uses POST) policy to finish configuring image search. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies. Starting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy. Example value: https://search.contoso.com/searchbyimage/upload
Microsoft Edge - Default Settings (users can override) / Downloads
ShowDownloadsInsecureWarningsEnabled Enable insecure download warnings
If you enable or don't configure this policy, when a user tries to download potentially dangerous content from an HTTP site, the user receives a UI warning, such as "Insecure download blocked".
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ShowDownloadsInsecureWarningsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 128, Windows 7 or later
- Template
- msedge.admx
Enables warnings when potentially dangerous content is downloaded over HTTP. If you enable or don't configure this policy, when a user tries to download potentially dangerous content from an HTTP site, the user receives a UI warning, such as "Insecure download blocked". The user can still download the item. If you disable this policy, the warnings for insecure downloads are suppressed.
DefaultDownloadDirectory Set default download directory
If you don't configure this policy, Microsoft Edge uses the platform-specific default download directory.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- DefaultDownloadDirectory
- Supported on
- Microsoft Edge version 147, Windows 7 or later
- Template
- msedge.admx
This policy sets the default directory that Microsoft Edge uses to download files. Users can change the directory through browser settings. If you don't configure this policy, Microsoft Edge uses the platform-specific default download directory. This policy has no effect if the DownloadDirectory policy is set. For a list of supported variables, see https://learn.microsoft.com/en-us/deployedge/edge-learnmore-create-user-directory-vars . Example value: /home/${user_name}/Downloads
Microsoft Edge - Default Settings (users can override) / Edge Website Typo Protection settings
TyposquattingCheckerEnabled Configure Edge Website Typo Protection
If you don't configure this policy, Edge Website Typo Protection is turned on but users can choose whether to use Edge Website Typo Protection.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- TyposquattingCheckerEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, Edge Website Typo Protection is turned on.
- Supported on
- Microsoft Edge version 96, Windows 7 or later
- Template
- msedge.admx
This policy setting lets you configure whether to turn on Edge Website Typo Protection. Edge Website Typo Protection provides warning messages to help protect your users from potential typosquatting sites. By default, Edge Website Typo Protection is turned on. If you enable this policy, Edge Website Typo Protection is turned on. If you disable this policy, Edge Website Typo Protection is turned off. If you don't configure this policy, Edge Website Typo Protection is turned on but users can choose whether to use Edge Website Typo Protection.
Microsoft Edge - Default Settings (users can override) / Extensions
ControlDefaultStateOfAllowExtensionFromOtherStoresSettingEnabled Configure default state of Allow extensions from other stores setting
If the Admin first sets the policy as Enabled, but then changes it to not configured or disabled, it has no impact on user settings and the setting remains as it is. When disabled or not configured, the user can manage the Allow extensions from other store setting.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ControlDefaultStateOfAllowExtensionFromOtherStoresSettingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 101, Windows 7 or later
- Template
- msedge.admx
This policy allows you to control the default state of the Allow extensions from other stores setting. This policy can't be used to stop installation of extensions from other stores such as Chrome Web Store. To stop installation of extensions from other stores, use the Extension Settings policy: https://go.microsoft.com/fwlink/?linkid=2187098. When enabled, Allow extensions from other stores are turned on. So, users don't have to turn on the flag manually while installing extensions from other supported stores such as Chrome Web Store. However a user can override this setting. If the user turned on the setting and then turned it off, this setting may not work. If the Admin first sets the policy as Enabled, but then changes it to not configured or disabled, it has no impact on user settings and the setting remains as it is. When disabled or not configured, the user can manage the Allow extensions from other store setting.
Microsoft Edge - Default Settings (users can override) / Games settings
GamerModeEnabled Enable Gamer Mode (obsolete)
If you enable or don't configure this policy, users can opt into Gamer Mode.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- GamerModeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 117-140, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 140. Microsoft Edge Gamer Mode allows gamers to personalize their browser with gaming themes and gives them the option of enabling Efficiency Mode for PC gaming, the Gaming feed on new tabs, sidebar apps for gamers, and more. If you enable or don't configure this policy, users can opt into Gamer Mode. If you disable this policy, Gamer Mode is disabled. Note: With Microsoft Edge version 141, this policy is obsolete because the Gamer Mode feature is removed.
Microsoft Edge - Default Settings (users can override) / HTTP authentication
WindowsHelloForHTTPAuthEnabled Windows Hello For HTTP Auth Enabled
If you enable or don't configure this policy, Microsoft Edge uses Windows Credential UI.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- WindowsHelloForHTTPAuthEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 90, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Windows Credential UI is used to respond to NTLM and Negotiate authentication challenges. If you enable or don't configure this policy, Microsoft Edge uses Windows Credential UI. If you disable this policy, Microsoft Edge uses its built-in username and password prompt.
Microsoft Edge - Default Settings (users can override) / Identity and sign-in
AutomaticProfileSwitchingSiteList Configure the automatic profile switching site list
If you don't configure this policy, Microsoft Edge continues using its heuristics to automatically switch sites.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- AutomaticProfileSwitchingSiteList
- Supported on
- Microsoft Edge version 120, Windows 7 or later
- Template
- msedge.admx
Sets this policy to control which profiles Microsoft Edge uses to open sites in. Switching configurations for sites listed in this policy takes precedence over other heuristics Microsoft Edge uses for switching sites; however, sites not listed on this policy are still subject to switching by those heuristics. If you don't configure this policy, Microsoft Edge continues using its heuristics to automatically switch sites. This policy maps a URL hostname to a profile that's used to open the site. The 'site' field takes the form of a URL hostname. The 'profile' field can take one of the following values: - 'Work': The most recently used Microsoft Entra signed-in profile is used to open a 'site'. - 'Personal': The most recently used Microsoft Account (MSA) signed-in profile is used to open a 'site'. - 'No preference': The currently used profile is used to open a 'site'. - 'Wildcard email address': This takes the form of '*@contoso.com'. A profile whose username ends with the contents following the '*' is used to open a 'site'. Example value: [ { "site": "work.com", "profile": "Work" }, { "site": "personal.com", "profile": "Personal" }, { "site": "nopreference.com", "profile": "No preference" }, { "site": "contoso.com", "profile": "*@contoso.com" } ]
SignInCtaOnNtpEnabled Enable sign in click to action dialog (obsolete)
If you enable or don't configure this policy, sign in click to action dialog is shown on New tab page.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- SignInCtaOnNtpEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 99-130, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 130. Configure this policy to show sign in click to action dialog on New tab page. If you enable or don't configure this policy, sign in click to action dialog is shown on New tab page. If you disable this policy, sign in click to action dialog isn't shown on the New tab page. This policy is obsolete as the feature isn't enabled in Microsoft Edge, and this policy isn't supported for Microsoft Edge in the future.
EdgeOpenExternalLinksWithPrimaryWorkProfileEnabled Use Primary Work Profile as default to open external links
If enabled or not configured, Microsoft Edge uses the Primary Work Profile as the default for opening external links.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- EdgeOpenExternalLinksWithPrimaryWorkProfileEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 138, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Microsoft Edge uses the Primary Work Profile as the default profile when opening external links. 1. On Windows, the Primary Work Profile refers to the profile signed in with the Entra ID account used to enroll the device. 2. On macOS and Linux, the Primary Work Profile is the only profile signed in with an Entra ID account. If multiple profiles are signed in with Entra ID accounts, the Primary Work Profile setting doesn't apply. Policy behavior: 1. If enabled or not configured, Microsoft Edge uses the Primary Work Profile as the default for opening external links. 2. If disabled, the last used profile becomes the default for opening external links. Note: This policy doesn't override the following scenarios: 1. If the EdgeDefaultProfileEnabled policy is set, it takes precedence over this policy. 2. External links opened from Outlook or Microsoft Teams may be configured to launch in a specific profile, which can override the Primary Work Profile setting. 3. If the user sets a preference for "Default profile for external links" in Profile preferences, that setting takes effect.
Microsoft Edge - Default Settings (users can override) / Password manager and protection
PasswordMonitorAllowed Allow users to be alerted if their passwords are found to be unsafe
If you don't configure the policy, users can turn this feature on or off.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- PasswordMonitorAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 85, Windows 7 or later
- Template
- msedge.admx
Allow Microsoft Edge to monitor user passwords. If you enable this policy, the user gets alerted if any of their passwords stored in Microsoft Edge are found to be unsafe. Microsoft Edge will show an alert and this information will also be available in Settings > Passwords > Password Monitor. If you disable this policy, users aren't asked for permission to enable this feature. Their passwords aren't scanned, and they aren't alerted either. If you don't configure the policy, users can turn this feature on or off. To learn more about how Microsoft Edge finds unsafe passwords see https://go.microsoft.com/fwlink/?linkid=2133833 Additional guidance: This policy can be set as both Recommended and Mandatory, however with an important callout. Mandatory enabled: If the policy is set to Mandatory enabled, the UI in Settings will be disabled but remain in 'On' state, and a briefcase icon will be made visible next to it with this description displayed on hover - "This setting is managed by your organization." Recommended enabled: If the policy is set to Recommended enabled, the UI in Settings will remain in 'Off' state, but a briefcase icon will be made visible next to it with this description displayed on hover - "Your organization recommends a specific value for this setting and you have chosen a different value" Mandatory and Recommended disabled: Both these states will work the normal way, with the usual captions being shown to users.
PasswordRevealEnabled Enable Password reveal button
If you enable or don't configure this policy, the browser user setting defaults to displaying the password reveal button.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- PasswordRevealEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 87, Windows 7 or later
- Template
- msedge.admx
Lets you configure the default display of the browser password reveal button for password input fields on websites. If you enable or don't configure this policy, the browser user setting defaults to displaying the password reveal button. If you disable this policy, the browser user setting can't display the password reveal button. For accessibility, users can change the browser setting from the default policy. This policy only affects the browser password reveal button but doesn't affect websites' custom reveal buttons.
PasswordManagerEnabled Enable saving passwords to the password manager
If you enable or don't configure this policy, users can save and add their passwords in Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- PasswordManagerEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enable Microsoft Edge to save user passwords. The next time a user visits a site with a saved password, Microsoft Edge will enter the password automatically. If you enable or don't configure this policy, users can save and add their passwords in Microsoft Edge. If you disable this policy, users can't save and add new passwords, but they can still use previously saved passwords.
PasswordDeleteOnBrowserCloseEnabled Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes
If you disable or don't configure this policy, the user's personal configuration is used.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- PasswordDeleteOnBrowserCloseEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 117, Windows 7 or later
- Template
- msedge.admx
When this policy is enabled, the passwords saved with Edge Password Manager are exempted from deletion when the browser closes. This policy is only effective when the 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) policy is enabled. If you enable this policy, passwords aren't cleared when the browser closes. If you disable or don't configure this policy, the user's personal configuration is used.
Microsoft Edge - Default Settings (users can override) / Performance
EfficiencyMode Configure when energy saver (previously named efficiency mode) should become active
By default, energy saver is set to 'BalancedSavings'. On devices with no battery, energy saver is disabled by default and does not become active.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- EfficiencyMode
- Supported on
- Microsoft Edge version 96, Windows 7 or later
- Template
- msedge.admx
0Energy saver is always active1Energy saver is never active2Energy saver is active when the device is unplugged3Energy saver is active when the device is unplugged and the battery is low4When the device is unplugged, energy saver takes moderate steps to save battery. When the device is unplugged and the battery is low, energy saver takes extra steps to save battery.5When the device is unplugged or unplugged and the battery is low, energy saver takes extra steps to save battery.This policy setting lets you configure when energy saver becomes active. By default, energy saver is set to 'BalancedSavings'. On devices with no battery, energy saver is disabled by default and does not become active. Please note that Windows Energy Saver settings can influence when energy saver becomes active on all devices. Individual sites may be blocked from participating in energy saver by configuring the policy 'SleepingTabsBlockedForUrls' (Block sleeping tabs on specific sites). Set this policy to 'AlwaysActive' and energy saver is always active. Set this policy to 'NeverActive' and energy saver never becomes active. Set this policy to 'ActiveWhenUnplugged' and energy saver becomes active when the device is unplugged. Set this policy to 'ActiveWhenUnpluggedBatteryLow' and energy saver becomes active when the device is unplugged and the battery is low. Set this policy to 'BalancedSavings' and when the device is unplugged, energy saver takes moderate steps to save battery. When the device is unplugged and the battery is low, energy saver takes extra steps to save battery. Set this policy to 'MaximumSavings' and when the device is unplugged or unplugged and the battery is low, energy saver takes extra steps to save battery. If the device does not have a battery, energy saver never becomes active in any mode other than 'AlwaysActive' unless the setting or 'EfficiencyModeEnabled' (Efficiency mode enabled) policy is enabled. This policy has no effect if the 'EfficiencyModeEnabled' policy is disabled. Learn more about energy saver: https://go.microsoft.com/fwlink/?linkid=2173921 Learn more about energy saver: https://learn.microsoft.com/en-us/windows-hardware/design/component-guidelines/energy-saver Policy options mapping: * AlwaysActive (0) = Energy saver is always active * NeverActive (1) = Energy saver is never active * ActiveWhenUnplugged (2) = Energy saver is active when the device is unplugged * ActiveWhenUnpluggedBatteryLow (3) = Energy saver is active when the device is unplugged and the battery is low * BalancedSavings (4) = When the device is unplugged, energy saver takes moderate steps to save battery. When the device is unplugged and the battery is low, energy saver takes extra steps to save battery. * MaximumSavings (5) = When the device is unplugged or unplugged and the battery is low, energy saver takes extra steps to save battery. Use the preceding information when configuring this policy.
EfficiencyModeEnabled Efficiency mode enabled
If you don't configure this policy, efficiency mode will be enabled for devices with a battery and disabled otherwise.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- EfficiencyModeEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, efficiency mode is enabled for devices with a battery and is disabled otherwise.
- Supported on
- Microsoft Edge version 106, Windows 7 or later
- Template
- msedge.admx
Enables efficiency mode which helps extend battery life by saving computer resources. By default, efficiency mode is enabled for devices with a battery and is disabled otherwise. If you enable this policy, efficiency mode becomes active according to the setting chosen by the user. You can configure the efficiency mode setting using the 'EfficiencyMode' (Configure when energy saver (previously named efficiency mode) should become active) policy. If the device doesn't have a battery, efficiency mode is always active. If you disable this policy, efficiency mode is never active. The 'EfficiencyMode' and 'EfficiencyModeOnPowerEnabled' (Enable efficiency mode when the device is connected to a power source) policies will have no effect. If you don't configure this policy, efficiency mode will be enabled for devices with a battery and disabled otherwise. Users can choose the efficiency mode option they want in edge://settings/system. Learn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921
EfficiencyModeOnPowerEnabled Enable efficiency mode when the device is connected to a power source
If you disable or don't configure this policy, efficiency mode will never become active when the device is connected to a power source.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- EfficiencyModeOnPowerEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 106, Windows 7 or later
- Template
- msedge.admx
Allows efficiency mode to become active when the device is connected to a power source. On devices with no battery, this policy has no effect. If you enable this policy, efficiency mode will become active when the device is connected to a power source. If you disable or don't configure this policy, efficiency mode will never become active when the device is connected to a power source. This policy has no effect if the 'EfficiencyModeEnabled' (Efficiency mode enabled) policy is disabled. Learn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921
StartupBoostEnabled Enable startup boost
If you don't configure this policy, startup boost may initially be off or on.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- StartupBoostEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 88, Windows 7 or later
- Template
- msedge.admx
Allows Microsoft Edge processes to start at OS sign-in and restart in background after the last browser window is closed. If Microsoft Edge is running in background mode, the browser might not close when the last window is closed and the browser won't be restarted in background when the window closes. See the 'BackgroundModeEnabled' (Continue running background apps after Microsoft Edge closes) policy for information about what happens after configuring Microsoft Edge background mode behavior. If you enable this policy, startup boost is turned on. If you disable this policy, startup boost is turned off. If you don't configure this policy, startup boost may initially be off or on. The user can configure its behavior in edge://settings/system. Learn more about startup boost: https://go.microsoft.com/fwlink/?linkid=2147018
ExtensionsPerformanceDetectorEnabled Extensions Performance Detector enabled
If you enable or don't configure this policy, users receive Extensions Performance Detector notifications from Browser Essentials.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ExtensionsPerformanceDetectorEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 130, Windows 7 or later
- Template
- msedge.admx
This policy controls if users can access the Extensions Performance Detector Recommended Action feature in Browser Essentials. This feature alerts extension users if their extensions are causing performance regressions in the browser and allows them to take action to resolve the issue. If you enable or don't configure this policy, users receive Extensions Performance Detector notifications from Browser Essentials. When there's an active alert, users are able to view the impact of extensions on their browser's performance and make an informed decision to disable impacting extensions. The detector will exclude browser-managed extensions, such as Google Docs offline, component extensions, and organization-managed extensions (that is, extensions that can't be disabled). If you disable this policy, users won't receive notifications or be able to view the Extensions Performance Detector Recommended Action.
PerformanceDetectorEnabled Performance Detector Enabled
If you enable or don't configure this policy, performance detector is turned on.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- PerformanceDetectorEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 107, Windows 7 or later
- Template
- msedge.admx
The performance detector detects tab performance issues and recommends actions to fix the performance issues. If you enable or don't configure this policy, performance detector is turned on. If you disable this policy, performance detector is turned off. The user can configure its behavior in edge://settings/system. Learn more about performance detector: https://aka.ms/EdgePerformanceDetector
PinBrowserEssentialsToolbarButton Pin browser essentials toolbar button
If you enable or don't configure this policy, the Browser essentials button is pinned on the toolbar.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- PinBrowserEssentialsToolbarButton
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 114, Windows 7 or later
- Template
- msedge.admx
This policy lets you configure whether to pin the Browser essentials button on the toolbar. When the button is pinned, it always appears on the toolbar. When the button isn't pinned, it only appears when there's an alert. An example of this kind of alert is the performance detector alert that indicates the browser is using high CPU or memory. If you enable or don't configure this policy, the Browser essentials button is pinned on the toolbar. If you disable this policy, the Browser essentials button isn't pinned on the toolbar. Learn more about browser essentials: https://go.microsoft.com/fwlink/?linkid=2240439
Microsoft Edge - Default Settings (users can override) / Printing
PrintPreviewStickySettings Configure the sticky print preview settings
If you disable or don't configure this policy, print preview settings aren't impacted.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- PrintPreviewStickySettings
- Supported on
- Microsoft Edge version 110, Windows 7 or later
- Template
- msedge.admx
Configuring this policy sets the print preview settings as the most recent choice in Print Preview instead of the default print preview settings. Each item of this policy expects a boolean: Layout specifies if the webpage layout should be kept sticky or not in print preview settings. If you set this to True, the webpage layout uses the recent choice; otherwise, it sets to default value. Size specifies if the page size should be kept sticky or not in print preview settings. If you set this to True, the page size uses the recent choice; otherwise, it sets to default value. Scale Type specifies if the scaling percentage and scale type should be kept sticky or not in print preview settings. If you set this to True, the scale percentage and scale type both use the recent choice; otherwise, it will set to default value. Margins specifies if the page margin should be kept sticky or not in print preview settings. If you set this to True, the page margins use the recent choice; otherwise, it sets to default value. If you enable this policy, the selected values use the most recent choice in Print Preview. If you disable or don't configure this policy, print preview settings aren't impacted. Example value: { "layout": false, "margins": true, "scaleType": false, "size": true } Compact example value: {"layout": false, "margins": true, "scaleType": false, "size": true}
PrintHeaderFooter Print headers and footers
If you don't configure this policy, users can decide whether to print headers and footers.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- PrintHeaderFooter
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Force 'headers and footers' to be on or off in the printing dialog. If you don't configure this policy, users can decide whether to print headers and footers. If you disable this policy, users can't print headers and footers. If you enable this policy, users always print headers and footers.
PrintPreviewUseSystemDefaultPrinter Set the system default printer as the default printer
If you disable this policy or don't configure it, Print Preview uses the most recently used printer as the default destination choice.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- PrintPreviewUseSystemDefaultPrinter
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Tells Microsoft Edge to use the system default printer as the default choice in Print Preview instead of the most recently used printer. If you disable this policy or don't configure it, Print Preview uses the most recently used printer as the default destination choice. If you enable this policy, Print Preview uses the OS system default printer as the default destination choice.
PrintingWebpageLayout Sets layout for printing
If you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- PrintingWebpageLayout
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
0Sets layout option as portrait1Sets layout option as landscapeConfiguring this policy sets the layout for printing webpages. If you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout. If you enable this policy, the selected option is set as the layout option. Policy options mapping: * portrait (0) = Sets layout option as portrait * landscape (1) = Sets layout option as landscape Use the preceding information when configuring this policy.
Microsoft Edge - Default Settings (users can override) / Scareware Blocker settings
ScarewareBlockerProtectionEnabled Configure Microsoft Edge Scareware blocker protection
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ScarewareBlockerProtectionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 134, Windows 7 or later
- Template
- msedge.admx
This policy setting allows administrators to control whether Microsoft Edge enables Scareware blocker, an AI-powered feature for protecting users from potential tech scams. To support this feature, Microsoft Edge downloads a machine learning model file from Microsoft to the device. If you enable or don’t configure this policy, Microsoft Edge Scareware blocker uses local AI to detect potential tech scams. If you disable this policy, Microsoft Edge Scareware blocker is disabled. The machine learning model file doesn't download to the device, and if downloaded, a deletion occurs. When this policy is enabled, the policies 'ScarewareBlockerBlocksDetectedSitesEnabled' (Configure Microsoft Edge scareware blocker to block sites detected as potential tech scams), 'ScarewareBlockerSendDetectedSitesToSmartScreenEnabled' (Configure Microsoft Edge Scareware blocker to share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen), and 'ScarewareBlockerAllowListDomains' (Configure the list of domains where Microsoft Edge Scareware blockers don't run) are used to configure the behavior of the Scareware blocker feature. If both of those policies are disabled, enabling this policy has no effect. When this policy is disabled, the policies 'ScarewareBlockerBlocksDetectedSitesEnabled', 'ScarewareBlockerSendDetectedSitesToSmartScreenEnabled', and 'ScarewareBlockerAllowListDomains' have no effect.
ScarewareBlockerBlocksDetectedSitesEnabled Configure Microsoft Edge scareware blocker to block sites detected as potential tech scams
If you enable or don't configure this policy, Microsoft Edge blocks sites detected as potential tech scams.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ScarewareBlockerBlocksDetectedSitesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 142, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Microsoft Edge blocks sites that are detected as potential tech scams. This policy only takes effect if ScarewareBlockerProtectionEnabled is enabled. If you enable or don't configure this policy, Microsoft Edge blocks sites detected as potential tech scams. If you disable this policy, Microsoft Edge doesn't block sites detected as potential tech scams.
ScarewareBlockerSendDetectedSitesToSmartScreenEnabled Configure Microsoft Edge Scareware blocker to share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen
If you disable or don't configure this policy, Microsoft Edge doesn't share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ScarewareBlockerSendDetectedSitesToSmartScreenEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 142, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Microsoft Edge shares URLs of sites that are detected as potential tech scams with Microsoft Defender SmartScreen. This policy only takes effect if ScarewareBlockerProtectionEnabled is enabled. If you enable this policy, Microsoft Edge shares URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen. If you disable or don't configure this policy, Microsoft Edge doesn't share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.
Microsoft Edge - Default Settings (users can override) / Sleeping tabs settings
SleepingTabsBlockedForUrls_recommended Block sleeping tabs on specific sites
If you don't configure this policy, all sites are eligible to be put to sleep unless the user's personal configuration blocks them.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- List subkey
- Software\Policies\Microsoft\Edge\Recommended\SleepingTabsBlockedForUrls
- Supported on
- Microsoft Edge version 88, Windows 7 or later
- Template
- msedge.admx
Define a list of sites, based on URL patterns, that aren't allowed to be put to sleep by sleeping tabs. Sites in this list are also excluded from other performance optimizations like efficiency mode and tab discard. If the policy 'SleepingTabsEnabled' (Configure sleeping tabs) is disabled, this list isn't used and no sites are put to sleep automatically. If you don't configure this policy, all sites are eligible to be put to sleep unless the user's personal configuration blocks them. Example value: https://www.contoso.com [*.]contoso.edu
AutoDiscardSleepingTabsEnabled Configure auto discard sleeping tabs
If the 'SleepingTabsEnabled' (Configure sleeping tabs) policy is enabled, then this feature is enabled by default. If the 'SleepingTabsEnabled' is disabled, then this feature is disabled by default and can't be enabled.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- AutoDiscardSleepingTabsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 120, Windows 7 or later
- Template
- msedge.admx
Setting this policy enables inactive (sleeping) tabs to be automatically discarded after 1.5 days of inactivity. This is done to save memory. When the user switches back to a discarded tab, the tab needs to be reloaded. If the 'SleepingTabsEnabled' (Configure sleeping tabs) policy is enabled, then this feature is enabled by default. If the 'SleepingTabsEnabled' is disabled, then this feature is disabled by default and can't be enabled. If enabled, idle background tabs will be discarded after 1.5 days. If disabled, idle background tab won't be discarded after 1.5 days. Tabs can still be discarded for other reasons if this policy is disabled.
SleepingTabsEnabled Configure sleeping tabs
If this policy is not configured, users can choose whether to enable sleeping tabs.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- SleepingTabsEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, sleeping tabs is turned on.
- Supported on
- Microsoft Edge version 88, Windows 7 or later
- Template
- msedge.admx
This policy setting lets you configure whether to turn on sleeping tabs. Sleeping tabs reduces CPU, battery, and memory usage by putting idle background tabs to sleep. Microsoft Edge uses heuristics to avoid putting tabs to sleep that do useful work in the background, such as display notifications, play sound, and stream video. By default, sleeping tabs is turned on. Individual sites may be blocked from being put to sleep by configuring the policy 'SleepingTabsBlockedForUrls' (Block sleeping tabs on specific sites). If this policy is enabled, sleeping tabs are turned on. If this policy is disabled, sleeping tabs are turned off. However, during moderate memory pressure, the system may freeze (sleep) tabs before discarding them. If this policy is not configured, users can choose whether to enable sleeping tabs.
SleepingTabsTimeout Set the background tab inactivity timeout for sleeping tabs
Tabs are only put to sleep automatically when the policy 'SleepingTabsEnabled' (Configure sleeping tabs) is enabled or isn't configured, and the user has enabled the sleeping tabs setting. If you don't configure this policy, users can choose the timeout value.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- SleepingTabsTimeout
- Stated default
- By default, this timeout is 7,200 seconds (2 hours).
- Supported on
- Microsoft Edge version 88, Windows 7 or later
- Template
- msedge.admx
3030 seconds of inactivity3005 minutes of inactivity90015 minutes of inactivity180030 minutes of inactivity36001 hour of inactivity72002 hours of inactivity108003 hours of inactivity216006 hours of inactivity4320012 hours of inactivityThis policy setting lets you configure the timeout, in seconds, after which inactive background tabs are automatically put to sleep if sleeping tabs is enabled. By default, this timeout is 7,200 seconds (2 hours). Tabs are only put to sleep automatically when the policy 'SleepingTabsEnabled' (Configure sleeping tabs) is enabled or isn't configured, and the user has enabled the sleeping tabs setting. If you don't configure this policy, users can choose the timeout value. Policy options mapping: * 30Seconds (30) = 30 seconds of inactivity * 5Minutes (300) = 5 minutes of inactivity * 15Minutes (900) = 15 minutes of inactivity * 30Minutes (1800) = 30 minutes of inactivity * 1Hour (3600) = 1 hour of inactivity * 2Hours (7200) = 2 hours of inactivity * 3Hours (10800) = 3 hours of inactivity * 6Hours (21600) = 6 hours of inactivity * 12Hours (43200) = 12 hours of inactivity Use the preceding information when configuring this policy.
Microsoft Edge - Default Settings (users can override) / SmartScreen settings
SmartScreenEnabled Configure Microsoft Defender SmartScreen
If you don't configure this setting, users can choose whether to use Microsoft Defender SmartScreen.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- SmartScreenEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, Microsoft Defender SmartScreen is turned on.
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
This policy setting lets you configure whether to turn on Microsoft Defender SmartScreen. Microsoft Defender SmartScreen provides warning messages to help protect your users from potential phishing scams and malicious software. By default, Microsoft Defender SmartScreen is turned on. If you enable this setting, Microsoft Defender SmartScreen is turned on. If you disable this setting, Microsoft Defender SmartScreen is turned off. If you don't configure this setting, users can choose whether to use Microsoft Defender SmartScreen. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.
SmartScreenPuaEnabled Configure Microsoft Defender SmartScreen to block potentially unwanted apps
If you don't configure this setting, users can choose whether to use potentially unwanted app blocking with Microsoft Defender SmartScreen.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- SmartScreenPuaEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- Potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off by default.
- Supported on
- Microsoft Edge version 80, Windows 7 or later
- Template
- msedge.admx
This policy setting lets you configure whether to turn on blocking for potentially unwanted apps with Microsoft Defender SmartScreen. Potentially unwanted app blocking with Microsoft Defender SmartScreen provides warning messages to help protect users from adware, coin miners, bundleware, and other low-reputation apps that are hosted by websites. Potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off by default. If you enable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned on. If you disable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off. If you don't configure this setting, users can choose whether to use potentially unwanted app blocking with Microsoft Defender SmartScreen. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are managed via Mobile Device Management (MDM) or joined to a domain via MCX.
SmartScreenDnsRequestsEnabled Enable Microsoft Defender SmartScreen DNS requests
If you enable or don't configure this setting, Microsoft Defender SmartScreen can make DNS requests.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- SmartScreenDnsRequestsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 97, Windows 7 or later
- Template
- msedge.admx
This policy lets you configure whether to enable DNS requests made by Microsoft Defender SmartScreen. Note: Disabling DNS requests prevent Microsoft Defender SmartScreen from getting IP addresses, and potentially impact the IP-based protections provided. If you enable or don't configure this setting, Microsoft Defender SmartScreen can make DNS requests. If you disable this setting, Microsoft Defender SmartScreen can't make any DNS requests. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are managed via MDM or joined to a domain via MCX.
NewSmartScreenLibraryEnabled Enable new SmartScreen library (obsolete)
If you enable or don't configure this policy, Microsoft Edge uses the new SmartScreen library (libSmartScreenN). Before Microsoft Edge version 103, if you don't configure this policy, Microsoft Edge uses the old SmartScreen library (libSmartScreen).
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- NewSmartScreenLibraryEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 95-107, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 107. This policy doesn't work because it was only intended to be a short-term mechanism to support the update to a new SmartScreen client. Allows the Microsoft Edge browser to load the new SmartScreen library (libSmartScreenN) for any SmartScreen checks on site URLs or application downloads. If you enable or don't configure this policy, Microsoft Edge uses the new SmartScreen library (libSmartScreenN). If you disable this policy, Microsoft Edge uses the old SmartScreen library (libSmartScreen). Before Microsoft Edge version 103, if you don't configure this policy, Microsoft Edge uses the old SmartScreen library (libSmartScreen). This policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management. This also includes macOS instances that are that are managed via MDM or joined to a domain via MCX.
SmartScreenForTrustedDownloadsEnabled Force Microsoft Defender SmartScreen checks on downloads from trusted sources
If you enable or don't configure this setting, Microsoft Defender SmartScreen checks the download's reputation regardless of source.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- SmartScreenForTrustedDownloadsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 78, Windows 7 or later
- Template
- msedge.admx
This policy setting lets you configure whether Microsoft Defender SmartScreen checks download reputation from a trusted source. In Windows, the policy determines a trusted source by checking its Internet zone. If the source comes from the local system, intranet, or trusted sites zone, then the download is considered trusted and safe. If you enable or don't configure this setting, Microsoft Defender SmartScreen checks the download's reputation regardless of source. If you disable this setting, Microsoft Defender SmartScreen doesn't check the download's reputation when downloading from a trusted source. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management.
Microsoft Edge - Default Settings (users can override) / Startup, home page and new tab page
RestoreOnStartup Action to take on Microsoft Edge startup
Disabling this setting is the same as leaving it not configured.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- RestoreOnStartup
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
5Open a new tab1Restore the last session4Open a list of URLs6Open a list of URLs and restore the last sessionSpecify how Microsoft Edge behaves when it starts. If you want a new tab to always open on startup, choose 'RestoreOnStartupIsNewTabPage'. If you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'RestoreOnStartupIsLastSession'. The browsing session is restored as it was. This option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies). If you want to open a specific set of URLs, choose 'RestoreOnStartupIsURLs'. Starting in Microsoft Edge version 125, if you want to reopen URLs that were open the last time Microsoft Edge closed and open a specific set of URLs, choose 'RestoreOnStartupIsLastSessionAndURLs'. Disabling this setting is the same as leaving it not configured. Users can change it in Microsoft Edge. This policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is only available on instances that are managed via MDM or joined to a domain via MCX. Policy options mapping: * RestoreOnStartupIsNewTabPage (5) = Open a new tab * RestoreOnStartupIsLastSession (1) = Restore the last session * RestoreOnStartupIsURLs (4) = Open a list of URLs * RestoreOnStartupIsLastSessionAndURLs (6) = Open a list of URLs and restore the last session Use the preceding information when configuring this policy.
HomepageLocation Configure the home page URL
If you disable or don't configure this policy, users can choose their own home page, as long as the 'HomepageIsNewTabPage' policy isn't enabled.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- HomepageLocation
- Stated default
- By default, the Home button opens the new tab page (as configured by the user or with the policy 'NewTabPageLocation' (Configure the new tab page URL)), and the user is able to choose between the URL configured by this policy and the new tab page.
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Configures the default home page URL in Microsoft Edge. The home page is the page opened by the Home button. 'RestoreOnStartup' (Action to take on Microsoft Edge startup) policies control the pages that open on startup. You can either set a URL here or set the home page to open the new tab page 'edge://newtab'. By default, the Home button opens the new tab page (as configured by the user or with the policy 'NewTabPageLocation' (Configure the new tab page URL)), and the user is able to choose between the URL configured by this policy and the new tab page. If you enable this policy, users can't change their home page URL, but they can choose the behavior for the Home button to open either the set URL or the new tab page. If you wish to enforce the usage of the set URL, you must also configure 'HomepageIsNewTabPage' (Set the new tab page as the home page)=Disabled. If you disable or don't configure this policy, users can choose their own home page, as long as the 'HomepageIsNewTabPage' policy isn't enabled. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX. Example value: https://www.contoso.com
NewTabPageSetFeedType Configure the Microsoft Edge new tab page experience (obsolete)
If you disable or don't configure this policy, users with an Azure Active Directory browser sign-in are offered the Office 365 new tab page feed experience, and the standard new tab page feed experience.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- NewTabPageSetFeedType
- Supported on
- Microsoft Edge version 79-92, Windows 7 or later
- Template
- msedge.admx
0Microsoft News feed experience1Office 365 feed experienceOBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 92. This policy is obsolete because the new version of the enterprise new tab page no longer requires choosing between different content types. Instead, the content that's presented to the user can be controlled via the Microsoft 365 admin center. To get to the Microsoft 365 admin center, sign in at https://admin.microsoft.com with your admin account. Lets you choose either the Microsoft News or Office 365 feed experience for the new tab page. If you set this policy to 'News', users see the Microsoft News feed experience on the new tab page. If you set this policy to 'Office', users with an Azure Active Directory browser sign-in see the Office 365 feed experience on the new tab page. If you disable or don't configure this policy, users with an Azure Active Directory browser sign-in are offered the Office 365 new tab page feed experience, and the standard new tab page feed experience. Users without an Azure Active Directory browser sign-in to see the standard new tab page experience. If you enable this policy *and* the 'NewTabPageLocation' (Configure the new tab page URL) policy, 'NewTabPageLocation' has precedence. Policy options mapping: * News (0) = Microsoft News feed experience * Office (1) = Office 365 feed experience Use the preceding information when configuring this policy.
NewTabPageLocation Configure the new tab page URL
If you don't configure this policy, the default new tab page is used.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- NewTabPageLocation
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Configures the default URL for the new tab page. The recommended version of this policy doesn't currently work and functions exactly like the mandatory version. This policy determines the page that opens when new tabs are created (including when new windows are opened). It also affects the startup page if this page opens to the new tab page. This policy doesn't determine which page opens on startup; that factor is controlled by the 'RestoreOnStartup' (Action to take on Microsoft Edge startup) policy. It also doesn't affect the home page if this home page opens to the new tab page. If you don't configure this policy, the default new tab page is used. If you configure this policy *and* the 'NewTabPageSetFeedType' (Configure the Microsoft Edge new tab page experience) policy, this policy takes precedence. If a blank tab is preferred, "about:blank" is the correct URL to use, not "about://blank". This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or joined to instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX. Example value: https://www.fabrikam.com
NewTabPagePrerenderEnabled Enable preload of the new tab page for faster rendering
If you don't configure this policy, preloading is enabled and a user can change this setting.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- NewTabPagePrerenderEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 85, Windows 7 or later
- Template
- msedge.admx
If you configure this policy, preloading the New tab page is enabled, and users can't change this setting. If you don't configure this policy, preloading is enabled and a user can change this setting.
NewTabPageManagedQuickLinks Set new tab page quick links
By default, Microsoft Edge displays quick links on the new tab page from user-added shortcuts and top sites based on browsing history.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- NewTabPageManagedQuickLinks
- Supported on
- Microsoft Edge version 79, Windows 7 or later
- Template
- msedge.admx
By default, Microsoft Edge displays quick links on the new tab page from user-added shortcuts and top sites based on browsing history. With this policy, you can configure up to three quick link tiles on the new tab page, expressed as a JSON object: [ { "url": "https://www.contoso.com", "title": "Contoso Portal", "pinned": true/false }, ... ] The 'url' field is required; 'title' and 'pinned' are optional. If 'title' isn't provided, the URL is used as the default title. If 'pinned' isn't provided, the default value is false. Microsoft Edge presents these tiles in the order listed, from left to right, with all pinned tiles displayed ahead of nonpinned tiles. If you set this policy as mandatory, the 'pinned' field is ignored and all tiles are pinned. The tiles can't be deleted by the user and always appear at the front of the quick links list. If you set this policy as recommended, pinned tiles remain in the list but the user has the ability to edit and delete them. Quick link tiles that aren't pinned behave like default top sites and are pushed off the list if other websites are visited more frequently. When applying nonpinned links via this policy to an existing browser profile, the links don't appear at all, depending on how they rank compared to the user's browsing history. Example value: [ { "pinned": true, "title": "Contoso Portal", "url": "https://contoso.com" }, { "title": "Fabrikam", "url": "https://fabrikam.com" } ]
SetNTPDefaultFeedTab Set the default Copilot new tab page feed tab to Work or Discover
If you set this policy to 'Work' (0) or don't configure this policy, Microsoft Edge sets the default feed tab to Work. ) is set to 'EnableBothWorkDiscover' (0) or isn't configured.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- SetNTPDefaultFeedTab
- Supported on
- Microsoft Edge version 148, Windows 7 or later
- Template
- msedge.admx
0Work1DiscoverThis policy sets the default feed tab on the Copilot new tab page to Work or Discover. If you set this policy to 'Work' (0) or don't configure this policy, Microsoft Edge sets the default feed tab to Work. If you set this policy to 'Discover' (1), Microsoft Edge sets the default feed tab to Discover. This policy only takes effect when 'ConfigureNTPFeedTabVisibility' (Configure whether the Discover or Work feed tabs are shown on the Copilot new tab page.) is set to 'EnableBothWorkDiscover' (0) or isn't configured. If only one feed tab is visible, this policy has no effect. Policy options mapping: * NTPDefaultFeedTabWork (0) = Work * NTPDefaultFeedTabDiscover (1) = Discover Use the preceding information when configuring this policy.
HomepageIsNewTabPage Set the new tab page as the home page
If you don't configure this policy, users can choose whether the set URL or the new tab page is their home page.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- HomepageIsNewTabPage
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Configures the default home page in Microsoft Edge. You can set the home page to a URL you specify or to the new tab page. If you enable this policy, the Home button is set to the new tab page as configured by the user or with the policy 'NewTabPageLocation' (Configure the new tab page URL) and the URL set with the policy 'HomepageLocation' (Configure the home page URL) is not taken into consideration. If you disable this policy, the Home button is the set URL as configured by the user or as configured in the policy 'HomepageLocation'. If you don't configure this policy, users can choose whether the set URL or the new tab page is their home page. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.
ShowHomeButton Show Home button on toolbar
If you don't configure the policy, users can choose whether to show the home button.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- Value name
- ShowHomeButton
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Shows the Home button on Microsoft Edge's toolbar. Enable this policy to always show the Home button. Disable it to never show the button. If you don't configure the policy, users can choose whether to show the home button.
RestoreOnStartupURLs_recommended Sites to open when the browser starts
If you don't configure this policy, no site is opened on startup.
- Registry key
- Software\Policies\Microsoft\Edge\Recommended
- List subkey
- Software\Policies\Microsoft\Edge\Recommended\RestoreOnStartupURLs
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specify a list of websites to open automatically when the browser starts. If you don't configure this policy, no site is opened on startup. This policy only works if you also set the 'RestoreOnStartup' (Action to take on Microsoft Edge startup) policy to 'Open a list of URLs' (4). This policy is available only on specific Windows instances. These instances include devices that are joined to a Microsoft Active Directory domain, devices joined to Microsoft Azure Active Directory`, or devices enrolled for device management. Example value: https://contoso.com https://www.fabrikam.com
Microsoft Edge / Application Guard settings
ApplicationGuardContainerProxy Application Guard Container Proxy
If you don't configure this policy, Microsoft Edge Application Guard uses the proxy configuration of the host.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ApplicationGuardContainerProxy
- Supported on
- Microsoft Edge version 84, Windows 7 or later
- Template
- msedge.admx
Configures the proxy settings for Microsoft Edge Application Guard. If you enable this policy, Microsoft Edge Application Guard ignores other sources of proxy configurations. If you don't configure this policy, Microsoft Edge Application Guard uses the proxy configuration of the host. This policy doesn't affect the proxy configuration of Microsoft Edge outside of Application Guard (on the host). The ProxyMode field lets you specify the proxy server used by Microsoft Edge Application Guard. The ProxyPacUrl field is a URL to a proxy.pac file. This policy doesn't affect the proxy configuration of Microsoft Edge outside of Application Guard (on the host). The ProxyMode field lets you specify the proxy server that's used by Microsoft Edge Application Guard. The ProxyPacUrl field is a URL for a proxy .pac file. The ProxyServer field is a URL for the proxy server. If you choose the 'direct' value as 'ProxyMode', all the other fields are ignored. If you choose the 'auto_detect' value as 'ProxyMode', all the other fields are ignored. If you choose the 'fixed_servers' value as 'ProxyMode', the 'ProxyServer' field is used. If you choose the 'pac_script' value as 'ProxyMode', the 'ProxyPacUrl' field is used. For more information about identifying Application Guard traffic via dual proxy, see https://go.microsoft.com/fwlink/?linkid=2134653. Example value: { "ProxyMode": "direct", "ProxyPacUrl": "https://internal.site/example.pac", "ProxyServer": "123.123.123.123:8080" } Compact example value: {"ProxyMode": "direct", "ProxyPacUrl": "https://internal.site/example.pac", "ProxyServer": "123.123.123.123:8080"}
ApplicationGuardFavoritesSyncEnabled Application Guard Favorites Sync Enabled
If you disable or don't configure this policy, favorites on the host won't be shared to the container.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ApplicationGuardFavoritesSyncEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 90, Windows 7 or later
- Template
- msedge.admx
This policy allows Microsoft Edge computers/devices that have application guard enabled to sync favorites from the host to the container so the favorites match. If 'ManagedFavorites' (Configure favorites) are configured, those favorites are also synced to the container. If you enable this policy, editing favorites in the container is disabled. So, the add favorites and add favorites folder buttons are blurred out in the UI of the container browser. If you disable or don't configure this policy, favorites on the host won't be shared to the container.
ApplicationGuardTrafficIdentificationEnabled Application Guard Traffic Identification
If you enable or don't configure this policy, Application Guard adds an extra HTTP header (X-MS-ApplicationGuard-Initiated) to all outbound HTTP requests made from the Application Guard container.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ApplicationGuardTrafficIdentificationEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 91, Windows 7 or later
- Template
- msedge.admx
If you enable or don't configure this policy, Application Guard adds an extra HTTP header (X-MS-ApplicationGuard-Initiated) to all outbound HTTP requests made from the Application Guard container. If you disable this policy, the extra header isn't added to the traffic.
ApplicationGuardPassiveModeEnabled Ignore Application Guard site list configuration and browse Microsoft Edge normally
If you disable or don't configure this policy, Microsoft Edge doesn't ignore the Application Guard site list.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ApplicationGuardPassiveModeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 94, Windows 7 or later
- Template
- msedge.admx
Set whether Microsoft Edge should ignore the Application Guard site list configuration for trusted and untrusted sites. If you enable this policy, all navigations from Microsoft Edge are accessed normally within Microsoft Edge without redirecting to the Application Guard container, including navigations to untrusted sites. Note: This policy ONLY impacts Microsoft Edge; so, navigations from other browsers are redirected to the Application Guard Container if you have the corresponding extensions enabled. If you disable or don't configure this policy, Microsoft Edge doesn't ignore the Application Guard site list. If users try to navigate to an untrusted site in the host, the site opens in the container.
ApplicationGuardUploadBlockingEnabled Prevents files from being uploaded while in Application Guard
If you disable or don't configure this policy, users will be able to upload files while in Application Guard.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ApplicationGuardUploadBlockingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 96, Windows 7 or later
- Template
- msedge.admx
Sets whether files can be uploaded while in Application Guard. If you enable this policy, users won't be able to upload files in Application Guard. If you disable or don't configure this policy, users will be able to upload files while in Application Guard.
Microsoft Edge / Cast
EdgeDisableDialProtocolForCastDiscovery Disable DIAL protocol for cast device discovery
By default, Cast device discovery uses DIAL protocol.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeDisableDialProtocolForCastDiscovery
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 121, Windows 7 or later
- Template
- msedge.admx
Enable this policy to disable the DIAL (Discovery And Launch) protocol for cast device discovery. (If EnableMediaRouter is disabled, this policy has no effect). Enable this policy to disable DIAL protocol. By default, Cast device discovery uses DIAL protocol.
EnableMediaRouter Enable Google Cast
By default, Google Cast is enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EnableMediaRouter
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enable this policy to enable Google Cast. Users can launch it from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar icon. Disable this policy to disable Google Cast. By default, Google Cast is enabled.
ShowCastIconInToolbar Show the cast icon in the toolbar
If you don't configure this policy or if you disable it, users can pin or remove the icon by using its contextual menu.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ShowCastIconInToolbar
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Set this policy to true to show the Cast toolbar icon on the toolbar or the overflow menu. Users won't be able to remove it. If you don't configure this policy or if you disable it, users can pin or remove the icon by using its contextual menu. If you've also set the 'EnableMediaRouter' (Enable Google Cast) policy to false, then this policy is ignored, and the toolbar icon isn't shown.
Microsoft Edge / Certificate management settings
CACertificateManagementAllowed Allow users to manage installed CA certificates.
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- CACertificateManagementAllowed
- Supported on
- Microsoft Edge version 133, Windows 7 or later
- Template
- msedge.admx
0Allow users to manage all certificates1Allow users to manage user certificates2Disallow users from managing certificatesThis policy determines the level of access users have when managing CA certificates in Microsoft Edge. Setting the policy to UserOnly (1) allows users to manage only user-imported certificates. Trust settings for built-in certificates cannot be changed. Setting the policy to None (2) lets users view certificates but not manage them. Note: The certificate management experience is available starting in Microsoft Edge version 136. Policy options mapping: * All (0) = Allow users to manage all certificates * UserOnly (1) = Allow users to manage user certificates * None (2) = Disallow users from managing certificates Use the preceding information when configuring this policy.
CAHintCertificates TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\CAHintCertificates
- Supported on
- Microsoft Edge version 133, Windows 7 or later
- Template
- msedge.admx
This policy defines certificates that Microsoft Edge doesn't explicitly trust or distrust but may be used as hints during certificate path-building. The specified certificates are considered as intermediates during path validation; the server's certificate still chain to a trusted root to be considered valid. Certificates must be base64-encoded. Example value: MIIFljCCA36gAwIBAgINAgO8U1lrNMcY9QFQZjANBgkqhkiG9w0BAQsFADBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjEwHhcNMjAwODEzMDAwMDQyWhcNMjcwOTMwMDAwMDQyWjBGMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzETMBEGA1UEAxMKR1RTIENBIDFDMzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAPWI3+dijB43+DdCkH9sh9D7ZYIl/ejLa6T/belaI+KZ9hzpkgOZE3wJCor6QtZeViSqejOEH9Hpabu5dOxXTGZok3c3VVP+ORBNtzS7XyV3NzsXlOo85Z3VvMO0Q+sup0fvsEQRY9i0QYXdQTBIkxu/t/bgRQIh4JZCF8/ZK2VWNAcmBA2o/X3KLu/qSHw3TT8An4Pf73WELnlXXPxXbhqW//yMmqaZviXZf5YsBvcRKgKAgOtjGDxQSYflispfGStZloEAoPtR28p3CwvJlk/vcEnHXG0g/Zm0tOLKLnf9LdwLtmsTDIwZKxeWmLnwi/agJ7u2441Rj72ux5uxiZ0CAwEAAaOCAYAwggF8MA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwEgYDVR0TAQH/BAgwBgEB/wIBADAdBgNVHQ4EFgQUinR/r4XN7pXNPZzQ4kYU83E1HScwHwYDVR0jBBgwFoAU5K8rJnEaK0gnhS9SZizv8IkTcT4waAYIKwYBBQUHAQEEXDBaMCYGCCsGAQUFBzABhhpodHRwOi8vb2NzcC5wa2kuZ29vZy9ndHNyMTAwBggrBgEFBQcwAoYkaHR0cDovL3BraS5nb29nL3JlcG8vY2VydHMvZ3RzcjEuZGVyMDQGA1UdHwQtMCswKaAnoCWGI2h0dHA6Ly9jcmwucGtpLmdvb2cvZ3RzcjEvZ3RzcjEuY3JsMFcGA1UdIARQME4wOAYKKwYBBAHWeQIFAzAqMCgGCCsGAQUFBwIBFhxodHRwczovL3BraS5nb29nL3JlcG9zaXRvcnkvMAgGBmeBDAECATAIBgZngQwBAgIwDQYJKoZIhvcNAQELBQADggIBAIl9rCBcDDy+mqhXlRu0rvqrpXJxtDaV/d9AEQNMwkYUuxQkq/BQcSLbrcRuf8/xam/IgxvYzolfh2yHuKkMo5uhYpSTld9brmYZCwKWnvy15xBpPnrLRklfRuFBsdeYTWU0AIAaP0+fbH9JAIFTQaSSIYKCGvGjRFsqUBITTcFTNvNCCK9U+o53UxtkOCcXCb1YyRt8OS1b887U7ZfbFAO/CVMkH8IMBHmYJvJh8VNS/UKMG2YrPxWhu//2m+OBmgEGcYk1KCTd4b3rGS3hSMs9WYNRtHTGnXzGsYZbr8w0xNPM1IERlQCh9BIiAfq0g3GvjLeMcySsN1PCAJA/Ef5c7TaUEDu9Ka7ixzpiO2xj2YC/WXGsYye5TBeg2vZzFb8q3o/zpWwygTMD0IZRcZk0upONXbVRWPeyk+gB9lm+cZv9TSjOz23HFtz30dZGm6fKa+l3D/2gthsjgx0QGtkJAITgRNOidSOzNIb2ILCkXhAd4FJGAJ2xDx8hcFH1mt0G/FX0Kw4zd8NLQsLxdxP8c4CU6x+7Nz/OAipmsHMdMqUybDKwjuDEI/9bfU1lcKwrmz3O2+BtjjKAvpafkmO8l7tdufThcV4q5O8DIrGKZTqPwJNl1IXNDw9bg1kWRxYtnCQ6yICmJhSFm/Y3m6xv+cXDBlHz4n/FsRC6UfTd
CADistrustedCertificates TLS certificates that should be distrusted by Microsoft Edge for server authentication
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\CADistrustedCertificates
- Supported on
- Microsoft Edge version 133, Windows 7 or later
- Template
- msedge.admx
This policy enables defining a list of certificate public keys that should be distrusted by Microsoft Edge for TLS server authentication. The policy value is a list of base64-encoded X.509 certificates. Any certificate with a matching SPKI (SubjectPublicKeyInfo) is distrusted. Example value: MIIB/TCCAaOgAwIBAgIUQthnWVsd1jWpUCNBf/uILjXC+t4wCgYIKoZIzj0EAwIwVDELMAkGA1UEBhMCVVMxETAPBgNVBAgMCFZpcmdpbmlhMQ8wDQYDVQQHDAZSZXN0b24xITAfBgNVBAoMGEludGVybmV0IFdpZGdpdHMgUHR5IEx0ZDAeFw0yMzEyMDcxNjE5NTVaFw0yMzEyMjExNjE5NTVaMFQxCzAJBgNVBAYTAlVTMREwDwYDVQQIDAhWaXJnaW5pYTEPMA0GA1UEBwwGUmVzdG9uMSEwHwYDVQQKDBhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAQ9Akav/KB0aVA9FM1QK4J1CEHn5rFOyY/nxcr5HG3+Fom0Kwu5zTR/kz9eOYgtG/1NmCzbiEKaULDfzA8V9aJ7o1MwUTAdBgNVHQ4EFgQUq37bLKiuw8Y/G+rurMf46hw7EekwHwYDVR0jBBgwFoAUq37bLKiuw8Y/G+rurMf46hw7EekwDwYDVR0TAQH/BAUwAwEB/zAKBggqhkjOPQQDAgNIADBFAiEA/JhtLSgtVOcXkgFJ9V5Vb6lhGdiKQFfzO9wTxPeCxCECIFePYPucys2n/r9MOBMHiX/8068ssv+uceqokzUg0mAb
CACertificatesWithConstraints TLS certificates that should be trusted by Microsoft Edge for server authentication with constraints
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- CACertificatesWithConstraints
- Supported on
- Microsoft Edge version 133, Windows 7 or later
- Template
- msedge.admx
This policy enables a list of TLS certificates that should be trusted by Microsoft Edge for server authentication, with constraints added outside the certificate. If no constraint of a certain type is present, then any name of that type is allowed. Certificates should be base64-encoded. At least one constraint must be specified for each certificate. The permitted_dns_names field is a list of DNS names that are allowed for the certificate. If the DNS name in the certificate request doesn't match one of the specified DNS names, the certificate isn't trusted. The permitted_cidrs field is a list of CIDR (Classless Inter-Domain Routing) ranges that will be allowed for the certificate. If the IP address in the certificate request doesn't fall within one of the permitted CIDR ranges, the certificate isn't trusted. Example value: [ { "certificate": "MIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X", "constraints": { "permitted_dns_names": [ "example.org" ], "permitted_cidrs": [ "10.1.1.0/24" ] } } ]
CACertificates TLS server certificates that should be trusted by Microsoft Edge
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\CACertificates
- Supported on
- Microsoft Edge version 133, Windows 7 or later
- Template
- msedge.admx
This policy enables a list of Transport Layer Security (TLS) certificates that Microsoft Edge trusts for server authentication. Certificates should be base64 encoded. Example value: MIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X
CAPlatformIntegrationEnabled Use user-added TLS certificates from platform trust stores for server authentication
If enabled (or unset), user-added TLS certificates from platform trust stores will be used in path-building for TLS server authentication.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- CAPlatformIntegrationEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 133, Windows 7 or later
- Template
- msedge.admx
If enabled (or unset), user-added TLS certificates from platform trust stores will be used in path-building for TLS server authentication. If disabled, user-added TLS certificates from platform trust stores won't be used in path-building for TLS server authentication.
Microsoft Edge / Content settings
AutomaticFullscreenAllowedForUrls Allow automatic full screen on specified sites
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\AutomaticFullscreenAllowedForUrls
- Supported on
- Microsoft Edge version 132, Windows 7 or later
- Template
- msedge.admx
For security reasons, the requestFullscreen() web API requires a prior user gesture ("transient activation") to be called or it fails. Users' personal settings can allow certain origins to call this API without a prior user gesture. This policy supersedes users' personal settings and allows matching origins to call the API without a prior user gesture. For detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards (*) are allowed. Origins matching both blocked and allowed policy patterns are blocked. Origins not specified by policy or user settings require a prior user gesture to call this API. Example value: https://www.example.com [*.]example.edu
CookiesAllowedForUrls Allow cookies on specific sites
If you don't configure this policy, the global default value from the 'DefaultCookiesSetting' (Configure cookies) policy (if set) or the user's personal configuration is used for all sites.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\CookiesAllowedForUrls
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Define a list of sites, based on URL patterns, that are allowed to set cookies. URL patterns can be a single URL indicating that the site can use cookies on all top-level sites. Patterns can also be two URLs delimited by a comma. The first specifies the site that should be allowed to use cookies. The second specifies the top-level site that the first value should be applied on. If you use a pair of URLs, the first value in the pair supports *, but the second value doesn't. Using * for the first value indicates that all sites can use cookies when the second URL is the top-level site. If you don't configure this policy, the global default value from the 'DefaultCookiesSetting' (Configure cookies) policy (if set) or the user's personal configuration is used for all sites. For more information, see the 'CookiesBlockedForUrls' (Block cookies on specific sites) and 'CookiesSessionOnlyForUrls' (Limit cookies from specific websites to the current session) policies. Note there can't be conflicting URL patterns set between these three policies: - 'CookiesBlockedForUrls' - CookiesAllowedForUrls - 'CookiesSessionOnlyForUrls' For detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy. To allow third-party cookies to be set, specify a pair of URL patterns delimited by a comma. The first value in the pair specifies the third-party site that should be allowed to use cookies. The second value in the pair specifies the top-level site that the first value should be applied on. The first value in the pair supports * but the second value doesn't. To exclude cookies from being deleted on exit, configure the 'SaveCookiesOnExit' (Save cookies when Microsoft Edge closes) policy. Example value: https://www.contoso.com [*.]contoso.edu https://loaded-as-third-party.fabrikam.com,https://www.contoso.com *,https://www.contoso.com
IdleDetectionAllowedForUrls Allow idle detection on these sites
If you don't configure this policy, the default behavior applies to all sites.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\IdleDetectionAllowedForUrls
- Supported on
- Microsoft Edge version 145, Windows 7 or later
- Template
- msedge.admx
Allows you to specify a list of URL patterns for sites that are allowed to use the Idle Detection API. If you don't configure this policy, the default behavior applies to all sites. The default behavior is determined by the DefaultIdleDetectionSetting policy, if configured, or by the user’s personal settings otherwise. Only the origin of the URL is evaluated. Any path specified in a URL pattern is ignored. Wildcards, *, are supported. For detailed information about valid URL pattern formats, see https://go.microsoft.com/fwlink/?linkid=209532. URL patterns specified in the blocklist take precedence over this allowlist. This allowlist takes precedence over the DefaultIdleDetectionSetting policy. Example value: https://www.example.com [*.]example.edu
ImagesAllowedForUrls Allow images on these sites
If you don't configure this policy, the global default value is used for all sites either from the 'DefaultImagesSetting' (Default images setting) policy (if set) or the user's personal configuration.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ImagesAllowedForUrls
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Define a list of sites, based on URL patterns, that can display images. If you don't configure this policy, the global default value is used for all sites either from the 'DefaultImagesSetting' (Default images setting) policy (if set) or the user's personal configuration. For detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards (*) are allowed. Example value: https://www.contoso.com [*.]contoso.edu
InsecureContentAllowedForUrls Allow insecure content on specified sites
If you don't configure this policy, blockable mixed content is blocked and optionally blockable mixed content is upgraded.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\InsecureContentAllowedForUrls
- Supported on
- Microsoft Edge version 80, Windows 7 or later
- Template
- msedge.admx
Create a list of URL patterns to specify sites that can display or, as of version 94, download insecure mixed content (that is, HTTP content on HTTPS sites). If you don't configure this policy, blockable mixed content is blocked and optionally blockable mixed content is upgraded. However, users are allowed to set exceptions to allow insecure mixed content for specific sites. For detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards (*) are allowed. Example value: https://www.example.com [*.]example.edu
IntranetFileLinksEnabled Allow intranet zone file URL links from Microsoft Edge to open in Windows File Explorer
If you disable or don't configure this policy, file URL links don't open.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- IntranetFileLinksEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- *, [::1]) are considered internet zone by default.
- Supported on
- Microsoft Edge version 95, Windows 7 or later
- Template
- msedge.admx
This setting allows file URL links to intranet zone files from intranet zone HTTPS websites to open Windows File Explorer for that file or directory. If you enable this policy, intranet zone file URL links originating from intranet zone HTTPS pages open Windows File Explorer to the parent directory of the file and select the file. Intranet zone directory URL links originating from intranet zone HTTPS pages open Windows File Explorer to the directory with no items in the directory selected. If you disable or don't configure this policy, file URL links don't open. Microsoft Edge uses the definition of intranet zone as configured for Internet Explorer. https://localhost/ is blocked as an exception of allowed intranet zone host, while loopback addresses (127.0.0.*, [::1]) are considered internet zone by default. Users may opt out of prompts on a per-protocol/per-site basis unless the 'ExternalProtocolDialogShowAlwaysOpenCheckbox' (Show an "Always open" checkbox in external protocol dialog) policy is disabled.
JavaScriptAllowedForUrls Allow JavaScript on specific sites
If you don't configure this policy, 'DefaultJavaScriptSetting' (Default JavaScript setting) applies for all sites, when the setting is enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\JavaScriptAllowedForUrls
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Define a list of sites, based on URL patterns, that are allowed to run JavaScript. If you don't configure this policy, 'DefaultJavaScriptSetting' (Default JavaScript setting) applies for all sites, when the setting is enabled. If not, the user's personal setting applies. For detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. Example value: https://www.contoso.com [*.]contoso.edu
JavaScriptOptimizerAllowedForSites Allow JavaScript optimization on these sites
If you don't configure this policy for a site, then the policy from 'DefaultJavaScriptOptimizerSetting' applies to the site, if set, otherwise Javascript optimization is enabled for the site.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\JavaScriptOptimizerAllowedForSites
- Supported on
- Microsoft Edge version 134, Windows 7 or later
- Template
- msedge.admx
Allows you to set a list of site URL patterns that specify sites for which advanced JavaScript optimizations are enabled. For detailed information on valid site url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. JavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com doesn't correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there's no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com. This policy applies on a frame-by-frame basis and not based on top-level origin URL alone; so, for example, if contoso.com is listed in the 'JavaScriptOptimizerAllowedForSites' (Allow JavaScript optimization on these sites) policy but contoso.com loads a frame containing fabrikam.com, then contoso.com has JavaScript optimizations enabled, but fabrikam.com uses the policy from 'DefaultJavaScriptOptimizerSetting' (Control use of JavaScript optimizers), if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value. If you don't configure this policy for a site, then the policy from 'DefaultJavaScriptOptimizerSetting' applies to the site, if set, otherwise Javascript optimization is enabled for the site. Example value: [*.]example.edu
JavaScriptJitAllowedForSites Allow JavaScript to use JIT on these sites
If you don't configure this policy for a site then the policy from 'DefaultJavaScriptJitSetting' applies to the site, if set, otherwise Javascript JIT is enabled for the site.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\JavaScriptJitAllowedForSites
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
Allows you to set a list of site URL patterns that specify sites that are allowed to run JavaScript with JIT (Just In Time) compiler enabled. For detailed information on valid site URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. JavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com won't correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there's no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com. This policy applies on a frame-by-frame basis and not based on top-level origin URL alone; so, for example, if contoso.com is listed in the JavaScriptJitAllowedForSites policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript JIT enabled, but fabrikam.com will use the policy from 'DefaultJavaScriptJitSetting' (Control use of JavaScript JIT), if set, or default to JavaScript JIT enabled. If you don't configure this policy for a site then the policy from 'DefaultJavaScriptJitSetting' applies to the site, if set, otherwise Javascript JIT is enabled for the site. Example value: [*.]example.edu
WebHidAllowDevicesForUrls Allow listed sites connect to specific HID devices
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebHidAllowDevicesForUrls
- Supported on
- Microsoft Edge version 109, Windows 7 or later
- Template
- msedge.admx
This setting lets you list the URLs that specify which sites are automatically granted permission to access a HID device with the given vendor and product IDs. If you set this policy, each item in the list requires both devices and urls fields for the item to be valid; otherwise, the item is ignored. * Each item in the devices field must have a vendor_id and may have a product_id field. * Omitting the product_id field will create a policy matching any device with the specified vendor ID. * An item which has a product_id field without a vendor_id field is invalid and is ignored. If you don't set this policy, then 'DefaultWebHidGuardSetting' (Control use of the WebHID API) applies, if it's set. If not, the user's personal setting applies. For detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy. URLs in this policy shouldn't conflict with those configured through 'WebHidBlockedForUrls' (Block the WebHID API on these sites). If they do, this policy takes precedence over 'WebHidBlockedForUrls'. Example value: [ { "devices": [ { "product_id": 5678, "vendor_id": 1234 } ], "urls": [ "https://microsoft.com", "https://chromium.org" ] } ]
WebHidAllowAllDevicesForUrls Allow listed sites to connect to any HID device
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\WebHidAllowAllDevicesForUrls
- Supported on
- Microsoft Edge version 109, Windows 7 or later
- Template
- msedge.admx
This setting allows you to list sites which are automatically granted permission to access all available devices. The URLs must be valid; else, the policy is ignored. Only the origin (scheme, host, and port) of the URL is evaluated. For detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy. This policy overrides 'DefaultWebHidGuardSetting' (Control use of the WebHID API), 'WebHidAskForUrls' (Allow the WebHID API on these sites), 'WebHidBlockedForUrls' (Block the WebHID API on these sites), and the user's preferences. Example value: https://microsoft.com https://chromium.org
LocalFontsAllowedForUrls Allow Local Fonts permission on these sites
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\LocalFontsAllowedForUrls
- Supported on
- Microsoft Edge version 149, Windows 7 or later
- Template
- msedge.admx
Specifies a list of site URL patterns for which the local fonts permission is automatically granted. Sites in this list can access information about local fonts. For detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are supported. This policy matches based on origin only; any path in the URL pattern is ignored. If a site isn't included in this policy, the 'DefaultLocalFontsSetting' (Default Local Fonts permission setting) policy applies if configured. Otherwise, the browser default behavior applies, and users can choose the permission on a per-site basis. Example value: https://www.example.com [*.]example.edu
AutomaticDownloadsAllowedForUrls Allow multiple automatic downloads in quick succession on specific sites
If you don't configure this policy, 'DefaultAutomaticDownloadsSetting' (Default automatic downloads setting) applies for all sites, if it's set.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\AutomaticDownloadsAllowedForUrls
- Supported on
- Microsoft Edge version 110, Windows 7 or later
- Template
- msedge.admx
Define a list of sites, based on URL patterns, that are allowed to perform multiple successive automatic downloads. If you don't configure this policy, 'DefaultAutomaticDownloadsSetting' (Default automatic downloads setting) applies for all sites, if it's set. If it isn't set, then the user's personal setting applies. For more detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Example value: https://contoso.com [*.]contoso.edu
NotificationsAllowedForUrls Allow notifications on specific sites
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\NotificationsAllowedForUrls
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows you to create a list of URL patterns to specify sites that are allowed to display notifications. If you don't set this policy, the global default value is used for all sites. This default value is from the 'DefaultNotificationsSetting' (Default notification setting) policy if set, or from the user's personal configuration. For detailed information on valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Example value: https://www.contoso.com [*.]contoso.edu
ShowPDFDefaultRecommendationsEnabled Allow notifications to set Microsoft Edge as default PDF reader
If you enable or don't configure this setting, employees receive recommendations from Microsoft Edge to set itself as the default PDF handler.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ShowPDFDefaultRecommendationsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
This policy setting lets you decide whether employees should receive recommendations to set Microsoft Edge as PDF handler. If you enable or don't configure this setting, employees receive recommendations from Microsoft Edge to set itself as the default PDF handler. If you disable this setting, employees can't receive any notifications from Microsoft Edge to set itself as the default PDF handler.
PopupsAllowedForUrls Allow pop-up windows on specific sites
If you don't configure this policy, the global default value from the 'DefaultPopupsSetting' (Default pop-up window setting) policy (if set) or the user's personal configuration is used for all sites.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\PopupsAllowedForUrls
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Define a list of sites, based on URL patterns, that can open pop-up windows. Wildcards (*) are allowed. If you don't configure this policy, the global default value from the 'DefaultPopupsSetting' (Default pop-up window setting) policy (if set) or the user's personal configuration is used for all sites. Example value: https://www.contoso.com [*.]contoso.edu
PreciseGeolocationAllowedForUrls Allow precise geolocation on these sites
If you leave this policy unset, DefaultGeolocationSetting applies to all sites (if configured).
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\PreciseGeolocationAllowedForUrls
- Supported on
- Microsoft Edge version 144, Windows 7 or later
- Template
- msedge.admx
This policy lets you specify a list of URL patterns for sites that are allowed to access the user's high-accuracy geolocation without prompting for permission. If you leave this policy unset, DefaultGeolocationSetting applies to all sites (if configured). Otherwise, the user's personal setting is used. For information about valid url patterns, see https://learn.microsoft.com/deployedge/edge-learnmmore-url-list-filter%20format. Wildcards (*) are supported. Example value: https://www.example.com [*.]example.edu
FileSystemReadAskForUrls Allow read access via the File System API on these sites
Leaving the policy unset means 'DefaultFileSystemReadGuardSetting' (Control use of the File System API for reading) applies for all sites, if set.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\FileSystemReadAskForUrls
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them read access to files or directories in the host operating system's file system via the File System API. Leaving the policy unset means 'DefaultFileSystemReadGuardSetting' (Control use of the File System API for reading) applies for all sites, if set. If not, users' personal settings apply. URL patterns can't conflict with 'FileSystemReadBlockedForUrls' (Block read access via the File System API on these sites). Neither policy takes precedence if a URL matches with both. For detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
PdfLocalFileAccessAllowedForDomains Allow specified sites to access file:// URLs in the PDF Viewer
If you disable or don't configure this policy, sites cannot access file:// URLs in the PDF Viewer.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\PdfLocalFileAccessAllowedForDomains
- Supported on
- Microsoft Edge version 147, Windows 7 or later
- Template
- msedge.admx
Controls which sites can access file:// URLs in the PDF Viewer. If you enable this policy, sites in the list can access file:// URLs in the PDF Viewer. If you disable or don't configure this policy, sites cannot access file:// URLs in the PDF Viewer. Example value: example.com contoso.com
PluginsAllowedForUrls Allow the Adobe Flash plug-in on specific sites (obsolete)
If you don't configure this policy, the global default value from the 'DefaultPluginsSetting' (Default Adobe Flash setting) policy (if set) or the user's personal configuration is used for all sites.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\PluginsAllowedForUrls
- Supported on
- Microsoft Edge version 77-87, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 87. This policy doesn't work because Flash is no longer supported by Microsoft Edge. Define a list of sites, based on URL patterns, that can run the Adobe Flash plug-in. If you don't configure this policy, the global default value from the 'DefaultPluginsSetting' (Default Adobe Flash setting) policy (if set) or the user's personal configuration is used for all sites. For detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. However, starting in M85, patterns with '*' and '[*.]' wildcards in the host are no longer supported for this policy. Example value: https://www.contoso.com http://contoso.edu:8080
WebHidAskForUrls Allow the WebHID API on these sites
Leaving the policy unset means 'DefaultWebHidGuardSetting' (Control use of the WebHID API) applies for all sites, if set.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\WebHidAskForUrls
- Supported on
- Microsoft Edge version 100, Windows 7 or later
- Template
- msedge.admx
Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a HID device. Leaving the policy unset means 'DefaultWebHidGuardSetting' (Control use of the WebHID API) applies for all sites, if set. If not, users' personal settings apply. For URL patterns that don't match the policy, the following values are applied in order of precedence: * 'WebHidBlockedForUrls' (Block the WebHID API on these sites) (if there's a match), * 'DefaultWebHidGuardSetting' (if set), or * Users' personal settings. URL patterns must not conflict with 'WebHidBlockedForUrls'. Neither policy takes precedence if a URL matches both patterns. For detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy. Example value: https://microsoft.com https://chromium.org
WebUsbAskForUrls Allow WebUSB on specific sites
If you don't configure this policy, the global default value from the 'DefaultWebUsbGuardSetting' (Control use of the WebUSB API) policy (if set) or the user's personal configuration is used for all sites.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\WebUsbAskForUrls
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Define a list of sites, based on URL patterns, that can ask the user for access to a USB device. If you don't configure this policy, the global default value from the 'DefaultWebUsbGuardSetting' (Control use of the WebUSB API) policy (if set) or the user's personal configuration is used for all sites. The URL patterns defined in this policy can't conflict with those configured in the 'WebUsbBlockedForUrls' (Block WebUSB on specific sites) policy - you can't both allow and block a URL. For detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322 Example value: https://www.contoso.com [*.]contoso.edu
WindowManagementAllowedForUrls Allow Window Management permission on specified sites
If this policy isn't configured for a site, then the policy from 'DefaultWindowManagementSetting' (Default Window Management permission setting) applies to the site, if configured.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\WindowManagementAllowedForUrls
- Supported on
- Microsoft Edge version 123, Windows 7 or later
- Template
- msedge.admx
Lets you configure a list of site URL patterns that specify sites, which automatically grant the window management permission. This extends the ability of sites to see information about the device's screens. This information can be used to open and place windows or request fullscreen on specific screens. For detailed information on valid site url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy only matches based on site origin, so any path in the URL pattern is ignored. If this policy isn't configured for a site, then the policy from 'DefaultWindowManagementSetting' (Default Window Management permission setting) applies to the site, if configured. Otherwise the permission follows the browser's defaults and lets users choose this permission per site. Example value: https://www.example.com [*.]example.edu
FileSystemWriteAskForUrls Allow write access to files and directories on these sites
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\FileSystemWriteAskForUrls
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
If you set this policy, you can list the URL patterns that specify which sites can ask users to grant them write access to files or directories in the host operating system's file system. If you don't set this policy, 'DefaultFileSystemWriteGuardSetting' (Control use of the File System API for writing) applies for all sites, if it's set. If not, users' personal settings apply. URL patterns can't conflict with 'FileSystemWriteBlockedForUrls' (Block write access to files and directories on these sites). Neither policy takes precedence if a URL matches with both. For detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
WebHidAllowDevicesWithHidUsagesForUrls Automatically grant permission to these sites to connect to HID devices containing top-level collections with the given HID usage
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebHidAllowDevicesWithHidUsagesForUrls
- Supported on
- Microsoft Edge version 109, Windows 7 or later
- Template
- msedge.admx
This setting allows you to list the URLs that specify which sites are automatically granted permission to access an HID device containing a top-level collection with the given HID usage. Each item in the list requires both usages and urls fields for the policy to be valid. * Each item in the usages field must have a usage_page and may have a usage field. * Omitting the usage field creates a policy matching any device containing a top-level collection with a usage from the specified usage page. * An item which has a usage field without a usage_page field is invalid and is ignored. If you don't set this policy, then 'DefaultWebHidGuardSetting' (Control use of the WebHID API) applies, if it's set. If not, the user's personal setting applies. For detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy. URLs in this policy shouldn't conflict with those configured through 'WebHidBlockedForUrls' (Block the WebHID API on these sites). If they do, this policy takes precedence over 'WebHidBlockedForUrls'. Example value: [ { "urls": [ "https://microsoft.com", "https://chromium.org" ], "usages": [ { "usage": 5678, "usage_page": 1234 } ] } ]
SerialAllowAllPortsForUrls Automatically grant sites permission to connect all serial ports
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\SerialAllowAllPortsForUrls
- Supported on
- Microsoft Edge version 97, Windows 7 or later
- Template
- msedge.admx
Setting the policy allows you to list sites that are automatically granted permission to access all available serial ports. The URLs must be valid; else, the policy is ignored. Only the origin (scheme, host, and port) of the URL is considered. This policy overrides 'DefaultSerialGuardSetting' (Control use of the Serial API), 'SerialAskForUrls' (Allow the Serial API on specific sites), 'SerialBlockedForUrls' (Block the Serial API on specific sites), and the user's preferences. Example value: https://www.example.com
SerialAllowUsbDevicesForUrls Automatically grant sites permission to connect to USB serial devices
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SerialAllowUsbDevicesForUrls
- Supported on
- Microsoft Edge version 97, Windows 7 or later
- Template
- msedge.admx
Setting the policy lets you list sites that are automatically granted permission to access USB serial devices with vendor and product IDs that match the vendor_id and product_id fields. Optionally you can omit the product_id field. This enables site access to the vendor's devices. When you provide a product ID, then you give the site access to a specific device from the vendor but not all devices. The URLs must be valid, or the policy is ignored. Only the origin (scheme, host, and port) of the URL is considered. This policy overrides 'DefaultSerialGuardSetting' (Control use of the Serial API), 'SerialAskForUrls' (Allow the Serial API on specific sites), 'SerialBlockedForUrls' (Block the Serial API on specific sites), and the user's preferences. This policy only affects access to USB devices through the Web Serial API. To grant access to USB devices through the WebUSB API, see the 'WebUsbAllowDevicesForUrls' (Grant access to specific sites to connect to specific USB devices) policy. Example value: [ { "devices": [ { "product_id": 5678, "vendor_id": 1234 } ], "urls": [ "https://specific-device.example.com" ] }, { "devices": [ { "vendor_id": 1234 } ], "urls": [ "https://all-vendor-devices.example.com" ] } ]
AutoSelectCertificateForUrls Automatically select client certificates for these sites
If you leave the policy unset, there's no autoselection for any site.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\AutoSelectCertificateForUrls
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Setting the policy lets you make a list of URL patterns that specify sites for which Microsoft Edge can automatically select a client certificate. The value is an array of stringified JSON dictionaries, each with the form { "pattern": "$URL_PATTERN", "filter" : $FILTER }, where $URL_PATTERN is a content setting pattern. $FILTER restricts the client certificates the browser automatically selects from. Independent of the filter, only certificates that match the server's certificate request are selected. Examples for the usage of the $FILTER section: * When $FILTER is set to { "ISSUER": { "CN": "$ISSUER_CN" } }, only client certificates issued by a certificate with the CommonName $ISSUER_CN are selected. * When $FILTER contains both the "ISSUER" and the "SUBJECT" sections, only client certificates that satisfy both conditions are selected. * When $FILTER contains a "SUBJECT" section with the "O" value, a certificate needs at least one organization matching the specified value to be selected. * When $FILTER contains a "SUBJECT" section with a "OU" value, a certificate needs at least one organizational unit matching the specified value to be selected. * When $FILTER is set to {}, the selection of client certificates isn't additionally restricted. Filters provided by the web server still apply. If you leave the policy unset, there's no autoselection for any site. Example value: {"pattern":"https://www.contoso.com","filter":{"ISSUER":{"CN":"certificate issuer name", "L": "certificate issuer location", "O": "certificate issuer org", "OU": "certificate issuer org unit"}, "SUBJECT":{"CN":"certificate subject name", "L": "certificate subject location", "O": "certificate subject org", "OU": "certificate subject org unit"}}}
AutomaticFullscreenBlockedForUrls Block automatic full screen on specified sites
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\AutomaticFullscreenBlockedForUrls
- Supported on
- Microsoft Edge version 132, Windows 7 or later
- Template
- msedge.admx
For security reasons, the requestFullscreen() web API requires a prior user gesture ("transient activation") to be called or it fails. Users' personal settings can allow certain origins to call this API without a prior user gesture. This policy supersedes users' personal settings and blocks matching origins from calling the API without a prior user gesture. For detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards (*) are allowed. Origins matching both blocked and allowed policy patterns are blocked. Origins not specified by policy or user settings require a prior user gesture to call this API. Example value: https://www.example.com [*.]example.edu
CookiesBlockedForUrls Block cookies on specific sites
If you don't configure this policy, the global default value from the 'DefaultCookiesSetting' (Configure cookies) policy (if set) or the user's personal configuration is used for all sites.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\CookiesBlockedForUrls
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Define a list of sites, based on URL patterns, that can't set cookies. If you don't configure this policy, the global default value from the 'DefaultCookiesSetting' (Configure cookies) policy (if set) or the user's personal configuration is used for all sites. See the 'CookiesAllowedForUrls' (Allow cookies on specific sites) and 'CookiesSessionOnlyForUrls' (Limit cookies from specific websites to the current session) policies for more information. Note there can't be conflicting URL patterns set between these three policies: - CookiesBlockedForUrls - 'CookiesAllowedForUrls' - 'CookiesSessionOnlyForUrls' For detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy. Example value: https://www.contoso.com [*.]contoso.edu
GeolocationBlockedForUrls Block geolocation on these sites
If you disable or don't configure this policy, DefaultGeolocationSetting applies to all sites, if configured. If it's not configured, the user’s personal browser setting is used.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\GeolocationBlockedForUrls
- Supported on
- Microsoft Edge version 144, Windows 7 or later
- Template
- msedge.admx
Use this policy to define a list of URL patterns for sites that are blocked from accessing the user's geolocation. These sites also can't prompt the user for location permissions. If you enable this policy, the list you provide determines which sites are blocked from requesting or accessing geolocation. If you disable or don't configure this policy, DefaultGeolocationSetting applies to all sites, if configured. If it's not configured, the user’s personal browser setting is used. For detailed information on valid url patterns, see the documentation on pattern formats: https://learn.microsoft.com/deployedge/edge-learnmmore-url-list-filter%20format. Example value: https://www.example.com [*.]example.edu
IdleDetectionBlockedForUrls Block idle detection on these sites
If you do not configure this policy, the default behavior applies to all sites.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\IdleDetectionBlockedForUrls
- Supported on
- Microsoft Edge version 145, Windows 7 or later
- Template
- msedge.admx
Allows you to specify a list of URL patterns for sites that are not allowed to use the Idle Detection API. Only the origin of the URL is evaluated. Any path specified in a URL pattern is ignored. Wildcards, *, are supported. For detailed information about valid URL pattern formats, see https://go.microsoft.com/fwlink/?linkid=2095322. If you do not configure this policy, the default behavior applies to all sites. The default behavior is determined by the DefaultIdleDetectionSetting policy, if configured, or by the user’s personal settings otherwise. Example value: https://www.example.com [*.]example.edu
ImagesBlockedForUrls Block images on specific sites
If you don't configure this policy, the global default value from the 'DefaultImagesSetting' (Default images setting) policy (if set) or the user's personal configuration is used for all sites.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ImagesBlockedForUrls
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Define a list of sites, based on URL patterns, that aren't allowed to display images. If you don't configure this policy, the global default value from the 'DefaultImagesSetting' (Default images setting) policy (if set) or the user's personal configuration is used for all sites. For detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards (*) are allowed. Example value: https://www.contoso.com [*.]contoso.edu
InsecureContentBlockedForUrls Block insecure content on specified sites
If you don't configure this policy, blockable mixed content is blocked, and optionally blockable mixed content is upgraded.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\InsecureContentBlockedForUrls
- Supported on
- Microsoft Edge version 80, Windows 7 or later
- Template
- msedge.admx
Creates a list of URL patterns to specify sites that aren't allowed to display blockable (that is, active) mixed content (that is, HTTP content on HTTPS sites) and for which optionally blockable mixed content upgrades are disabled. If you don't configure this policy, blockable mixed content is blocked, and optionally blockable mixed content is upgraded. However, users are allowed to set exceptions to allow insecure mixed content for specific sites. For detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards (*) are allowed. Example value: https://www.example.com [*.]example.edu
JavaScriptJitBlockedForSites Block JavaScript from using JIT on these sites
If you don't configure this policy for a site, then the policy from 'DefaultJavaScriptJitSetting' applies to the site, if set; otherwise, JavaScript JIT is enabled for the site.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\JavaScriptJitBlockedForSites
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
Allows you to set a list of site URL patterns that specify sites that aren't allowed to run JavaScript JIT (Just In Time) compiler enabled. Disabling the JavaScript JIT means that Microsoft Edge may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Microsoft Edge to render web content in a more secure configuration. For detailed information on valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. JavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com. This policy applies on a frame-by-frame basis and not based on top-level origin URL alone; so, for example, if contoso.com is listed in the JavaScriptJitBlockedForSites policy but contoso.com loads a frame containing fabrikam.com, then contoso.com has JavaScript JIT disabled, but fabrikam.com uses the policy from 'DefaultJavaScriptJitSetting' (Control use of JavaScript JIT), if set, or default to JavaScript JIT enabled. If you don't configure this policy for a site, then the policy from 'DefaultJavaScriptJitSetting' applies to the site, if set; otherwise, JavaScript JIT is enabled for the site. Example value: [*.]example.edu
JavaScriptBlockedForUrls Block JavaScript on specific sites
If you don't configure this policy, 'DefaultJavaScriptSetting' (Default JavaScript setting) applies for all sites, if it's set.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\JavaScriptBlockedForUrls
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Defines a list of sites, based on URL patterns, that aren't allowed to run JavaScript. If you don't configure this policy, 'DefaultJavaScriptSetting' (Default JavaScript setting) applies for all sites, if it's set. If not, the user's personal setting applies. For detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy blocks JavaScript based on whether the origin of the top-level document (usually the page URL that's also displayed in the address bar) matches any of the patterns. Therefore, this policy isn't appropriate for mitigating web supply-chain attacks. For example, supplying the pattern `https://[*.]foo.com/` doesn't prevent a page hosted on, say, `https://contoso.com`, from running a script loaded from `https://www.foo.com/example.js`. Furthermore, supplying the pattern `https://contoso.com/` doesn't prevent a document from `https://contoso.com` from running scripts if it isn't the top-level document, but embedded as a subframe into a page hosted on another origin, say, `https://www.fabrikam.com`. Example value: https://www.contoso.com [*.]contoso.edu
JavaScriptOptimizerBlockedForSites Block JavaScript optimizations on these sites
If you don't configure this policy for a site, then the policy from 'DefaultJavaScriptOptimizerSetting' applies to the site, if set; otherwise, JavaScript optimization is enabled for the site.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\JavaScriptOptimizerBlockedForSites
- Supported on
- Microsoft Edge version 134, Windows 7 or later
- Template
- msedge.admx
Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are disabled. Disabling JavaScript optimizations means that Microsoft Edge may render web content more slowly. For detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. JavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com won't correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there's no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com. This policy applies on a frame-by-frame basis and isn't based on top-level origin url alone; so, for example, if contoso.com is listed in the 'JavaScriptOptimizerBlockedForSites' (Block JavaScript optimizations on these sites) policy but contoso.com loads a frame containing fabrikam.com, then contoso.com has JavaScript optimizations disabled, but fabrikam.com will use the policy from 'DefaultJavaScriptOptimizerSetting' (Control use of JavaScript optimizers), if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value. If you don't configure this policy for a site, then the policy from 'DefaultJavaScriptOptimizerSetting' applies to the site, if set; otherwise, JavaScript optimization is enabled for the site. Example value: [*.]example.edu
LocalFontsBlockedForUrls Block Local Fonts permission on these sites
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\LocalFontsBlockedForUrls
- Supported on
- Microsoft Edge version 149, Windows 7 or later
- Template
- msedge.admx
Specifies a list of site URL patterns for which the local fonts permission is automatically denied. Sites in this list are prevented from accessing information about local fonts. For detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are supported. This policy matches based on origin only; any path in the URL pattern is ignored. If a site isn't included in this policy, the 'DefaultLocalFontsSetting' (Default Local Fonts permission setting) policy applies if configured. Otherwise, the browser default behavior applies, and users can choose the permission on a per-site basis. Example value: https://www.example.com [*.]example.edu
AutomaticDownloadsBlockedForUrls Block multiple automatic downloads in quick succession on specific sites
If you don't configure this policy, 'DefaultAutomaticDownloadsSetting' (Default automatic downloads setting) applies for all sites, if that setting is active.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\AutomaticDownloadsBlockedForUrls
- Supported on
- Microsoft Edge version 110, Windows 7 or later
- Template
- msedge.admx
Define a list of sites, based on URL patterns, where multiple successive automatic downloads aren't allowed. If you don't configure this policy, 'DefaultAutomaticDownloadsSetting' (Default automatic downloads setting) applies for all sites, if that setting is active. If it isn't set, then the user's personal setting applies. For more detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Example value: https://contoso.com [*.]contoso.com
NotificationsBlockedForUrls Block notifications on specific sites
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\NotificationsBlockedForUrls
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows you to create a list of url patterns to specify sites that aren't allowed to display notifications. If you don't set this policy, the global default value is used for all sites. This default value is from the 'DefaultNotificationsSetting' (Default notification setting) policy if it's set, or from the user's personal configuration. For detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Example value: https://www.contoso.com [*.]contoso.edu
PopupsBlockedForUrls Block pop-up windows on specific sites
If you don't configure this policy, the global default value from the 'DefaultPopupsSetting' (Default pop-up window setting) policy (if set) or the user's personal configuration is used for all sites.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\PopupsBlockedForUrls
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Define a list of sites, based on URL patterns, that are blocked from opening pop-up windows. Wildcards (*) are allowed. If you don't configure this policy, the global default value from the 'DefaultPopupsSetting' (Default pop-up window setting) policy (if set) or the user's personal configuration is used for all sites. Example value: https://www.contoso.com [*.]contoso.edu
FileSystemReadBlockedForUrls Block read access via the File System API on these sites
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\FileSystemReadBlockedForUrls
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
If you set this policy, you can list the URL patterns that specify which sites can't ask users to grant them read access to files or directories in the host operating system's file system via the File System API. If you don't set this policy, 'DefaultFileSystemReadGuardSetting' (Control use of the File System API for reading) applies for all sites, if set. If not, users' personal settings apply. URL patterns can't conflict with 'FileSystemReadAskForUrls' (Allow read access via the File System API on these sites). Neither policy takes precedence if a URL matches with both. For detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
PluginsBlockedForUrls Block the Adobe Flash plug-in on specific sites (obsolete)
If you don't configure this policy, the global default value from the 'DefaultPluginsSetting' (Default Adobe Flash setting) policy (if set) or the user's personal configuration is used for all sites.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\PluginsBlockedForUrls
- Supported on
- Microsoft Edge version 77-87, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 87. This policy doesn't work because Flash is no longer supported by Microsoft Edge. Define a list of sites, based on URL patterns, that are blocked from running Adobe Flash. If you don't configure this policy, the global default value from the 'DefaultPluginsSetting' (Default Adobe Flash setting) policy (if set) or the user's personal configuration is used for all sites. For detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. However, starting in M85, patterns with '*' and '[*.]' wildcards in the host are no longer supported for this policy. Example value: https://www.contoso.com http://contoso.edu:8080
WebHidBlockedForUrls Block the WebHID API on these sites
Leaving the policy unset means 'DefaultWebHidGuardSetting' (Control use of the WebHID API) applies for all sites, if set.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\WebHidBlockedForUrls
- Supported on
- Microsoft Edge version 100, Windows 7 or later
- Template
- msedge.admx
Setting the policy lets you list the URL patterns that specify which sites can't ask users to grant them access to a HID device. Leaving the policy unset means 'DefaultWebHidGuardSetting' (Control use of the WebHID API) applies for all sites, if set. If not, users' personal settings apply. For URL patterns that don't match the policy, the following values are applied in order of precedence: * 'WebHidAskForUrls' (Allow the WebHID API on these sites) (if there's a match), * 'DefaultWebHidGuardSetting' (if set), or * Users' personal settings. URL patterns can't conflict with 'WebHidAskForUrls'. Neither policy takes precedence if a URL matches both patterns. For detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy. Example value: https://microsoft.com https://chromium.org
WebUsbBlockedForUrls Block WebUSB on specific sites
If you don't configure this policy, the global default value from the 'DefaultWebUsbGuardSetting' (Control use of the WebUSB API) policy (if set) or the user's personal configuration is used for all sites.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\WebUsbBlockedForUrls
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Define a list of sites, based on URL patterns, that can't ask the user to grant them access to a USB device. If you don't configure this policy, the global default value from the 'DefaultWebUsbGuardSetting' (Control use of the WebUSB API) policy (if set) or the user's personal configuration is used for all sites. URL patterns in this policy can't conflict with those configured in the 'WebUsbAskForUrls' (Allow WebUSB on specific sites) policy. You can't both allow and block a URL. For detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Example value: https://www.contoso.com [*.]contoso.edu
WindowManagementBlockedForUrls Block Window Management permission on specified sites
If this policy isn't configured for a site, then the policy from 'DefaultWindowManagementSetting' (Default Window Management permission setting) applies to the site, if configured.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\WindowManagementBlockedForUrls
- Supported on
- Microsoft Edge version 123, Windows 7 or later
- Template
- msedge.admx
Lets you configure a list of site URL patterns that specify sites which can automatically deny the window management permission. This limits the ability of sites to see information about the device's screens. This information can be used to open and place windows or request fullscreen on specific screens. For detailed information on valid site URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy only matches based on site origin, so any path in the URL pattern is ignored. If this policy isn't configured for a site, then the policy from 'DefaultWindowManagementSetting' (Default Window Management permission setting) applies to the site, if configured. Otherwise the permission follows the browser's defaults and lets users choose this permission per site. Example value: https://www.example.com [*.]example.edu
FileSystemWriteBlockedForUrls Block write access to files and directories on these sites
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\FileSystemWriteBlockedForUrls
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
If you set this policy, you can list the URL patterns that specify which sites can't ask users to grant them write access to files or directories in the host operating system's file system. If you don't set this policy, 'DefaultFileSystemWriteGuardSetting' (Control use of the File System API for writing) applies for all sites, if it's set. If not, users' personal settings apply. URL patterns can't conflict with 'FileSystemWriteAskForUrls' (Allow write access to files and directories on these sites). Neither policy takes precedence if a URL matches with both. For detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy. Example value: https://www.example.com [*.]example.edu
SpotlightExperiencesAndRecommendationsEnabled Choose whether users can receive customized background images and text, suggestions, notifications, and tips for Microsoft services
If you enable or don't configure this setting, spotlight experiences and recommendations are turned on.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SpotlightExperiencesAndRecommendationsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
Choose whether users can receive customized background images and text, suggestions, notifications, and tips for Microsoft services. If you enable or don't configure this setting, spotlight experiences and recommendations are turned on. If you disable this setting, spotlight experiences and recommendations are turned off.
DefaultCookiesSetting Configure cookies
If you don't configure this policy, the default 'AllowCookies' is used, and users can change this setting in Microsoft Edge Settings.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultCookiesSetting
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
1Let all sites create cookies2Don't let any site create cookies4Keep cookies for the duration of the session, except ones listed in "SaveCookiesOnExit"Control whether websites can create cookies on the user's device. This policy is all or nothing - you can let all websites create cookies, or no websites create cookies. You can't use this policy to enable cookies from specific websites. Set the policy to 'SessionOnly' to clear cookies when the session closes. If you don't configure this policy, the default 'AllowCookies' is used, and users can change this setting in Microsoft Edge Settings. (If you don't want users to be able to change this setting, set the policy.) Policy options mapping: * AllowCookies (1) = Let all sites create cookies * BlockCookies (2) = Don't let any site create cookies * SessionOnly (4) = Keep cookies for the duration of the session, except ones listed in 'SaveCookiesOnExit' (Save cookies when Microsoft Edge closes) Use the preceding information when configuring this policy.
DefaultInsecureContentSetting Control use of insecure content exceptions
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultInsecureContentSetting
- Supported on
- Microsoft Edge version 80, Windows 7 or later
- Template
- msedge.admx
2Don't allow any site to load mixed content3Allow users to add exceptions to allow mixed contentAllows you to set whether users can add exceptions to allow mixed content for specific sites. This policy can be overridden for specific URL patterns using the 'InsecureContentAllowedForUrls' (Allow insecure content on specified sites) and 'InsecureContentBlockedForUrls' (Block insecure content on specified sites) policies. If this policy isn't set, users are allowed to add exceptions to allow blockable mixed content and disable autoupgrades for optionally blockable mixed content. Policy options mapping: * BlockInsecureContent (2) = Don't allow any site to load mixed content * AllowExceptionsInsecureContent (3) = Allow users to add exceptions to allow mixed content Use the preceding information when configuring this policy.
DefaultJavaScriptJitSetting Control use of JavaScript JIT
If you don't configure this policy, JavaScript JIT is enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultJavaScriptJitSetting
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
1Allow any site to run JavaScript JIT2Do not allow any site to run JavaScript JITAllows you to set whether Microsoft Edge runs the v8 JavaScript engine with JIT (Just In Time) compiler enabled or not. Disabling the JavaScript JIT means that Microsoft Edge can render web content more slowly, and can also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT can allow Microsoft Edge to render web content in a more secure configuration. This policy can be overridden for specific URL patterns using the 'JavaScriptJitAllowedForSites' (Allow JavaScript to use JIT on these sites) and 'JavaScriptJitBlockedForSites' (Block JavaScript from using JIT on these sites) policies. If you don't configure this policy, JavaScript JIT is enabled. Policy options mapping: * AllowJavaScriptJit (1) = Allow any site to run JavaScript JIT * BlockJavaScriptJit (2) = Do not allow any site to run JavaScript JIT Use the preceding information when configuring this policy.
DefaultJavaScriptOptimizerSetting Control use of JavaScript optimizers
If you don't configure this policy, JavaScript optimizations are enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultJavaScriptOptimizerSetting
- Supported on
- Microsoft Edge version 134, Windows 7 or later
- Template
- msedge.admx
1Enable advanced JavaScript optimizations on all sites2Disable advanced JavaScript optimizations on all sitesAllows you to set whether Microsoft Edge will run the v8 JavaScript engine with more advanced JavaScript optimizations enabled. Disabling JavaScript optimizations (by setting this policy's value to 2) will mean that Microsoft Edge may render web content more slowly. This policy can be overridden for specific URL patterns using the 'JavaScriptOptimizerAllowedForSites' (Allow JavaScript optimization on these sites) and 'JavaScriptOptimizerBlockedForSites' (Block JavaScript optimizations on these sites) policies. If you don't configure this policy, JavaScript optimizations are enabled. Policy options mapping: * AllowJavaScriptOptimizer (1) = Enable advanced JavaScript optimizations on all sites * BlockJavaScriptOptimizer (2) = Disable advanced JavaScript optimizations on all sites Use the preceding information when configuring this policy.
DefaultFileSystemReadGuardSetting Control use of the File System API for reading
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultFileSystemReadGuardSetting
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
2Don't allow any site to request read access to files and directories via the File System API3Allow sites to ask the user to grant read access to files and directories via the File System APIIf you set this policy to 3, websites can ask for read access to the host operating system's filesystem using the File System API. If you set this policy to 2, access is denied. If you don't set this policy, websites can ask for access. Users can change this setting. Policy options mapping: * BlockFileSystemRead (2) = Don't allow any site to request read access to files and directories via the File System API * AskFileSystemRead (3) = Allow sites to ask the user to grant read access to files and directories via the File System API Use the preceding information when configuring this policy.
DefaultFileSystemWriteGuardSetting Control use of the File System API for writing
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultFileSystemWriteGuardSetting
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
2Don't allow any site to request write access to files and directories3Allow sites to ask the user to grant write access to files and directoriesIf you set this policy to 3, websites can ask for write access to the host operating system's filesystem using the File System API. If you set this policy to 2, access is denied. If you don't set this policy, websites can ask for access. Users can change this setting. Policy options mapping: * BlockFileSystemWrite (2) = Don't allow any site to request write access to files and directories * AskFileSystemWrite (3) = Allow sites to ask the user to grant write access to files and directories Use the preceding information when configuring this policy.
DefaultWebBluetoothGuardSetting Control use of the Web Bluetooth API
If you don't configure this policy, the default value ('AskWebBluetooth', meaning users are asked each time) is used and users can change it.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultWebBluetoothGuardSetting
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
2Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API3Allow sites to ask the user to grant access to a nearby Bluetooth deviceControl whether websites can access nearby Bluetooth devices. You can completely block access or require the site to ask the user each time it wants to access a Bluetooth device. If you don't configure this policy, the default value ('AskWebBluetooth', meaning users are asked each time) is used and users can change it. Policy options mapping: * BlockWebBluetooth (2) = Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API * AskWebBluetooth (3) = Allow sites to ask the user to grant access to a nearby Bluetooth device Use the preceding information when configuring this policy.
DefaultWebHidGuardSetting Control use of the WebHID API
Leaving it unset lets websites ask for access, but users can change this setting.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultWebHidGuardSetting
- Supported on
- Microsoft Edge version 100, Windows 7 or later
- Template
- msedge.admx
2Do not allow any site to request access to HID devices via the WebHID API3Allow sites to ask the user to grant access to a HID deviceSetting the policy to 3 lets websites ask for access to HID devices. Setting the policy to 2 denies access to HID devices. Leaving it unset lets websites ask for access, but users can change this setting. This policy can be overridden for specific url patterns using the 'WebHidAskForUrls' (Allow the WebHID API on these sites) and 'WebHidBlockedForUrls' (Block the WebHID API on these sites) policies. Policy options mapping: * BlockWebHid (2) = Do not allow any site to request access to HID devices via the WebHID API * AskWebHid (3) = Allow sites to ask the user to grant access to a HID device Use the preceding information when configuring this policy.
DefaultWebUsbGuardSetting Control use of the WebUSB API
If you don't configure this policy, sites can ask users whether they can access the connected USB devices ('AskWebUsb') by default, and users can change this setting.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultWebUsbGuardSetting
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
2Do not allow any site to request access to USB devices via the WebUSB API3Allow sites to ask the user to grant access to a connected USB deviceSet whether websites can access connected USB devices. You can completely block access or ask the user each time a website wants to get access to connected USB devices. You can override this policy for specific URL patterns by using the 'WebUsbAskForUrls' (Allow WebUSB on specific sites) and 'WebUsbBlockedForUrls' (Block WebUSB on specific sites) policies. If you don't configure this policy, sites can ask users whether they can access the connected USB devices ('AskWebUsb') by default, and users can change this setting. Policy options mapping: * BlockWebUsb (2) = Do not allow any site to request access to USB devices via the WebUSB API * AskWebUsb (3) = Allow sites to ask the user to grant access to a connected USB device Use the preceding information when configuring this policy.
DataUrlInSvgUseEnabled Data URL support for SVGUseElement
If this policy is disabled or not configured, Data URLs can't work in SVGUseElement.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DataUrlInSvgUseEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- This policy enables Data URL support for SVGUseElement, which is disabled by default starting in Microsoft Edge version 119.
- Supported on
- Microsoft Edge version 118, Windows 7 or later
- Template
- msedge.admx
This policy enables Data URL support for SVGUseElement, which is disabled by default starting in Microsoft Edge version 119. If this policy is enabled, Data URLs keep working in SVGUseElement. If this policy is disabled or not configured, Data URLs can't work in SVGUseElement.
DefaultPluginsSetting Default Adobe Flash setting (obsolete)
If you don't configure this policy, the user can change this setting manually.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultPluginsSetting
- Supported on
- Microsoft Edge version 77-87, Windows 7 or later
- Template
- msedge.admx
2Block the Adobe Flash plugin3Click to playOBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 87. This policy doesn't work because Flash is no longer supported by Microsoft Edge. 'PluginsAllowedForUrls' (Allow the Adobe Flash plug-in on specific sites) and 'PluginsBlockedForUrls' (Block the Adobe Flash plug-in on specific sites) are checked first, then this policy. The options are 'ClickToPlay' and 'BlockPlugins'. If you set this policy to 'BlockPlugins', this plugin is denied for all websites. 'ClickToPlay' lets the Flash plugin run, but users click the placeholder to start it. If you don't configure this policy, the user can change this setting manually. Note: Automatic playback is only for domains explicitly listed in the 'PluginsAllowedForUrls' policy. To turn automatic playback on for all sites, add http://* and https://* to the allowed list of URLs. Policy options mapping: * BlockPlugins (2) = Block the Adobe Flash plugin * ClickToPlay (3) = Click to play Use the preceding information when configuring this policy.
DefaultAutomaticDownloadsSetting Default automatic downloads setting
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultAutomaticDownloadsSetting
- Supported on
- Microsoft Edge version 110, Windows 7 or later
- Template
- msedge.admx
1Allow all websites to perform multiple downloads without requiring a user gesture between each download.2Prevent all websites from performing multiple downloads, even after a user gesture.Administrators can use this policy to control whether websites can perform multiple downloads successively. Individual site behavior can be managed using the AutomaticDownloadsAllowedForUrls and AutomaticDownloadsBlockedForUrls policies. Default behavior: - A user gesture is required for each additional download. - Users can modify their browser settings to disable successive downloads. Policy options mapping: * AllowAutomaticDownloads (1) = Allow all websites to perform multiple downloads without requiring a user gesture between each download. * BlockAutomaticDownloads (2) = Prevent all websites from performing multiple downloads, even after a user gesture. Use the preceding information when configuring this policy.
DefaultGeolocationSetting Default geolocation setting
If you don't configure this policy, 'AskGeolocation' is used and the user can change it.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultGeolocationSetting
- Stated default
- You can allow tracking by default ('AllowGeolocation'), deny it by default ('BlockGeolocation'), or ask the user each time a website requests their location ('AskGeolocation').
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
1Allow sites to track users' physical location2Don't allow any site to track users' physical location3Ask whenever a site wants to track users' physical locationSet whether websites can track users' physical locations. You can allow tracking by default ('AllowGeolocation'), deny it by default ('BlockGeolocation'), or ask the user each time a website requests their location ('AskGeolocation'). If you don't configure this policy, 'AskGeolocation' is used and the user can change it. Policy options mapping: * AllowGeolocation (1) = Allow sites to track users' physical location * BlockGeolocation (2) = Don't allow any site to track users' physical location * AskGeolocation (3) = Ask whenever a site wants to track users' physical location Use the preceding information when configuring this policy.
DefaultIdleDetectionSetting Default idle detection setting
If you do not configure this policy, users can decide whether to allow the Idle Detection API and can change this setting themselves.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultIdleDetectionSetting
- Supported on
- Microsoft Edge version 145, Windows 7 or later
- Template
- msedge.admx
1Allow sites to detect idle state without asking the user2Do not allow any site to detect the user's idle state3Ask every time a site wants to detect the user's idle stateSetting this policy to 1 - AllowIdleDetection allows websites to use the Idle Detection API without requesting user permission. Setting this policy to 2 - BlockIdleDetection prevents websites from using the Idle Detection API. Setting this policy to 3 - AskIdleDetection requires websites to request user permission each time before using the Idle Detection API. If you do not configure this policy, users can decide whether to allow the Idle Detection API and can change this setting themselves. Policy options mapping: * AllowIdleDetection (1) = Allow sites to detect idle state without asking the user * BlockIdleDetection (2) = Do not allow any site to detect the user's idle state * AskIdleDetection (3) = Ask every time a site wants to detect the user's idle state Use the preceding information when configuring this policy.
DefaultImagesSetting Default images setting
If you don't configure this policy, images are allowed by default, and the user can change this setting.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultImagesSetting
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
1Allow all sites to show all images2Don't allow any site to show imagesSet whether websites can display images. You can allow images on all sites ('AllowImages') or block them on all sites ('BlockImages'). If you don't configure this policy, images are allowed by default, and the user can change this setting. Policy options mapping: * AllowImages (1) = Allow all sites to show all images * BlockImages (2) = Don't allow any site to show images Use the preceding information when configuring this policy.
DefaultJavaScriptSetting Default JavaScript setting
If you don't configure this policy, all sites can run JavaScript by default, and the user can change this setting.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultJavaScriptSetting
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
1Allow all sites to run JavaScript2Don't allow any site to run JavaScriptSet whether websites can run JavaScript. You can allow it for all sites ('AllowJavaScript') or block it for all sites ('BlockJavaScript'). If you don't configure this policy, all sites can run JavaScript by default, and the user can change this setting. Policy options mapping: * AllowJavaScript (1) = Allow all sites to run JavaScript * BlockJavaScript (2) = Don't allow any site to run JavaScript Use the preceding information when configuring this policy.
DefaultLocalFontsSetting Default Local Fonts permission setting
If you don't configure this policy, users are prompted by default and can change this setting.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultLocalFontsSetting
- Stated default
- If you set the policy to BlockLocalFonts (value 2), access to local fonts is denied by default. If you don't configure this policy, users are prompted by default and can change this setting.
- Supported on
- Microsoft Edge version 149, Windows 7 or later
- Template
- msedge.admx
2Denies the Local Fonts permission on all sites by default3Ask every time a site wants to obtain the Local Fonts permissionSetting this policy controls the default behavior for the local fonts permission. If you set the policy to BlockLocalFonts (value 2), access to local fonts is denied by default. Sites are prevented from accessing information about local fonts. If you set the policy to AskLocalFonts (value 3), users are prompted when a site requests access to local fonts. If permission is granted, the site can access information about local fonts. If a site is included in 'LocalFontsAllowedForUrls' (Allow Local Fonts permission on these sites) or 'LocalFontsBlockedForUrls' (Block Local Fonts permission on these sites), then that setting overrides the value set for this policy. If you don't configure this policy, users are prompted by default and can change this setting. Policy options mapping: * BlockLocalFonts (2) = Denies the Local Fonts permission on all sites by default * AskLocalFonts (3) = Ask every time a site wants to obtain the Local Fonts permission Use the preceding information when configuring this policy.
DefaultNotificationsSetting Default notification setting
If you don't configure this policy, notifications are allowed by default, and the user can change this setting.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultNotificationsSetting
- Stated default
- You can allow them by default ('AllowNotifications'), deny them by default ('BlockNotifications'), or have the user be asked each time a website wants to show a notification ('AskNotifications'). If you don't configure this policy, notifications are allowed by default, and the user can change this setting.
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
1Allow sites to show desktop notifications2Don't allow any site to show desktop notifications3Ask every time a site wants to show desktop notificationsSet whether websites can display desktop notifications. You can allow them by default ('AllowNotifications'), deny them by default ('BlockNotifications'), or have the user be asked each time a website wants to show a notification ('AskNotifications'). If you don't configure this policy, notifications are allowed by default, and the user can change this setting. Policy options mapping: * AllowNotifications (1) = Allow sites to show desktop notifications * BlockNotifications (2) = Don't allow any site to show desktop notifications * AskNotifications (3) = Ask every time a site wants to show desktop notifications Use the preceding information when configuring this policy.
DefaultPopupsSetting Default pop-up window setting
If you don't configure this policy, pop-up windows are blocked by default, and users can change this setting.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultPopupsSetting
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
1Allow all sites to show pop-ups2Do not allow any site to show popupsSet whether websites can show pop-up windows. You can allow them on all websites ('AllowPopups') or block them on all sites ('BlockPopups'). If you don't configure this policy, pop-up windows are blocked by default, and users can change this setting. Policy options mapping: * AllowPopups (1) = Allow all sites to show pop-ups * BlockPopups (2) = Do not allow any site to show popups Use the preceding information when configuring this policy.
DefaultThirdPartyStoragePartitioningSetting Default setting for third-party storage partitioning (obsolete)
If this policy is set to 1 - AllowPartitioning, or unset, third-party storage partitioning will be allowed by default.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultThirdPartyStoragePartitioningSetting
- Stated default
- This policy controls whether third-party storage partitioning is allowed by default. If this policy is set to 1 - AllowPartitioning, or unset, third-party storage partitioning will be allowed by default.
- Supported on
- Microsoft Edge version 115-145, Windows 7 or later
- Template
- msedge.admx
1Allow third-party storage partitioning by default.2Disable third-party storage partitioning.OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 145. This policy controls whether third-party storage partitioning is allowed by default. If this policy is set to 1 - AllowPartitioning, or unset, third-party storage partitioning will be allowed by default. This default may be overridden for specific top-level origins by other means. If this policy is set to 2 - BlockPartitioning, third-party storage partitioning will be disabled for all contexts. Use ThirdPartyStoragePartitioningBlockedForOrigins to disable third-party storage partitioning for specific top-level origins. This feature has been removed starting in Microsoft Edge version 146. To ensure compatibility, use the requestStorageAccess method instead. For more information, see https://developer.mozilla.org/en-US/docs/Web/API/Document/requestStorageAccess. Policy options mapping: * AllowPartitioning (1) = Allow third-party storage partitioning by default. * BlockPartitioning (2) = Disable third-party storage partitioning. Use the preceding information when configuring this policy.
DefaultWindowManagementSetting Default Window Management permission setting
Setting the policy to "BlockWindowManagement" (value 2) automatically denies the window management permission to sites by default. Setting the policy to "AskWindowManagement" (value 3) by default prompts the user when the window management permission is requested.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultWindowManagementSetting
- Supported on
- Microsoft Edge version 123, Windows 7 or later
- Template
- msedge.admx
2Denies the Window Management permission on all sites by default3Ask every time a site wants obtain the Window Management permissionSetting the policy to "BlockWindowManagement" (value 2) automatically denies the window management permission to sites by default. This setting limits the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens. Setting the policy to "AskWindowManagement" (value 3) by default prompts the user when the window management permission is requested. If users allow the permission, it extends the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens. Not configuring the policy means the "AskWindowManagement" policy applies, but users can change this setting. Policy options mapping: * BlockWindowManagement (2) = Denies the Window Management permission on all sites by default * AskWindowManagement (3) = Ask every time a site wants obtain the Window Management permission Use the preceding information when configuring this policy.
ThirdPartyStoragePartitioningBlockedForOrigins Disable third-party storage partitioning for specific top-level origins (obsolete)
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ThirdPartyStoragePartitioningBlockedForOrigins
- Supported on
- Microsoft Edge version 115-145, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 145. This policy lets you set a list of URL patterns that specify top-level origins for which third-party storage partitioning (partitioning of cross-origin iframe storage) should be disabled. If this policy isn't set or a top-level origin doesn't match one of the URL patterns, then the value from 'DefaultThirdPartyStoragePartitioningSetting' (Default setting for third-party storage partitioning) will be used. Note that the patterns you list are treated as origins, not URLs, so you shouldn't specify a path. For detailed information about valid origin patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. This feature has been removed starting in Microsoft Edge version 146. To ensure compatibility, use the requestStorageAccess method instead. For more information, see https://developer.mozilla.org/en-US/docs/Web/API/Document/requestStorageAccess. Example value: www.example.com [*.]example.edu
LegacySameSiteCookieBehaviorEnabled Enable default legacy SameSite cookie behavior setting (obsolete)
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- LegacySameSiteCookieBehaviorEnabled
- Supported on
- Microsoft Edge version 80-94, Windows 7 or later
- Template
- msedge.admx
1Revert to legacy SameSite behavior for cookies on all sites2Use SameSite-by-default behavior for cookies on all sitesOBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 94. This policy doesn't work because it was only intended to serve only as a short-term mechanism to give enterprises more time to update their environments if they were found to be incompatible with the SameSite behavior change. If you still require legacy cookie behavior, please use 'LegacySameSiteCookieBehaviorEnabledForDomainList' (Revert to legacy SameSite behavior for cookies on specified sites) to configure behavior on a per-domain basis. Lets you revert all cookies to legacy SameSite behavior. Reverting to legacy behavior causes cookies that don't specify a SameSite attribute to be treated as if they were "SameSite=None", removes the requirement for "SameSite=None" cookies to carry the "Secure" attribute, and skips the scheme comparison when evaluating if two sites are same-site. If you don't set this policy, the default SameSite behavior for cookies will depend on other configuration sources for the SameSite-by-default feature, the Cookies-without-SameSite-must-be-secure feature, and the Schemeful Same-Site feature. These features can also be configured by a field trial or the same-site-by-default-cookies flag, the cookies-without-same-site-must-be-secure flag, or the schemeful-same-site flag in edge://flags. Policy options mapping: * DefaultToLegacySameSiteCookieBehavior (1) = Revert to legacy SameSite behavior for cookies on all sites * DefaultToSameSiteByDefaultCookieBehavior (2) = Use SameSite-by-default behavior for cookies on all sites Use the preceding information when configuring this policy.
WebUsbAllowDevicesForUrls Grant access to specific sites to connect to specific USB devices
If you don't configure this policy, the global default value is used for all sites either from the 'DefaultWebUsbGuardSetting' (Control use of the WebUSB API) policy if it is set, or the user's personal configuration otherwise.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebUsbAllowDevicesForUrls
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allows you to set a list of URLs that specify which sites will automatically be granted permission to access a USB device with the given vendor and product IDs. Each item in the list must contain both devices and URLs for the policy to be valid. Each item in devices can contain a vendor ID and product ID field. Any ID that is omitted is treated as a wildcard with one exception, and that exception is that a product ID can't be specified without a vendor ID also being specified. Otherwise, the policy isn't valid and is ignored. The USB permission model uses the URL of the requesting site ("requesting URL") and the URL of the top-level frame site ("embedding URL") to grant permission to the requesting URL to access the USB device. The requesting URL may be different than the embedding URL when the requesting site is loaded in an iframe. Therefore, the "urls" field can contain up to two URL strings delimited by a comma to specify the requesting and embedding URL respectively. If only one URL is specified, then access to the corresponding USB devices is granted when the requesting site's URL matches this URL regardless of embedding status. The URLs in "urls" must be valid URLs; otherwise, the policy is ignored. This is deprecated and only supported for backwards compatibility in the following manner. If both a requesting and embedding URL are specified, then the embedding URL is granted the permission as top-level origin, and the requesting URL is ignored entirely. If you don't configure this policy, the global default value is used for all sites either from the 'DefaultWebUsbGuardSetting' (Control use of the WebUSB API) policy if it is set, or the user's personal configuration otherwise. URL patterns in this policy shouldn't clash with the ones configured via 'WebUsbBlockedForUrls' (Block WebUSB on specific sites). If there's a clash, this policy takes precedence over 'WebUsbBlockedForUrls' and 'WebUsbAskForUrls' (Allow WebUSB on specific sites). Example value: [ { "devices": [ { "product_id": 5678, "vendor_id": 1234 } ], "urls": [ "https://contoso.com", "https://fabrikam.com" ] } ]
CookiesSessionOnlyForUrls Limit cookies from specific websites to the current session
This is also the default behavior if you don't configure this policy.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\CookiesSessionOnlyForUrls
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Cookies created by websites that match a URL pattern you define are deleted when the session ends (when the window closes). Cookies created by websites that don't match the pattern are controlled by the 'DefaultCookiesSetting' (Configure cookies) policy (if set) or by the user's personal configuration. This is also the default behavior if you don't configure this policy. You can also use the 'CookiesAllowedForUrls' (Allow cookies on specific sites) and 'CookiesBlockedForUrls' (Block cookies on specific sites) policies to control which websites can create cookies. Note there can't be conflicting URL patterns set between these three policies: - 'CookiesBlockedForUrls' - 'CookiesAllowedForUrls' - CookiesSessionOnlyForUrls For detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy. If you set the 'RestoreOnStartup' (Action to take on Microsoft Edge startup) policy to restore URLs from previous sessions, this policy is ignored, and cookies are stored permanently for those sites. Example value: https://www.contoso.com [*.]contoso.edu
PartitionedBlobUrlUsage Manage Blob URL Partitioning During Fetching and Navigation
If this policy is set to Enabled or not set, Blob URLs are partitioned.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PartitionedBlobUrlUsage
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 135, Windows 7 or later
- Template
- msedge.admx
The 'PartitionedBlobUrlUsage' (Manage Blob URL Partitioning During Fetching and Navigation) policy controls whether Blob URLs are partitioned during fetching and navigation. If this policy is set to Enabled or not set, Blob URLs are partitioned. If this policy is set to Disabled, Blob URLs can't be partitioned. This represents the Blob URL behavior before Microsoft Edge version 135. The policy is scheduled to be available through Microsoft Edge version 146. After this version, the policy will be removed, and Microsoft Edge will no longer support unpartitioned blob storage. For detailed information on third-party storage partitioning, see https://github.com/privacycg/storage-partitioning.
LegacySameSiteCookieBehaviorEnabledForDomainList Revert to legacy SameSite behavior for cookies on specified sites (obsolete)
If 'LegacySameSiteCookieBehaviorEnabled' is unset, the global default value falls back to other configuration sources.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\LegacySameSiteCookieBehaviorEnabledForDomainList
- Supported on
- Microsoft Edge version 80-132, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 132. Cookies set for domains match specified patterns revert to legacy SameSite behavior. Reverting to legacy behavior causes cookies that don't specify a SameSite attribute to be treated as if they were "SameSite=None", removes the requirement for "SameSite=None" cookies to carry the "Secure" attribute, and skips the scheme comparison when evaluating if two sites are same-site. If you don't set this policy, the global default value is used. The global default is also used for cookies on domains not covered by the patterns you specify. The global default value can be configured using the 'LegacySameSiteCookieBehaviorEnabled' (Enable default legacy SameSite cookie behavior setting) policy. If 'LegacySameSiteCookieBehaviorEnabled' is unset, the global default value falls back to other configuration sources. For detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Patterns you list in this policy are treated as domains, not URLs, so you shouldn't specify a scheme or port. The policy is discontinued from Edge 132. Example value: www.example.com [*.]example.edu
Microsoft Edge / Cryptography compliance policies
PreferSlowCiphers Prefer specific encryption cipher algorithms for TLS
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PreferSlowCiphers
- Supported on
- Microsoft Edge version 146, Windows 7 or later
- Template
- msedge.admx
Prefer ciphers satisfying the requirements of CNSA 1.0 and 2.0Use Microsoft Edge's default cipher orderThis policy configures Microsoft Edge to order its preferred encryption ciphers in TLS 1.3 based on algorithms approved by a specific compliance regime. Setting this policy does not guarantee that any specific algorithms will be negotiated. This policy allows server operators who support both compliant and non-compliant clients to differentiate between them, and use certain non-default algorithms with increased cryptographic strength only for clients explicitly configured to prefer them. Setting the policy to 'cnsa' configures Microsoft Edge to prefer ciphers required for compliance with the Commercial National Security Algorithm Suite versions 1.0 and 2.0 (CNSA 1.0 and 2.0). Not setting the policy, or setting it to 'default', configures Microsoft Edge to use its default ciphers. Setting this policy isn't required for security. The default cryptography used by Microsoft Edge is strong enough to withstand a brute-force attack using the entire power of the Sun. Setting this policy will cause Microsoft Edge to be slower when accessing websites. This policy only affects TLS 1.3 and QUIC. It doesn't affect earlier versions of TLS. Policy options mapping: * CNSA (cnsa) = Prefer ciphers satisfying the requirements of CNSA 1.0 and 2.0 * Default (default) = Use Microsoft Edge's default cipher order Use the preceding information when configuring this policy. Example value: cnsa
PreferSlowKexAlgorithms Prefer specific key exchange algorithms for TLS
If you leave this policy unset or set it to 'default', the browser uses its standard key exchange order.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PreferSlowKexAlgorithms
- Supported on
- Microsoft Edge version 146, Windows 7 or later
- Template
- msedge.admx
Prefer key exchange methods satisfying the requirements of CNSA 2.0Use Microsoft Edge's default supported groupsThis policy configures Microsoft Edge to prioritize certain key agreement algorithms (supported groups) in TLS 1.3 based on compliance requirements. If you set this policy to 'cnsa2', Microsoft Edge prefers the algorithms required for the Commercial National Security Algorithm Suite 2.0 (CNSA 2.0). If you leave this policy unset or set it to 'default', the browser uses its standard key exchange order. This policy does not guarantee negotiation of a specific algorithm. It is designed to help server operators distinguish clients with compliance requirements and apply higher-strength, non-default algorithms only when appropriate. This policy applies only to TLS 1.3 and QUIC. The default cryptography used by Microsoft Edge already provides strong security, but enabling this policy may reduce performance when accessing websites. Policy options mapping: * CNSA2.0 (cnsa2) = Prefer key exchange methods satisfying the requirements of CNSA 2.0 * Default (default) = Use Microsoft Edge's default supported groups Use the preceding information when configuring this policy. Example value: cnsa2
Microsoft Edge / Default search provider
NewTabPageSearchBox Configure the new tab page search box experience
If you disable or don't configure this policy and: - If the address bar default search engine is Bing, the new tab page uses the search box to search on new tabs.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NewTabPageSearchBox
- Supported on
- Microsoft Edge version 85, Windows 7 or later
- Template
- msedge.admx
Search box (Recommended)Address barYou can configure the new tab page search box to use "Search box (Recommended)" or "Address bar" to search on new tabs. This policy only works if you set the search engine to a value other than Bing by setting the following two policies: 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL). If you disable or don't configure this policy and: - If the address bar default search engine is Bing, the new tab page uses the search box to search on new tabs. - If the address bar default search engine isn't Bing, users are offered an additional choice (use "Address bar") when searching on new tabs. If you enable this policy and set it to: - "Search box (Recommended)" ('bing'), the new tab page uses the search box to search on new tabs. - "Address bar" ('redirect'), the new tab page search box uses the address bar to search on new tabs. Policy options mapping: * bing (bing) = Search box (Recommended) * redirect (redirect) = Address bar Use the preceding information when configuring this policy. Example value: bing
DefaultSearchProviderEncodings Default search provider encodings
If not configured, the default, UTF-8, is used.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\DefaultSearchProviderEncodings
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specify the character encodings supported by the search provider. Encodings are code page names like UTF-8, GB2312, and ISO-8859-1. They're tried in the order provided. This policy is optional. If not configured, the default, UTF-8, is used. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies. Starting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy won't be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy. Example value: UTF-8 UTF-16 GB2312 ISO-8859-1
DefaultSearchProviderKeyword Default search provider keyword
If you don't configure it, no keyword activates the search provider.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultSearchProviderKeyword
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specifies the keyword, which is the shortcut used in the Address Bar to trigger the search for this provider. This policy is optional. If you don't configure it, no keyword activates the search provider. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies. Starting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy. Example value: mis
DefaultSearchProviderName Default search provider name
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultSearchProviderName
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specifies the name of the default search provider. If you enable this policy, you set the name of the default search provider. If you don't enable this policy or if you leave it empty, the host name specified by the search URL is used. 'DefaultSearchProviderName' should be set to an organization-approved encrypted search provider that corresponds to the encrypted search provider set in DTBC-0008. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies. Starting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy isn't be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy. Example value: My Intranet Search
DefaultSearchProviderSearchURL Default search provider search URL
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultSearchProviderSearchURL
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specifies the URL of the search engine used for a default search. The URL contains the string '{searchTerms}', which is replaced at query time by the terms the user is searching for. Specify Bing's search URL as: '{bing:baseURL}search?q={searchTerms}'. Specify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'. This policy is required when you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) policy; if you don't enable the latter policy, this policy is ignored. Starting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy won't be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy. Example value: https://search.contoso.com/search?q={searchTerms}
DefaultSearchProviderSuggestURL Default search provider URL for suggestions
If you don't configure it, users can't see search suggestions; they see suggestions from their browsing history and favorites.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultSearchProviderSuggestURL
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specifies the URL for the search engine used to provide search suggestions. The URL contains the string '{searchTerms}', which is replaced at query time by the text the user entered so far. This policy is optional. If you don't configure it, users can't see search suggestions; they see suggestions from their browsing history and favorites. Bing's suggest URL can be specified as: '{bing:baseURL}qbox?query={searchTerms}'. Google's suggest URL can be specified as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies. Starting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy isn't added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy. Example value: https://search.contoso.com/suggest?q={searchTerms}
DefaultSearchProviderEnabled Enable the default search provider
If these are left empty (not configured) or configured incorrectly, the user can choose the default provider. If you don't configure this policy, the default search provider is enabled, and the user can choose the default search provider and set the search provider list.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultSearchProviderEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enables the ability to use a default search provider. If you enable this policy, a user can search for a term by typing in the address bar (as long as what they type isn't a URL). You can specify the default search provider to use by enabling the rest of the default search policies. If these are left empty (not configured) or configured incorrectly, the user can choose the default provider. If you disable this policy, the user can't search from the address bar. If you enable or disable this policy, users can't change or override it. If you don't configure this policy, the default search provider is enabled, and the user can choose the default search provider and set the search provider list. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX. Starting in Microsoft Edge 84, you can set this policy as a recommended policy.
DefaultSearchProviderImageURLPostParams Parameters for an image URL that uses POST
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultSearchProviderImageURLPostParams
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
If you enable this policy, it specifies the parameters used when an image search that uses POST is performed. The policy consists of comma-separated name/value pairs. If a value is a template parameter, like {imageThumbnail} in the preceding example, it's replaced with real image thumbnail data. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies. Specify Bing's Image Search URL Post Params as: 'imageBin={google:imageThumbnailBase64}'. Specify Google's Image Search URL Post Params as: 'encoded_image={google:imageThumbnail},image_url={google:imageURL},sbisrc={google:imageSearchSource},original_width={google:imageOriginalWidth},original_height={google:imageOriginalHeight}'. If you don't set this policy, image search requests are sent using the GET method. Starting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy. Example value: content={imageThumbnail},url={imageURL},sbisrc={SearchSource}
DefaultSearchProviderImageURL Specifies the search-by-image feature for the default search provider
If you don't configure it, image search isn't available.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultSearchProviderImageURL
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specifies the URL to the search engine used for image search. Search requests are sent using the GET method. This policy is optional. If you don't configure it, image search isn't available. Specify Bing's Image Search URL as: '{bing:baseURL}images/detail/search?iss=sbiupload&FORM=ANCMS1#enterInsights'. Specify Google's Image Search URL as: '{google:baseURL}searchbyimage/upload'. See 'DefaultSearchProviderImageURLPostParams' (Parameters for an image URL that uses POST) policy to finish configuring image search. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies. Starting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the 'ManagedSearchEngines' (Manage Search Engines) policy. Example value: https://search.contoso.com/searchbyimage/upload
Microsoft Edge / Downloads
ShowDownloadsInsecureWarningsEnabled Enable insecure download warnings
If you enable or don't configure this policy, when a user tries to download potentially dangerous content from an HTTP site, the user receives a UI warning, such as "Insecure download blocked".
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ShowDownloadsInsecureWarningsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 128, Windows 7 or later
- Template
- msedge.admx
Enables warnings when potentially dangerous content is downloaded over HTTP. If you enable or don't configure this policy, when a user tries to download potentially dangerous content from an HTTP site, the user receives a UI warning, such as "Insecure download blocked". The user can still download the item. If you disable this policy, the warnings for insecure downloads are suppressed.
Microsoft Edge / Edge Website Typo Protection settings
TyposquattingCheckerEnabled Configure Edge Website Typo Protection
If you don't configure this policy, Edge Website Typo Protection is turned on but users can choose whether to use Edge Website Typo Protection.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- TyposquattingCheckerEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, Edge Website Typo Protection is turned on.
- Supported on
- Microsoft Edge version 96, Windows 7 or later
- Template
- msedge.admx
Microsoft Security BaselineTyposquattingCheckerEnabled = 1
This policy setting lets you configure whether to turn on Edge Website Typo Protection. Edge Website Typo Protection provides warning messages to help protect your users from potential typosquatting sites. By default, Edge Website Typo Protection is turned on. If you enable this policy, Edge Website Typo Protection is turned on. If you disable this policy, Edge Website Typo Protection is turned off. If you don't configure this policy, Edge Website Typo Protection is turned on but users can choose whether to use Edge Website Typo Protection.
TyposquattingAllowListDomains Configure the list of domains for which Microsoft Edge Website Typo Protection won't trigger warnings
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\TyposquattingAllowListDomains
- Supported on
- Microsoft Edge version 121, Windows 7 or later
- Template
- msedge.admx
Configures the list of Microsoft Edge Website Typo Protection trusted domains. This means: Microsoft Edge Website Typo Protection won't check for potentially malicious typosquatting websites. If you enable this policy, Microsoft Edge Website Typo Protection trusts these domains. If you disable or don't set this policy, default Microsoft Edge Website Typo Protection protection is applied to all resources. This only takes effect when TyposquattingCheckerEnabled policy isn't set or is set to enabled. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10/11 Pro; or Enterprise instances that enrolled for device management; or macOS instances that are that are managed via MDM or joined to a domain via MCX. This policy doesn't apply if your organization has enabled Microsoft Defender for Endpoint. You must configure your allowlists and blocklists in Microsoft 365 Defender portal using Indicators (Settings > Endpoints > Indicators). Example value: mydomain.com myuniversity.edu
PreventTyposquattingPromptOverride Prevent bypassing Edge Website Typo Protection prompts for sites
If you disable or don't configure this setting, users can ignore Edge Website Typo Protection warnings and continue to the site.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PreventTyposquattingPromptOverride
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 121, Windows 7 or later
- Template
- msedge.admx
This policy setting lets you decide whether users can override the Edge Website Typo Protection warnings about potential typosquatting websites. If you enable this setting, users can't ignore Edge Website Typo Protection warnings, and they're blocked from continuing to the site. If you disable or don't configure this setting, users can ignore Edge Website Typo Protection warnings and continue to the site. This only takes effect when TyposquattingCheckerEnabled policy isn't set or is set to enabled. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are managed via MDM or joined to a domain via MCX.
Microsoft Edge / Edge Workspaces settings
WorkspacesNavigationSettings Configure navigation settings per groups of URLs in Microsoft Edge Workspaces
If you don't configure this policy, Microsoft Edge Workspaces use only default and internally configured navigation settings.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WorkspacesNavigationSettings
- Supported on
- Microsoft Edge version 110, Windows 7 or later
- Template
- msedge.admx
This setting lets you define groups of URLs, and apply specific Microsoft Edge Workspaces navigation settings to each group. If you configure this policy, Microsoft Edge Workspaces use the configured settings when deciding whether and how to share navigations among collaborators in a Microsoft Edge Workspace. If you don't configure this policy, Microsoft Edge Workspaces use only default and internally configured navigation settings. For more information about configuration options, see https://go.microsoft.com/fwlink/?linkid=2218655 Note, format url_patterns according to https://go.microsoft.com/fwlink/?linkid=2095322. You can configure the url_regex_patterns in this policy to match multiple URLs using a Perl style regular expression for the pattern. Note that pattern matches are case sensitive. For more information about the regular expression rules that are used, refer to https://go.microsoft.com/fwlink/p/?linkid=2133903. Example value: [ { "navigation_options": { "do_not_send_to": true, "remove_all_query_parameters": true }, "url_patterns": [ "https://contoso.com", "https://www.fabrikam.com", ".exact.hostname.com" ] }, { "navigation_options": { "query_parameters_to_remove": [ "username", "login_hint" ] }, "url_patterns": [ "https://adatum.com" ] }, { "navigation_options": { "do_not_send_from": true, "prefer_initial_url": true }, "url_regex_patterns": [ "\\Ahttps://.*?tafe\\..*?trs.*?\\.fabrikam.com/Sts" ] } ]
EdgeWorkspacesEnabled Enable Workspaces
If you enable or don't configure this policy, users can access the Microsoft Edge Workspaces feature.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeWorkspacesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 106, Windows 7 or later
- Template
- msedge.admx
Microsoft Edge Workspaces helps improve productivity for users in your organization. If you enable or don't configure this policy, users can access the Microsoft Edge Workspaces feature. If you disable this policy, users won't be able to access the Microsoft Edge Workspaces feature. To learn more about the feature, see https://go.microsoft.com/fwlink/?linkid=2209950
Microsoft Edge / Experimentation
FeatureFlagOverridesControl Configure users ability to override feature flags
If you don't configure this policy, the behavior is the same as the 'OverridesEnabled'.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- FeatureFlagOverridesControl
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
2Allow users to override feature flags using command line arguments only1Allow users to override feature flags0Prevent users from overriding feature flagsConfigures users ability to override state of feature flags. If you set this policy to 'CommandLineOverridesEnabled', users can override state of feature flags using command line arguments but not edge://flags page. If you set this policy to 'OverridesEnabled', users can override state of feature flags using command line arguments or edge://flags page. If you set this policy to 'OverridesDisabled', users can't override state of feature flags using command line arguments or edge://flags page. If you don't configure this policy, the behavior is the same as the 'OverridesEnabled'. Policy options mapping: * CommandLineOverridesEnabled (2) = Allow users to override feature flags using command line arguments only * OverridesEnabled (1) = Allow users to override feature flags * OverridesDisabled (0) = Prevent users from overriding feature flags Use the preceding information when configuring this policy.
Microsoft Edge / Extensions
ExtensionInstallAllowlist Allow specific extensions to be installed
By default, all extensions are allowed.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ExtensionInstallAllowlist
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Setting this policy specifies which extensions aren't subject to the blocklist. A blocklist value of * means all extensions are blocked and users can only install extensions listed in the allow list. By default, all extensions are allowed. However, if you prohibited extensions by policy, you can use the list of allowed extensions to change that policy. Example value: extension_id1 extension_id2
ExtensionInstallTypeBlocklist Blocklist for extension install types
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ExtensionInstallTypeBlocklist
- Supported on
- Microsoft Edge version 123, Windows 7 or later
- Template
- msedge.admx
The blocklist controls which extension install types are disallowed. Setting the "command_line" will block an extension from being loaded from command line. Policy options mapping: * command_line (command_line) = Blocks extensions from being loaded from command line Use the preceding information when configuring this policy. Example value: command_line
BlockExternalExtensions Blocks external extensions from being installed
If you disable this setting or leave it unset, external extensions are allowed to be installed.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- BlockExternalExtensions
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 88, Windows 7 or later
- Template
- msedge.admx
Control the installation of external extensions. If you enable this setting, external extensions are blocked from being installed. If you disable this setting or leave it unset, external extensions are allowed to be installed. External extensions and their installation are documented at [Alternate extension distribution methods](/microsoft-edge/extensions-chromium/developer-guide/alternate-distribution-options).
ExtensionExtendedBackgroundLifetimeForPortConnectionsToUrls Configure a list of origins that grant an extended background lifetime to connecting extensions.
If unset, the policy's default values are used.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ExtensionExtendedBackgroundLifetimeForPortConnectionsToUrls
- Supported on
- Microsoft Edge version 128, Windows 7 or later
- Template
- msedge.admx
Extensions that connect to one of these origins keep running as long as the port is connected. If unset, the policy's default values are used. These are the app origins that offer software development kits (SDKs) that are known to not offer the possibility of restarting a closed connection to a previous state: - Smart Card Connector - Citrix Receiver (stable, beta, back-up) - VMware Horizon (stable, beta) If set, the default value list is extended with the newly configured values. The defaults and policy-provided entries grant the exception to the connecting extensions as long as the port is connected. Example value: chrome-extension://abcdefghijklmnopabcdefghijklmnop/ chrome-extension://bcdefghijklmnopabcdefghijklmnopa/
ExtensionAllowedTypes Configure allowed extension types
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ExtensionAllowedTypes
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Setting the policy controls which apps and extensions can be installed in Microsoft Edge, which hosts they can interact with, and limits runtime access. If you don't set this policy, there aren't any restrictions on acceptable extension and app types. Extensions and apps, which have a type that's not on the list can't be installed. Each value should be one of these strings: * "extension" * "theme" * "user_script" * "hosted_app" See the Microsoft Edge extensions documentation for more information about these types. Note: This policy also affects extensions and apps to be force-installed using 'ExtensionInstallForcelist' (Control which extensions are installed silently). Starting in Microsoft Edge version 149, the 'Microsoft365CopilotChatIconEnabled' (Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar) policy controls the display of Copilot in the toolbar. Policy options mapping: * extension (extension) = Extension * theme (theme) = Theme * user_script (user_script) = User script * hosted_app (hosted_app) = Hosted app * legacy_packaged_app (legacy_packaged_app) = Legacy packaged app * platform_app (platform_app) = Platform app Use the preceding information when configuring this policy. Example value: hosted_app
ExtensionInstallSources Configure extension and user script install sources
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ExtensionInstallSources
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Define URLs that can install extensions and themes. Define URLs that can install extensions and themes directly without having to drag and drop the packages to the edge://extensions page. Each item in this list is an extension-style match pattern (see https://go.microsoft.com/fwlink/?linkid=2095039). Users can easily install items from any URL that matches an item in this list. Both the location of the *.crx file and the page where the download is started from (in other words, the referrer) must be allowed by these patterns. Don't host the files at a location that requires authentication. The 'ExtensionInstallBlocklist' (Control which extensions cannot be installed) policy takes precedence over this policy. Any extensions that's on the blocklist won't be installed, even if it comes from a site on this list. Example value: https://corp.contoso.com/*
ExtensionSettings Configure extension management settings
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ExtensionSettings
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Setting this policy controls extension management settings for Microsoft Edge, including those configured by other extension-related policies. This policy supersedes any legacy policies. This policy maps an extension ID or update URL to a specific configuration. You can define a default configuration using the special ID "*", which applies to extensions without a custom configuration. Note that any per-ID extension setting from either 'ExtensionInstallForcelist' (Control which extensions are installed silently), 'ExtensionInstallAllowlist' (Allow specific extensions to be installed), 'ExtensionInstallBlocklist' (Control which extensions cannot be installed), or 'ExtensionSettings' (Configure extension management settings) will only inherit 'installation_mode' and 'update_url' from the "*" defaults. It will not inherit any other properties. With an update URL, configuration applies to extensions with the exact update URL stated in the extension manifest. If the 'override_update_url' flag is set to true, the extension is installed and updated using the update URL specified in the 'ExtensionInstallForcelist' policy or in 'update_url' field in this policy. The flag 'override_update_url' is ignored if the 'update_url' is the Edge Add-ons website update URL. For more details, check out the detailed guide to ExtensionSettings policy available at https://go.microsoft.com/fwlink/?linkid=2161555. To block extensions from a particular third party store, you only need to block the update_url for that store. For example, if you want to block extensions from Chrome Web Store, you can use the following JSON. {"update_url:https://clients2.google.com/service/update2/crx":{"installation_mode":"blocked"}} Note that you can still use 'ExtensionInstallForcelist' and 'ExtensionInstallAllowlist' to allow / force install specific extensions even if the store is blocked using the JSON in the previous example. If the 'sidebar_auto_open_blocked' flag is set to true in an extension's configuration, the hub-app (sidebar app) corresponding to the specified extension will be prevented from automatically opening. On Windows instances, apps and extensions from outside the Microsoft Edge Add-ons website can only be forced installed if the instance is joined to a Microsoft Active Directory domain or joined to Microsoft Azure Active Directory®. On macOS instances, apps and extensions from outside the Microsoft Edge Add-ons website can only be force installed if the instance is managed via MDM, joined to a domain via MCX. Starting in Microsoft Edge version 149, the 'Microsoft365CopilotChatIconEnabled' (Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar) policy controls the display of Copilot in the toolbar. Example value: { "*": { "allowed_types": [ "hosted_app" ], "blocked_install_message": "Custom error message.", "blocked_permissions": [ "downloads", "bookmarks" ], "install_sources": [ "https://company-intranet/apps" ], "installation_mode": "blocked", "runtime_allowed_hosts": [ "*://good.contoso.com" ], "runtime_blocked_hosts": [ "*://*.contoso.com" ] }, "abcdefghijklmnopabcdefghijklmnop": { "blocked_permissions": [ "history" ], "installation_mode": "allowed", "minimum_version_required": "1.0.1", "file_url_navigation_allowed": true }, "bcdefghijklmnopabcdefghijklmnopa": { "allowed_permissions": [ "downloads" ], "installation_mode": "force_installed", "override_update_url": true, "sidebar_auto_open_blocked": true, "runtime_allowed_hosts": [ "*://good.contoso.com" ], "runtime_blocked_hosts": [ "*://*.contoso.com" ], "toolbar_state": "force_shown", "update_url": "https://contoso.com/update_url" }, "cdefghijklmnopabcdefghijklmnopab": { "blocked_install_message": "Custom error message.", "installation_mode": "blocked" }, "defghijklmnopabcdefghijklmnopabc,efghijklmnopabcdefghijklmnopabcd": { "blocked_install_message": "Custom error message.", "installation_mode": "blocked" }, "fghijklmnopabcdefghijklmnopabcde": { "blocked_install_message": "Custom removal message.", "installation_mode": "removed" }, "update_url:https://www.contoso.com/update.xml": { "allowed_permissions": [ "downloads" ], "blocked_permissions": [ "wallpaper" ], "installation_mode": "allowed" } } Compact example value: {"*": {"allowed_types": ["hosted_app"], "blocked_install_message": "Custom error message.", "blocked_permissions": ["downloads", "bookmarks"], "install_sources": ["https://company-intranet/apps"], "installation_mode": "blocked", "runtime_allowed_hosts": ["*://good.contoso.com"], "runtime_blocked_hosts": ["*://*.contoso.com"]}, "abcdefghijklmnopabcdefghijklmnop": {"blocked_permissions": ["history"], "installation_mode": "allowed", "minimum_version_required": "1.0.1", "file_url_navigation_allowed": true}, "bcdefghijklmnopabcdefghijklmnopa": {"allowed_permissions": ["downloads"], "installation_mode": "force_installed", "override_update_url": true, "sidebar_auto_open_blocked": true, "runtime_allowed_hosts": ["*://good.contoso.com"], "runtime_blocked_hosts": ["*://*.contoso.com"], "toolbar_state": "force_shown", "update_url": "https://contoso.com/update_url"}, "cdefghijklmnopabcdefghijklmnopab": {"blocked_install_message": "Custom error message.", "installation_mode": "blocked"}, "defghijklmnopabcdefghijklmnopabc,efghijklmnopabcdefghijklmnopabcd": {"blocked_install_message": "Custom error message.", "installation_mode": "blocked"}, "fghijklmnopabcdefghijklmnopabcde": {"blocked_install_message": "Custom removal message.", "installation_mode": "removed"}, "update_url:https://www.contoso.com/update.xml": {"allowed_permissions": ["downloads"], "blocked_permissions": ["wallpaper"], "installation_mode": "allowed"}}
ExtensionManifestV2Availability Control Manifest v2 extension availability
If the policy is set to Default or not set, v2 extension loading is decided by browser. This option is going to be treated the same as if the policy is unset after v2 support is turned off by default.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ExtensionManifestV2Availability
- Stated default
- This option is going to be treated the same as if the policy is unset after v2 support is turned off by default. The option is going to be treated the same as if the policy isn't set before v2 support is turned off by default.
- Supported on
- Microsoft Edge version 123, Windows 7 or later
- Template
- msedge.admx
0Default browser behavior1Manifest v2 is disabled2Manifest v2 is enabled3Manifest v2 is enabled for forced extensions onlyControl if Manifest v2 extensions can be used by browser. Manifest v2 extensions support will be deprecated and all extensions need to be migrated to v3 in the future. More information about and the timeline of the migration hasn't been established. If the policy is set to Default or not set, v2 extension loading is decided by browser. This follows the preceding timeline when it's established. If the policy is set to Disable, v2 extensions installation are blocked, and existing ones are disabled. This option is going to be treated the same as if the policy is unset after v2 support is turned off by default. If the policy is set to Enable, v2 extensions are allowed. The option is going to be treated the same as if the policy isn't set before v2 support is turned off by default. If the policy is set to EnableForForcedExtensions, force installed v2 extensions are allowed. This includes extensions that are listed by 'ExtensionInstallForcelist' (Control which extensions are installed silently) or 'ExtensionSettings' (Configure extension management settings) with installation_mode "force_installed" or "normal_installed". All other v2 extensions are disabled. The option is always available regardless of the manifest migration state. Extensions availabilities are still controlled by other policies. Policy options mapping: * Default (0) = Default browser behavior * Disable (1) = Manifest v2 is disabled * Enable (2) = Manifest v2 is enabled * EnableForForcedExtensions (3) = Manifest v2 is enabled for forced extensions only Use the preceding information when configuring this policy.
EdgeSafeHostingExtensionEnabled Control Microsoft Edge Safe Hosting Extension
If you enable or don't configure this policy, the extension installs automatically and remains installed for 90 days after the user's last visit, then is removed if no further activity occurs.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeSafeHostingExtensionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 145, Windows 7 or later
- Template
- msedge.admx
This policy controls whether the Microsoft Edge Safe Hosting component extension is installed automatically when users visit supported Microsoft services, such as Microsoft 365 Copilot app. The Microsoft Edge Safe Hosting extension provides additional security capabilities for these services. When a user accesses a supported service, the extension installs automatically to enable those protections. If you enable or don't configure this policy, the extension installs automatically and remains installed for 90 days after the user's last visit, then is removed if no further activity occurs. If you disable this policy, the extension won't install automatically. If it’s already installed, it will be removed. Note: This policy controls only automatic installation. It doesn’t prevent users from manually installing other extensions from the Microsoft Edge Add-ons website.
ExtensionDeveloperModeSettings Control the availability of developer mode on extensions page
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ExtensionDeveloperModeSettings
- Supported on
- Microsoft Edge version 128, Windows 7 or later
- Template
- msedge.admx
0Allow the usage of developer mode on extensions page1Do not allow the usage of developer mode on extensions pageControl if users can turn on Developer Mode on edge://extensions. If the policy isn't set, users can turn on developer mode on the extension page unless DeveloperToolsAvailability policy is set to DeveloperToolsDisallowed (2). If the policy is set to Allow (0), users can turn on developer mode on the extensions page. If the policy is set to Disallow (1), users can't turn on developer mode on the extensions page. If this policy is set, DeveloperToolsAvailability can no longer control extensions developer mode. Policy options mapping: * Allow (0) = Allow the usage of developer mode on extensions page * Disallow (1) = Do not allow the usage of developer mode on extensions page Use the preceding information when configuring this policy.
ExtensionInstallForcelist Control which extensions are installed silently
By default, the Microsoft Edge Add-ons website's update URL is used.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ExtensionInstallForcelist
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Set this policy to specify a list of apps and extensions that install silently, without user interaction. Users can't uninstall or turn off this setting. Permissions are granted implicitly, including the enterprise.deviceAttributes and enterprise.platformKeys extension APIs. Note: These two APIs aren't available to apps and extensions that aren't force-installed. If you don't set this policy, no apps or extensions are autoinstalled and users can uninstall any app in Microsoft Edge. This policy supersedes 'ExtensionInstallBlocklist' (Control which extensions cannot be installed) policy. If a previously force-installed app or extension is removed from this list, Microsoft Edge automatically uninstalls it. For Windows instances not joined to a Microsoft Active Directory domain, forced installation is limited to apps and extensions listed in the Microsoft Edge Add-ons website. On macOS instances, apps and extensions from outside the Microsoft Edge Add-ons website can only be force installed if the instance is managed via MDM, or joined to a domain via MCX. The source code of any extension can be altered by users with developer tools, potentially rendering the extension unfunctional. If there's a concern, configure the 'DeveloperToolsAvailability' (Control where developer tools can be used) policy. Each list item of the policy is a string that contains an extension ID and, optionally, and an optional "update" URL separated by a semicolon (;). The extension ID is the 32-letter string found, for example, on edge://extensions when in Developer mode. If specified, the "update" URL should point to an Update Manifest XML document ( https://go.microsoft.com/fwlink/?linkid=2095043 ). The update URL should use one of the following schemes: http, https, or file. By default, the Microsoft Edge Add-ons website's update URL is used. The "update" URL set in this policy is only used for the initial installation; subsequent updates of the extension use the update URL in the extension's manifest. The update url for subsequent updates can be overridden using the ExtensionSettings policy. See https://learn.microsoft.com/deployedge/microsoft-edge-manage-extensions-ref-guide. Note: This policy doesn't apply to InPrivate mode. Read about hosting extensions at [Publish and update extensions in the Microsoft Edge Add-ons website](/microsoft-edge/extensions-chromium/enterprise/hosting-and-updating). Starting in Microsoft Edge version 149, the 'Microsoft365CopilotChatIconEnabled' (Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar) policy controls the display of Copilot in the toolbar. Example value: gbchcmhmhahfdphkhkmpfmihenigjmpp;https://edge.microsoft.com/extensionwebstorebase/v1/crx abcdefghijklmnopabcdefghijklmnop
ExtensionInstallBlocklist Control which extensions cannot be installed
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ExtensionInstallBlocklist
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Lets you specify which extensions the users CANNOT install. Extensions already installed will be disabled if blocked, without a way for the user to enable them. After a disabled extension is removed from the blocklist it will automatically get re-enabled. A blocklist value of '*' means all extensions are blocked unless they are explicitly listed in the allowlist. If this policy isn't set, the user can install any extension in Microsoft Edge. Starting in Microsoft Edge version 149, the 'Microsoft365CopilotChatIconEnabled' (Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar) policy controls the display of Copilot in the toolbar. Example value: extension_id1 extension_id2
MandatoryExtensionsForInPrivateNavigation Specify extensions users must allow in order to navigate using InPrivate mode
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\MandatoryExtensionsForInPrivateNavigation
- Supported on
- Microsoft Edge version 139, Windows 7 or later
- Template
- msedge.admx
This policy lets you specify a list of extension IDs that the user must explicitly allow to run in InPrivate mode in order to enable InPrivate browsing. If users don't allow all listed extensions to run in InPrivate mode, they're unable to navigate using InPrivate. If any extension in the list isn't installed, InPrivate navigation is blocked. This policy only applies when InPrivate mode is enabled. If InPrivate mode is disabled using the InPrivateModeAvailability policy, this policy has no effect. Example value: abcdefghijklmnopabcdefghijklmnop
Microsoft Edge / Games settings
GamerModeEnabled Enable Gamer Mode (obsolete)
If you enable or don't configure this policy, users can opt into Gamer Mode.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- GamerModeEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 117-140, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 140. Microsoft Edge Gamer Mode allows gamers to personalize their browser with gaming themes and gives them the option of enabling Efficiency Mode for PC gaming, the Gaming feed on new tabs, sidebar apps for gamers, and more. If you enable or don't configure this policy, users can opt into Gamer Mode. If you disable this policy, Gamer Mode is disabled. Note: With Microsoft Edge version 141, this policy is obsolete because the Gamer Mode feature is removed.
Microsoft Edge / Generative AI
GenAILocalFoundationalModelSettings Settings for GenAI local foundational model
If you disable or don't configure this policy, the default applies, and the model is downloaded automatically and used for inference.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- GenAILocalFoundationalModelSettings
- Supported on
- Microsoft Edge version 132, Windows 7 or later
- Template
- msedge.admx
0Downloads model automatically1Do not download modelThis policy controls whether Microsoft Edge downloads the foundational GenAI model and uses it for local inference. If you enable this policy and set the value to Allowed (0), the model is downloaded automatically and used for inference. If you enable this policy and set the value to Disallowed (1), the model isn't downloaded, and the existing model (if already downloaded) is deleted. If you disable or don't configure this policy, the default applies, and the model is downloaded automatically and used for inference. Note: This policy supports dynamic refresh, so changes take effect without requiring a browser restart. Model downloading can also be disabled by ComponentUpdatesEnabled. Policy options mapping: * Allowed (0) = Downloads model automatically * Disallowed (1) = Do not download model Use the preceding information when configuring this policy.
Microsoft Edge / HTTP authentication
BasicAuthOverHttpEnabled Allow Basic authentication for HTTP
If you enable or don't configure this policy, Basic authentication challenges received over nonsecure HTTP are allowed.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- BasicAuthOverHttpEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 88, Windows 7 or later
- Template
- msedge.admx
Microsoft Security BaselineBasicAuthOverHttpEnabled = 0
If you enable or don't configure this policy, Basic authentication challenges received over nonsecure HTTP are allowed. If you disable this policy, nonsecure HTTP requests from the Basic authentication scheme are blocked, and only secure HTTPS is allowed. This policy setting is ignored (and Basic is always forbidden) if the 'AuthSchemes' (Supported authentication schemes) policy is set and doesn't include Basic.
AllowCrossOriginAuthPrompt Allow cross-origin HTTP Authentication prompts
If you don't configure this policy, it's disabled and third-party images can't show an authentication prompt.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AllowCrossOriginAuthPrompt
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Controls whether third-party images on a page can show an authentication prompt. Typically, this is disabled as a phishing defense. If you don't configure this policy, it's disabled and third-party images can't show an authentication prompt.
AuthServerAllowlist Configure list of allowed authentication servers
If you don't configure this policy, Microsoft Edge tries to detect if a server is on the intranet - only then does it respond to IWA requests.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AuthServerAllowlist
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specifies which servers to enable for integrated authentication. Integrated authentication is only enabled when Microsoft Edge receives an authentication challenge from a proxy or from a server in this list. Separate multiple server names with commas. Wildcards (*) are allowed. If you don't configure this policy, Microsoft Edge tries to detect if a server is on the intranet - only then does it respond to IWA requests. If the server is on the internet, IWA requests from it are ignored by Microsoft Edge. Example value: *contoso.com,contoso.com
DisableAuthNegotiateCnameLookup Disable CNAME lookup when negotiating Kerberos authentication
If you disable this policy or don't configure it, the canonical name of the server is used.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DisableAuthNegotiateCnameLookup
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Determines whether the generated Kerberos SPN is based on the canonical DNS name (CNAME) or on the original name entered. If you enable this policy, CNAME lookup is skipped and the server name (as entered) is used. If you disable this policy or don't configure it, the canonical name of the server is used. This is determined through CNAME lookup.
EnableAuthNegotiatePort Include non-standard port in Kerberos SPN
If you don't configure or disable this policy, the generated Kerberos SPN won't include a port in any case.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EnableAuthNegotiatePort
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specifies whether the generated Kerberos service principal name (SPN) should include a nonstandard port. If you enable this policy, and if a user includes a nonstandard port (a port other than 80 or 443) in a URL, that port is included in the generated Kerberos SPN. If you don't configure or disable this policy, the generated Kerberos SPN won't include a port in any case.
AllHttpAuthSchemesAllowedForOrigins List of origins that allow all HTTP authentication
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\AllHttpAuthSchemesAllowedForOrigins
- Supported on
- Microsoft Edge version 102, Windows 7 or later
- Template
- msedge.admx
Set this policy to specify which origins allow all the HTTP authentication schemes Microsoft Edge supports regardless of the 'AuthSchemes' (Supported authentication schemes) policy. Format the origin pattern according to this format (https://support.google.com/chrome/a?p=url_blocklist_filter_format). Up to 1,000 exceptions can be defined in 'AllHttpAuthSchemesAllowedForOrigins' (List of origins that allow all HTTP authentication). Wildcards are allowed for the host component (e.g., '*:8000' matches all hosts on port 8000). To match all schemes or all ports, omit the component entirely (e.g., 'example.com' matches any scheme and any port). A hostname (e.g., 'example.com') also matches its subdomains. To match a host exactly and exclude its subdomains, prepend it with a dot (e.g., '.example.com'). To match all origins, use a single asterisk ('*'). Example value: *.example.com
AuthNegotiateDelegateAllowlist Specifies a list of servers that Microsoft Edge can delegate user credentials to
If you don't configure this policy, Microsoft Edge doesn't delegate user credentials even if a server is detected as Intranet.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AuthNegotiateDelegateAllowlist
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Configure the list of servers that Microsoft Edge can delegate to. Separate multiple server names with commas. Wildcards (*) are allowed. If you don't configure this policy, Microsoft Edge doesn't delegate user credentials even if a server is detected as Intranet. Example value: contoso.com
AuthSchemes Supported authentication schemes
If you don't configure this policy, all four schemes are used.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AuthSchemes
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Microsoft Security BaselineAuthSchemes = ntlm,negotiate
Specifies which HTTP authentication schemes are supported. You can configure the policy by using these values: 'basic', 'digest', 'ntlm', and 'negotiate'. Separate multiple values with commas. Note: All values for this policy are case sensitive. If you don't configure this policy, all four schemes are used. Example value: basic,digest,ntlm,negotiate
WindowsHelloForHTTPAuthEnabled Windows Hello For HTTP Auth Enabled
If you enable or don't configure this policy, Microsoft Edge uses Windows Credential UI.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WindowsHelloForHTTPAuthEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 90, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Windows Credential UI is used to respond to NTLM and Negotiate authentication challenges. If you enable or don't configure this policy, Microsoft Edge uses Windows Credential UI. If you disable this policy, Microsoft Edge uses its built-in username and password prompt.
Microsoft Edge / Identity and sign-in
M365AuthPopupsInWorkEnabled Allow M365 authentication popups in work profiles
If you enable this policy or don't configure it, Microsoft 365 authentication pop-ups are allowed in work profiles.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- M365AuthPopupsInWorkEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 148, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Microsoft Edge allows Microsoft 365 authentication pop-ups to bypass the pop-up blocker in work profiles. When users are signed in with a work account, some Microsoft 365 sites (for example, microsoft.com, cloud.microsoft, and visualstudio.com) may open authentication pop-ups to login.microsoftonline.com, login.live.com, or login.microsoft.com. These pop-ups are required to complete sign-in. If you enable this policy or don't configure it, Microsoft 365 authentication pop-ups are allowed in work profiles. If you disable this policy, Microsoft 365 authentication pop-ups follow the default settings like other pop-ups.
AutomaticProfileSwitchingSiteList Configure the automatic profile switching site list
If you don't configure this policy, Microsoft Edge continues using its heuristics to automatically switch sites.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AutomaticProfileSwitchingSiteList
- Supported on
- Microsoft Edge version 120, Windows 7 or later
- Template
- msedge.admx
Sets this policy to control which profiles Microsoft Edge uses to open sites in. Switching configurations for sites listed in this policy takes precedence over other heuristics Microsoft Edge uses for switching sites; however, sites not listed on this policy are still subject to switching by those heuristics. If you don't configure this policy, Microsoft Edge continues using its heuristics to automatically switch sites. This policy maps a URL hostname to a profile that's used to open the site. The 'site' field takes the form of a URL hostname. The 'profile' field can take one of the following values: - 'Work': The most recently used Microsoft Entra signed-in profile is used to open a 'site'. - 'Personal': The most recently used Microsoft Account (MSA) signed-in profile is used to open a 'site'. - 'No preference': The currently used profile is used to open a 'site'. - 'Wildcard email address': This takes the form of '*@contoso.com'. A profile whose username ends with the contents following the '*' is used to open a 'site'. Example value: [ { "site": "work.com", "profile": "Work" }, { "site": "personal.com", "profile": "Personal" }, { "site": "nopreference.com", "profile": "No preference" }, { "site": "contoso.com", "profile": "*@contoso.com" } ]
EdgeDefaultProfileEnabled Default Profile Setting Enabled
If you enable this policy, but don't configure or disable it, the policy will behave like it's never been set before.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeDefaultProfileEnabled
- Supported on
- Microsoft Edge version 101, Windows 7 or later
- Template
- msedge.admx
Configuring this policy lets you set a default profile in Microsoft Edge to be used when opening the browser rather than the last profile used. This policy doesn't affect when "--profile-directory" parameter is specified. Set the value to "Default" to refer to the default profile. The value is case sensitive. The value of the policy is the name of the profile (case sensitive) and can be configured with string that is the name of a specific profile. The value "Edge Kids Mode" and "Guest Profile" are considered not useful values because they not supposed to be a default profile. This policy doesn't impact the following scenarios: 1) Settings specified in "Profile preferences for sites" in "Profile preferences" 2) Links opening from Outlook and Teams. The following statements are under the condition of not specify the "--profile-directory" and configured value isn't "Edge Kids Mode" or "Guest Profile": If you enable this policy and configure it with a specific profile name and the specified profile can be found, Microsoft Edge will use the specified profile when launching and the setting of "Default profile for external link" is changed to the specified profile name and greyed out. If you enable this policy and configure it with a specific profile name but it can't be found, the policy will behave like it's never been set before. If you enable this policy, but don't configure or disable it, the policy will behave like it's never been set before. Example value: Default
EditProfileEnabled Enable editing profile in settings
If you enable or don't configure this policy, users can edit profile properties.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EditProfileEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 145, Windows 7 or later
- Template
- msedge.admx
This policy controls whether users can modify profile properties (such as profile avatar) from the profile settings page. If you enable or don't configure this policy, users can edit profile properties. The edit button is available on the profile settings page. If you disable this policy, users can't edit profile properties. The edit button is disabled on the profile settings page.
ImplicitSignInEnabled Enable implicit sign-in
If you enable or don't configure this setting, implicit sign-in is enabled, Microsoft Edge attempts to sign in the user into their profile based on what and how they sign in to their OS.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ImplicitSignInEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
Configure this policy to allow/disallow implicit sign-in. If you have configured the 'BrowserSignin' (Browser sign-in settings) policy to 'Disable browser sign-in', this policy doesn't take any effect. If you enable or don't configure this setting, implicit sign-in is enabled, Microsoft Edge attempts to sign in the user into their profile based on what and how they sign in to their OS. If you disable this setting, implicit sign-in is disabled.
ProactiveAuthWorkflowEnabled Enable proactive authentication
If you enable or don't configure this policy, Microsoft Edge authentication requests are automatically sent to the services using the account that is signed-in to the browser.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ProactiveAuthWorkflowEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 126, Windows 7 or later
- Template
- msedge.admx
This policy controls the proactive authentication in Microsoft Edge, that connects the signed-in user identity with Microsoft Bing, MSN and Copilot services for a smooth and consistent sign-in experience. If you enable or don't configure this policy, Microsoft Edge authentication requests are automatically sent to the services using the account that is signed-in to the browser. If you disable this policy, Microsoft Edge doesn't send authentications requests to these services, and users need to manually sign-in.
NonMicrosoftAccountSignInEnabled Enable sign-in to Microsoft Edge using non-Microsoft accounts
If you enable this policy or don't configure it, users can sign in to Microsoft Edge with non-Microsoft accounts when the feature is available.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NonMicrosoftAccountSignInEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 150, Windows 7 or later
- Template
- msedge.admx
This policy controls whether users can sign in to Microsoft Edge using non-Microsoft accounts, such as Google or Apple accounts. If you enable this policy or don't configure it, users can sign in to Microsoft Edge with non-Microsoft accounts when the feature is available. Related sign-in entry points, such as Google or Apple sign-in buttons in the profile flyout and unified sign-in experience, are shown when available. If you disable this policy, users can't sign in to Microsoft Edge with non-Microsoft accounts. Related sign-in entry points and code paths are hidden and disabled, regardless of related feature flag settings. Users can still sign in with Microsoft accounts.
LinkedAccountEnabled Enable the linked account feature (obsolete)
If you enable or don't configure this policy, linked account information is shown on a flyout.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- LinkedAccountEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 107-133, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 133. This policy is obsolete because Microsoft Edge no longer supports the linked account feature. Microsoft Edge guides a user to the account management page where they can link a Microsoft Account (MSA) to an Azure Active Directory (Azure AD) account. If you enable or don't configure this policy, linked account information is shown on a flyout. When the Azure AD profile doesn't have a linked account, it shows "Add account". If you disable this policy, linked accounts are turned off and no extra information is shown.
GuidedSwitchEnabled Guided Switch Enabled
If this policy isn't configured, guided switch is turned on by default.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- GuidedSwitchEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 103, Windows 7 or later
- Template
- msedge.admx
Allows Microsoft Edge to prompt the user to switch to the appropriate profile when Microsoft Edge detects that a link is a personal or work link. If you enable this policy, you're prompted to switch to another account if the current profile doesn't work for the requesting link. If you disable this policy, you aren't prompted to switch to another account when there's a profile and link mismatch. If this policy isn't configured, guided switch is turned on by default. A user can override this value in the browser settings.
OneAuthAuthenticationEnforced OneAuth Authentication Flow Enforced for signin
If you disable or don't configure this policy, sign-in process uses Windows Account Manager.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- OneAuthAuthenticationEnforced
- Enabled / Disabled
- 1 / 0
- Stated default
- On Windows 10 earlier to RS3, OneAuth is used for authentication in Microsoft Edge by default.
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
This policy allows users to decide whether to use the OneAuth library for sign-in and token fetch in Microsoft Edge on Windows 10 RS3 and later. If you disable or don't configure this policy, sign-in process uses Windows Account Manager. Microsoft Edge would be able to use accounts you signed in to Windows, Microsoft Office, or other Microsoft applications for sign in, without the need for a password. Or, you can provide valid account and password to sign in, which are stored in Windows Account Manager for future usage. You can investigate all accounts stored in Windows Account Manager through Windows Settings -> Accounts -> Email and accounts page. If you enable this policy, OneAuth authentication flow is used for account sign in. The OneAuth authentication flow has fewer dependencies and works without Windows shell. The account you use isn't stored in the Email and accounts page. This policy only takes effect on Windows 10 RS3 and later. On Windows 10 earlier to RS3, OneAuth is used for authentication in Microsoft Edge by default.
OnlyOnPremisesImplicitSigninEnabled Only on-premises account enabled for implicit sign-in
If you disable or don't configure this policy, all accounts are enabled for implicit sign in.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- OnlyOnPremisesImplicitSigninEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 94, Windows 7 or later
- Template
- msedge.admx
Configures this policy to decide whether only on-premises accounts are enabled for implicit sign in. If you enable this policy, only on-premises accounts are enabled for implicit sign in. Microsoft Edge doesn't attempt to implicitly sign in to Microsoft Services account (MSA) or Azure Active Directory (AAD) accounts. Upgrade from on-premises accounts to AAD accounts are also stopped. If you disable or don't configure this policy, all accounts are enabled for implicit sign in. This policy only takes effect when policy 'ConfigureOnPremisesAccountAutoSignIn' (Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account) is enabled and is set to 'SignInAndMakeDomainAccountNonRemovable'.
EdgeOpenExternalLinksWithAppSpecifiedProfile Prioritize App specified profile to open external links
Enabled or not configured: The app-specified profile is prioritized for opening external links.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeOpenExternalLinksWithAppSpecifiedProfile
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 139, Windows 7 or later
- Template
- msedge.admx
This policy controls whether the profile specified by an app (such as Microsoft Teams or Outlook) is given priority when opening external links, instead of the profile selected in the Default profile for external links setting. Policy behavior: 1. Enabled or not configured: The app-specified profile is prioritized for opening external links. This behavior overrides the profile selected in settings, and the behavior defined by the EdgeDefaultProfileEnabled and EdgeOpenExternalLinksWithPrimaryWorkProfileEnabled policies. If the app doesn't specify a profile, this policy has no effect. 2. Disabled: The profile selected in settings—along with the EdgeDefaultProfileEnabled and EdgeOpenExternalLinksWithPrimaryWorkProfileEnabled policies—is used to determine which profile opens external links. NOTE: This policy doesn't override user-defined preferences set through Automatic profile switching, including the Custom site switch setting located within it. If a user configured specific sites to open in designated profiles, those preferences take precedence.
SeamlessWebToBrowserSignInEnabled Seamless Web To Browser Sign-in Enabled
If this policy isn't configured, users can turn on/off Seamless Web to Browser Sign-in feature from settings by themselves.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SeamlessWebToBrowserSignInEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 133, Windows 7 or later
- Template
- msedge.admx
This policy only takes effect when the 'WebToBrowserSignInEnabled' (Web To Browser Sign-in Enabled) is enabled. If this policy is enabled, users can't turn off Seamless Web to Browser Sign-in feature from "Automatic sign in on Microsoft Edge" setting on Microsoft Edge profile settings page and that toggle will be greyed out. If this policy is disabled, users can't turn on Seamless Web to Browser Sign-in feature from "Automatic sign in on Microsoft Edge" setting on Microsoft Edge profile settings page and that toggle will be greyed out. If this policy isn't configured, users can turn on/off Seamless Web to Browser Sign-in feature from settings by themselves.
SwitchIntranetSitesToWorkProfile Switch intranet sites to a work or school profile
If you enable or don't configure this policy, navigations to intranet URLs switch to the most recently used work or school profile, if one exists.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SwitchIntranetSitesToWorkProfile
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 119, Windows 7 or later
- Template
- msedge.admx
Allows Microsoft Edge to switch to the appropriate profile when Microsoft Edge detects that a URL is the intranet. If you enable or don't configure this policy, navigations to intranet URLs switch to the most recently used work or school profile, if one exists. If you disable this policy, navigations to intranet URLs remain in the current browser profile.
SwitchSitesOnIEModeSiteListToWorkProfile Switch sites on the IE mode site list to a work or school profile
If you enable or don't configure this policy, navigations to URLs matching a site on the IE mode site list switch to the most recently used work or school profile if one exists.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SwitchSitesOnIEModeSiteListToWorkProfile
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 119, Windows 7 or later
- Template
- msedge.admx
Allows Microsoft Edge to switch to the appropriate profile when navigating to a site that matches an entry on the IE mode site list. Only sites that specify IE mode or Edge mode are switched to the work or school profile. If you enable or don't configure this policy, navigations to URLs matching a site on the IE mode site list switch to the most recently used work or school profile if one exists. If you disable this policy, navigations to URLs matching a site on the IE mode site list remain in the current browser profile.
WAMAuthBelowWin10RS3Enabled WAM for authentication below Windows 10 RS3 enabled
If you disable or don't configure this setting, OneAuth libraries are used instead of WAM on Windows 10 RS1 and RS2.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WAMAuthBelowWin10RS3Enabled
- Enabled / Disabled
- 1 / 0
- Stated default
- If this policy is enabled, then previous sign-in sessions (which used OneAuth by default) can't be used. On Windows 10 RS3 and above, WAM is used for authentication in Microsoft Edge by default.
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
Configure this policy to decide whether WAM is used for authentication in Microsoft Edge on Windows 10 RS1 and RS2. If you enable this setting, WAM is used in the authentication flow on Windows 10 RS1 and RS2. If you disable or don't configure this setting, OneAuth libraries are used instead of WAM on Windows 10 RS1 and RS2. If this policy is enabled, then previous sign-in sessions (which used OneAuth by default) can't be used. Sign out of those profiles. This policy will only take effect on Windows 10 RS1 and RS2. On Windows 10 RS3 and above, WAM is used for authentication in Microsoft Edge by default.
WebToBrowserSignInEnabled Web To Browser Sign-in Enabled
If this policy is enabled or not configured, users can get sign in CTA or seamless sign in experience(if 'SeamlessWebToBrowserSignInEnabled' (Seamless Web To Browser Sign-in Enabled) is enabled) when user sign in on Microsoft website.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebToBrowserSignInEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 133, Windows 7 or later
- Template
- msedge.admx
Allow user to sign in to the same account in Microsoft Edge when a user signs in to a Microsoft website. If this policy is enabled or not configured, users can get sign in CTA or seamless sign in experience(if 'SeamlessWebToBrowserSignInEnabled' (Seamless Web To Browser Sign-in Enabled) is enabled) when user sign in on Microsoft website. If this policy is disabled, user won't get sign in CTA or seamless sign in experience when user sign in on Microsoft website.
Microsoft Edge / Idle Browser Actions
IdleTimeoutActions Actions to run when the computer is idle
If you don't configure the IdleTimeout policy, this policy has no effect. If you don't configure this policy or no actions are selected, the IdleTimeout policy has no effect.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\IdleTimeoutActions
- Supported on
- Microsoft Edge version 134, Windows 7 or later
- Template
- msedge.admx
When the timeout from the IdleTimeout policy is reached, the browser runs the actions configured in this policy. If you don't configure the IdleTimeout policy, this policy has no effect. If you don't configure this policy or no actions are selected, the IdleTimeout policy has no effect. Supported actions are: 'close_browsers': close all browser windows and Progressive Web Apps (PWAs) for this profile. 'reload_pages': reload all webpages. For some pages, the user might be prompted for confirmation first. 'sign_out': sign out of browser. (This action only applies to iOS.) 'close_tabs': close all open tabs and create an NTP (New Tab Page). Supported in Android and iOS. 'clear_browsing_history', 'clear_download_history', 'clear_cookies_and_other_site_data', 'clear_cached_images_and_files', 'clear_password_signing', 'clear_autofill', 'clear_site_settings': clear the corresponding browsing data. Deleting cookies using this policy doesn't sign the user out of their profile, the user stays signed in. Setting 'clear_browsing_history', 'clear_password_signing', 'clear_autofill', and 'clear_site_settings' disables sync for the respective data types if sync isn't already disabled by setting either the SyncDisabled policy or BrowserSignin to disabled. Policy options mapping: * close_browsers (close_browsers) = Close Browsers * clear_browsing_history (clear_browsing_history) = Clear Browsing History * clear_download_history (clear_download_history) = Clear Download History * clear_cookies_and_other_site_data (clear_cookies_and_other_site_data) = Clear Cookies and Other Site Data * clear_cached_images_and_files (clear_cached_images_and_files) = Clear Cached Images and Files * clear_password_signin (clear_password_signin) = Clear Password sign in * clear_autofill (clear_autofill) = Clear Autofill * clear_site_settings (clear_site_settings) = Clear Site Settings * reload_pages (reload_pages) = Reload Pages * sign_out (sign_out) = Sign Out * close_tabs (close_tabs) = Close Tabs Use the preceding information when configuring this policy. Example value: close_browsers
IdleTimeout Delay before running idle actions
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- IdleTimeout
- Supported on
- Microsoft Edge version 134, Windows 7 or later
- Template
- msedge.admx
Triggers an action when the computer is idle. If you set this policy, it specifies the length of time without user input (in minutes) before the browser runs actions configured via the IdleTimeoutActions policy. If you don't set this policy, the browser doesn't run any action. The minimum threshold is 1 minute. "User input" is defined by Operating System APIs, and includes things like moving the mouse or typing on the keyboard.
Microsoft Edge / Immersive Reader settings
ImmersiveReaderGrammarToolsEnabled Enable Grammar Tools feature within Immersive Reader in Microsoft Edge (obsolete)
If you enable this policy or don't configure it, the Grammar Tools option shows up within Immersive Reader.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ImmersiveReaderGrammarToolsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 110-125, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 125. This policy is obsoleted because Grammar Tools is deprecated from Microsoft Edge. This policy can't work in Microsoft Edge version 126. Enables the Grammar Tools feature within Immersive Reader in Microsoft Edge. This helps improve reading comprehension by splitting words into syllables and highlighting nouns, verbs, adverbs, and adjectives. If you enable this policy or don't configure it, the Grammar Tools option shows up within Immersive Reader. If you disable this policy, users can't access the Grammar Tools feature within Immersive Reader.
ImmersiveReaderPictureDictionaryEnabled Enable Picture Dictionary feature within Immersive Reader in Microsoft Edge (obsolete)
If you enable this policy or don't configure it, the Picture Dictionary option shows up within Immersive Reader.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ImmersiveReaderPictureDictionaryEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 110-126, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 126. This Policy is obsoleted because Picture Dictionary is deprecated from Edge as of Sept, 2023. This policy won't work in Microsoft Edge Version 127. Enables the Picture Dictionary feature within Immersive Reader in Microsoft Edge. This feature helps in reading comprehension by letting a user to click on any single word and see an illustration related to the meaning. If you enable this policy or don't configure it, the Picture Dictionary option shows up within Immersive Reader. If you disable this policy, users can't access the Picture Dictionary feature within Immersive Reader.
Microsoft Edge / Kiosk Mode settings
KioskAddressBarEditingEnabled Configure address bar editing for kiosk mode public browsing experience
If you enable or don't configure this policy, users can change the URL in the address bar.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- KioskAddressBarEditingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 87, Windows 7 or later
- Template
- msedge.admx
This policy only applies to Microsoft Edge kiosk mode while using the public browsing experience. If you enable or don't configure this policy, users can change the URL in the address bar. If you disable this policy, it prevents users from changing the URL in the address bar. For detailed information on configuring kiosk Mode, see https://go.microsoft.com/fwlink/?linkid=2137578.
KioskDeleteDownloadsOnExit Delete files downloaded as part of kiosk session when Microsoft Edge closes
If you disable this policy or don't configure it, files downloaded as part of the kiosk session aren't deleted when Microsoft Edge closes.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- KioskDeleteDownloadsOnExit
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 87, Windows 7 or later
- Template
- msedge.admx
This policy only applies to Microsoft Edge kiosk mode. If you enable this policy, files downloaded as part of the kiosk session are deleted each time Microsoft Edge closes. If you disable this policy or don't configure it, files downloaded as part of the kiosk session aren't deleted when Microsoft Edge closes. For detailed information on configuring kiosk Mode, see https://go.microsoft.com/fwlink/?linkid=2137578.
KioskSwipeGesturesEnabled Swipe gestures in Microsoft Edge kiosk mode enabled
If you enable this policy or don't configure it, swipe gestures behave as expected.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- KioskSwipeGesturesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 101, Windows 7 or later
- Template
- msedge.admx
This policy only applies to Microsoft Edge kiosk mode. If you enable this policy or don't configure it, swipe gestures behave as expected. If you disable this policy, the user won't be able to use swipe gestures (for example, navigate forwards and backwards, refresh page). For detailed information on configuring kiosk mode, see https://go.microsoft.com/fwlink/?linkid=2137578.
Microsoft Edge / Manageability
EdgeManagementUserPolicyOverridesCloudMachinePolicy Allow cloud-based Microsoft Edge management service user policies to override local user policies.
If you disable or don't configure this policy, Microsoft Edge management service user policies take precedence.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeManagementUserPolicyOverridesCloudMachinePolicy
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 119, Windows 7 or later
- Template
- msedge.admx
If you enable this policy, cloud-based Microsoft Edge management service user policies take precedence if it conflicts with local user policy. If you disable or don't configure this policy, Microsoft Edge management service user policies take precedence. The policy can be combined with 'EdgeManagementPolicyOverridesPlatformPolicy' (Microsoft Edge management service policy overrides platform policy.). If both policies are enabled, all cloud-based Microsoft Edge management service policies take precedence over conflicting local service policies.
MAMWithDeviceDLPEnabled Allow MAM enrollment when managed device has Purview DLP policy configured
If you disable or don't configure this policy, MAM enrollment is blocked when Purview DLP is detected on the device.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- MAMWithDeviceDLPEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 147, Windows 7 or later
- Template
- msedge.admx
Controls whether Microsoft Edge allows Mobile Application Management (MAM) enrollment on managed devices when Microsoft Purview Data Loss Prevention (DLP) is configured. If you enable this policy, MAM enrollment is allowed even when Purview DLP is detected on the device. If you disable or don't configure this policy, MAM enrollment is blocked when Purview DLP is detected on the device.
EdgeManagementEnabled Microsoft Edge management enabled
If you enable or don't configure this policy, Microsoft Edge attempts to connect to the Microsoft Edge management service to download and apply policy assigned to the Azure AD account of the user.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeManagementEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 115, Windows 7 or later
- Template
- msedge.admx
Microsoft Edge management service in Microsoft 365 Admin Center lets you set policy and manage users through a Microsoft Edge focused cloud-based management experience. This policy lets you control whether Microsoft Edge management is enabled. If you enable or don't configure this policy, Microsoft Edge attempts to connect to the Microsoft Edge management service to download and apply policy assigned to the Azure AD account of the user. If you disable this policy, Microsoft Edge won't attempt to connect to the Microsoft Edge management service.
EdgeManagementEnrollmentToken Microsoft Edge management enrollment token
If you disable or don't configure this policy, Microsoft Edge doesn't attempt to connect to the Microsoft Edge management service.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeManagementEnrollmentToken
- Supported on
- Microsoft Edge version 115, Windows 7 or later
- Template
- msedge.admx
Microsoft Edge management service in Microsoft 365 Admin Center lets you set policy and manage users through a Microsoft Edge focused cloud-based management experience. This policy lets you specify an enrollment token that's used to register with Microsoft Edge management service and deploy the associated policies. The user must be signed in to Microsoft Edge with a valid work or school account; otherwise, Microsoft Edge doesn't download the policy. If you enable this policy, Microsoft Edge attempts to use the specified enrollment token to register with the Microsoft Edge management service and download the published policy. If you disable or don't configure this policy, Microsoft Edge doesn't attempt to connect to the Microsoft Edge management service. This policy can only be set as a platform policy. Example value: RgAAAACBbzoQDmUrRfq3WeKUoFeEBwBOqK2QPYsBT5V3lQFoKND-AAAAAAEVAAAOqK2QPYvBT5V4lQFoKMD-AAADTXvzAAAA0
EdgeManagementExtensionsFeedbackEnabled Microsoft Edge management extensions feedback enabled
If you disable or don't configure this policy, Microsoft Edge can't send any data to the Microsoft Edge service about blocked extensions.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeManagementExtensionsFeedbackEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 115, Windows 7 or later
- Template
- msedge.admx
This setting controls whether Microsoft Edge sends data about blocked extensions to the Microsoft Edge management service. The 'EdgeManagementEnabled' policy must also be enabled for this setting to take effect. If you enable this policy, Microsoft Edge sends data to the Microsoft Edge service when a user tries to install a blocked extension. If you disable or don't configure this policy, Microsoft Edge can't send any data to the Microsoft Edge service about blocked extensions.
EdgeManagementPolicyOverridesPlatformPolicy Microsoft Edge management service policy overrides platform policy.
If you disable or don't configure this policy, platform policy takes precedence if it conflicts with the cloud-based Microsoft Edge management service policy.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EdgeManagementPolicyOverridesPlatformPolicy
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 119, Windows 7 or later
- Template
- msedge.admx
If you enable this policy, the cloud-based Microsoft Edge management service policy takes precedence if it conflicts with platform policy. If you disable or don't configure this policy, platform policy takes precedence if it conflicts with the cloud-based Microsoft Edge management service policy. This mandatory policy affects machine scope cloud-based Microsoft Edge management policies. Machine policies apply to all edge browser instances regardless of the user who is logged in.
MAMEnabled Mobile App Management Enabled
If you enable this policy or don't configure it, Mobile App Management (MAM) Policies can be applied.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- MAMEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 89, Windows 7 or later
- Template
- msedge.admx
Allows the Microsoft Edge browser to retrieve policies from the Intune application management services and apply them to users' profiles. If you enable this policy or don't configure it, Mobile App Management (MAM) Policies can be applied. If you disable this policy, Microsoft Edge can't communicate with Intune to request MAM Policies.
Microsoft Edge / Native Messaging
NativeMessagingUserLevelHosts Allow user-level native messaging hosts (installed without admin permissions)
If you set this policy to Enabled or leave it unset, Microsoft Edge can use native messaging hosts installed at the user level.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NativeMessagingUserLevelHosts
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Microsoft Security BaselineNativeMessagingUserLevelHosts = 0
If you set this policy to Enabled or leave it unset, Microsoft Edge can use native messaging hosts installed at the user level. If you set this policy to Disabled, Microsoft Edge can only use these hosts if they're installed at the system level.
NativeMessagingBlocklist Configure native messaging block list
If you leave this policy unset, Microsoft Edge loads all installed native messaging hosts.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\NativeMessagingBlocklist
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Setting this policy specifies which native messaging hosts shouldn't be loaded. A deny list value of * means all native messaging hosts are denied unless they're explicitly allowed. If you leave this policy unset, Microsoft Edge loads all installed native messaging hosts. Example value: com.native.messaging.host.name1 com.native.messaging.host.name2
NativeMessagingAllowlist Control which native messaging hosts users can use
All native messaging hosts are allowed by default.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\NativeMessagingAllowlist
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Setting the policy specifies which native messaging hosts aren't subject to the deny list. A deny list value of * means all native messaging hosts are denied unless they're explicitly allowed. All native messaging hosts are allowed by default. However, if a native messaging host is denied by policy, the admin can use the allow list to change that policy. Example value: com.native.messaging.host.name1 com.native.messaging.host.name2
Microsoft Edge / Network settings
LocalNetworkAccessPermissionsPolicyDefaultEnabled Allow Local Network Access (LNA) requests in subframes without explicit delegation
If you disable or don't configure this policy, subframes must be explicitly delegated the Permissions Policy feature to make local network requests and trigger the permission prompt.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- LocalNetworkAccessPermissionsPolicyDefaultEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, Local Network Access permissions can be requested in cross-origin subframes only if they are explicitly delegated. If you enable this policy, subframes inherit all LNA Permissions Policy features by default and can make local network requests, which trigger the permission prompt.
- Supported on
- Microsoft Edge version 146, Windows 7 or later
- Template
- msedge.admx
Controls whether Local Network Access (LNA) permissions are inherited by cross-origin subframes. By default, Local Network Access permissions can be requested in cross-origin subframes only if they are explicitly delegated. If you enable this policy, subframes inherit all LNA Permissions Policy features by default and can make local network requests, which trigger the permission prompt. If you disable or don't configure this policy, subframes must be explicitly delegated the Permissions Policy feature to make local network requests and trigger the permission prompt. This policy applies to the Permissions Policy features "local-network-access", "loopback-network", and "local-network". For more information about Local Network Access, see https://learn.microsoft.com/deployedge/ms-edge-local-network-access.
LocalNetworkAccessAllowedForUrls Allow sites to make network requests to local devices and local network endpoints.
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\LocalNetworkAccessAllowedForUrls
- Supported on
- Microsoft Edge version 140, Windows 7 or later
- Template
- msedge.admx
Specifies a list of URL patterns for which requests initiated from matching origins are exempt from Local Network Access restrictions. Network requests initiated from websites served by matching origins are not subject to Local Network Access checks. For origins not covered by the patterns specified here, the user's personal configuration and applicable local network access restrictions apply. There are multiple policies that control origins impacting requests to local device and local network endpoints. If an origin matches more than one of the following policies, the policies take precedence in the following order: - LocalNetworkBlockedForUrls - LocalNetworkAllowedForUrls - LoopbackNetworkAccessBlockedForUrls - LoopbackNetworkAccessAllowedForUrls - LocalNetworkAccessBlockedForUrls - LocalNetworkAccessAllowedForUrls For detailed information about valid URL pattern syntax, see: https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns For more information about Local Network Access, see: https://wicg.github.io/local-network-access/ Note: This policy enables controlled exceptions to local network access restrictions. It allows specified public websites to access private IP addresses when required for trusted local communication scenarios. Example value: http://www.example.com:8080 [*.]example.edu *
LocalNetworkAllowedForUrls Allow sites to make network requests to local network endpoints.
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\LocalNetworkAllowedForUrls
- Supported on
- Microsoft Edge version 146, Windows 7 or later
- Template
- msedge.admx
Controls which website origins are exempt from Local Network Access checks when accessing local network endpoints. Network requests initiated from websites that match the specified URL patterns are not subject to Local Network Access checks. For origins not covered by the patterns specified in this policy, the user's personal configuration applies. For detailed information about valid URL patterns, see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns. For more information about Local Network Access restrictions, see https://wicg.github.io/local-network-access/. Multiple policies can list origins that affect requests to local network endpoints. If an origin matches more than one of the following policies, they take precedence in the following order: - LocalNetworkBlockedForUrls - LocalNetworkAllowedForUrls - LoopbackNetworkBlockedForUrls - LoopbackNetworkAllowedForUrls - LocalNetworkAccessBlockedForUrls - LocalNetworkAccessAllowedForUrls This policy controls access to local network endpoints (private IP addresses) and can be used to allow specific websites to access local network resources. Example value: http://www.example.com:8080 [*.]example.edu *
LoopbackNetworkAllowedForUrls Allow sites to make network requests to the local device.
If this policy is disabled or not configured, no additional exemptions are granted beyond the user's existing configuration.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\LoopbackNetworkAllowedForUrls
- Supported on
- Microsoft Edge version 146, Windows 7 or later
- Template
- msedge.admx
Specifies a list of URL patterns for which requests initiated from matching origins are exempt from Local Network Access restrictions when accessing loopback addresses (127.0.0.1, ::1, localhost). If a requesting origin matches a URL pattern specified in this policy, requests to loopback addresses are allowed and are not subject to Local Network Access restrictions. For origins not covered by this policy, the user's personal settings and local network access restrictions apply. If this policy is disabled or not configured, no additional exemptions are granted beyond the user's existing configuration. Multiple policies can specify origins that affect requests to the local device. If an origin matches more than one of the following policies, they are applied in the following order of precedence: - LoopbackNetworkBlockedForUrls - LoopbackNetworkAllowedForUrls - LocalNetworkAccessBlockedForUrls - LocalNetworkAccessAllowedForUrls For guidance on valid URL pattern syntax, see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns . Example value: http://www.example.com:8080 [*.]example.edu *
LocalNetworkAccessBlockedForUrls Block sites from making network requests to local devices and local network endpoints.
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\LocalNetworkAccessBlockedForUrls
- Supported on
- Microsoft Edge version 140, Windows 7 or later
- Template
- msedge.admx
Specifies a list of URL patterns for which requests initiated from matching origins are blocked from issuing Local Network Access requests. Network requests initiated from websites served by matching origins are prevented from accessing local device and local network endpoints. For origins not covered by the patterns specified here, the user's personal configuration applies. There are multiple policies that control origins impacting requests to local device and local network endpoints. If an origin matches more than one of the following policies, the policies take precedence in the following order: - LocalNetworkBlockedForUrls - LocalNetworkAllowedForUrls - LoopbackNetworkAccessBlockedForUrls - LoopbackNetworkAccessAllowedForUrls - LocalNetworkAccessBlockedForUrls - LocalNetworkAccessAllowedForUrls For detailed information about valid URL pattern syntax, see: https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns For more information about Local Network Access, see: https://wicg.github.io/local-network-access/ Note: This policy blocks specified public websites from accessing private IP addresses. It helps reduce exposure of internal network resources unless access is explicitly permitted by policy. Example value: http://www.example.com:8080 [*.]example.edu *
LocalNetworkBlockedForUrls Block sites from making network requests to local network endpoints.
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\LocalNetworkBlockedForUrls
- Supported on
- Microsoft Edge version 146, Windows 7 or later
- Template
- msedge.admx
Controls which website origins are blocked from making Local Network Access requests to local network endpoints. Network requests initiated from websites that match the specified URL patterns are blocked from issuing Local Network Access requests. For origins not covered by the patterns specified in this policy, the user's personal configuration applies. For detailed information about valid URL patterns, see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns. For more information about Local Network Access restrictions, see https://wicg.github.io/local-network-access/. Multiple policies can list origins that affect requests to local network endpoints. If an origin matches more than one of the following policies, they take precedence in the following order: - LocalNetworkBlockedForUrls - LocalNetworkAllowedForUrls - LoopbackNetworkBlockedForUrls - LoopbackNetworkAllowedForUrls - LocalNetworkAccessBlockedForUrls - LocalNetworkAccessAllowedForUrls This policy controls access to local network endpoints (private IP addresses) and can be used to block specific websites from accessing local network resources. Example value: http://www.example.com:8080 [*.]example.edu *
LoopbackNetworkBlockedForUrls Block sites from making network requests to the local device.
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\LoopbackNetworkBlockedForUrls
- Supported on
- Microsoft Edge version 146, Windows 7 or later
- Template
- msedge.admx
Specifies a list of URL patterns for which requests initiated from matching origins to loopback addresses (127.0.0.1, ::1, localhost) are blocked from issuing Local Network Access requests. If a requesting origin matches a URL pattern specified in this policy, requests to loopback addresses are blocked. For origins not covered by this policy, the user's personal settings and local network access restrictions apply. Multiple policies can specify origins that affect requests to the local device. If an origin matches more than one of the following policies, they are applied in the following order of precedence: - LoopbackNetworkBlockedForUrls - LoopbackNetworkAllowedForUrls - LocalNetworkAccessBlockedForUrls - LocalNetworkAccessAllowedForUrls Note: This policy improves local network security by blocking specified public websites from accessing loopback addresses. It helps prevent unauthorized external sites from reaching local services running on the device unless explicitly permitted. For more information about Local Network Access, see https://wicg.github.io/local-network-access/ Example value: http://www.example.com:8080 [*.]example.edu *
BlockTruncatedCookies Block truncated cookies (obsolete)
If you enable or don't configure this policy, the new behavior is enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- BlockTruncatedCookies
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 123-131, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 131. This policy provides a temporary opt-out for changes to how Microsoft Edge handles cookies set via JavaScript that contain certain control characters (NULL, carriage return, and line feed). Previously, the presence of any of these characters in a cookie string would cause it to be truncated but still set. Now, the presence of these characters will cause the whole cookie string to be ignored. If you enable or don't configure this policy, the new behavior is enabled. If you disable this policy, the old behavior is enabled. This policy is obsolete because this policy was originally implemented as a safety measure if there was a breakage, but none have been reported.
DataURLWhitespacePreservationEnabled DataURL Whitespace Preservation for all media types
If this policy is left unset or is set to True, the new behavior is enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DataURLWhitespacePreservationEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 133, Windows 7 or later
- Template
- msedge.admx
This policy provides a temporary opt-out for changes to how Edge handles whitepsace in data URLS. Previously, whitespace would be kept only if the top level media type was text or contained the media type string xml. Now, whitespace is preserved in all data URLs, regardless of media type. If this policy is left unset or is set to True, the new behavior is enabled. When this policy is set to False, the old behavior is enabled.
CompressionDictionaryTransportEnabled Enable compression dictionary transport support
If you enable this policy or don't configure it, Microsoft Edge accepts web contents using the compression dictionary transport feature.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- CompressionDictionaryTransportEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 118, Windows 7 or later
- Template
- msedge.admx
This feature enables the use of dictionary-specific content encodings in the Accept-Encoding request header ("sbr" and "zst-d") when dictionaries are available for use. If you enable this policy or don't configure it, Microsoft Edge accepts web contents using the compression dictionary transport feature. If you disable this policy, Microsoft Edge turns off the compression dictionary transport feature.
IPv6ReachabilityOverrideEnabled Enable IPv6 reachability check override
If you disable or don't configure this policy, the IPv6 reachability check won't be overridden.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- IPv6ReachabilityOverrideEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 132, Windows 7 or later
- Template
- msedge.admx
This policy enables an override of the IPv6 reachability check. When overridden, the system will always query AAAA records when resolving host names. It applies to all users and interfaces on the device. If you enable this policy, the IPv6 reachability check is overridden. If you disable or don't configure this policy, the IPv6 reachability check won't be overridden. The system only queries AAAA records when it's reachable to a global IPv6 host.
ZstdContentEncodingEnabled Enable zstd content encoding support (obsolete)
If this policy is not configured, the default behavior is to enable support for zstd content encoding.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ZstdContentEncodingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 125-137, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 137. This policy controls whether Microsoft Edge supports Zstandard (zstd) content encoding. If this policy is enabled, Microsoft Edge advertises zstd in the Accept-Encoding request header and can decompress responses encoded with zstd. If this policy is disabled, Microsoft Edge doesn't advertise or support zstd content encoding. If this policy is not configured, the default behavior is to enable support for zstd content encoding. NOTE: This policy is obsolete starting with Microsoft Edge version 138 because Microsoft Edge now always supports zstd content encoding.
AccessControlAllowMethodsInCORSPreflightSpecConformant Make Access-Control-Allow-Methods matching in CORS preflight spec conformant
If you enable or don't configure this policy, request methods aren't uppercased, unless matching case-insensitively with DELETE, GET, HEAD, OPTIONS, POST, or PUT.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AccessControlAllowMethodsInCORSPreflightSpecConformant
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 123, Windows 7 or later
- Template
- msedge.admx
This policy controls whether request methods are uppercased when matching with Access-Control-Allow-Methods response headers in CORS preflight. If you disable this policy, request methods are uppercased. This is the behavior on or before Microsoft Edge 108. If you enable or don't configure this policy, request methods aren't uppercased, unless matching case-insensitively with DELETE, GET, HEAD, OPTIONS, POST, or PUT. This would reject fetch(url, {method: 'Foo'}) + "Access-Control-Allow-Methods: FOO" response header, and would accept fetch(url, {method: 'Foo'}) + "Access-Control-Allow-Methods: Foo" response header. Note: request methods "post" and "put" aren't affected, while "patch" is affected. This policy is intended to be temporary and will be removed in the future.
LocalNetworkAccessIpAddressSpaceOverrides Override IP address space mappings
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\LocalNetworkAccessIpAddressSpaceOverrides
- Supported on
- Microsoft Edge version 146, Windows 7 or later
- Template
- msedge.admx
Specifies IP address space overrides for Local Network Access restrictions. This policy allows administrators to treat specific IP address ranges as public (exempt from Local Network Access restrictions) or as local (subject to Local Network Access restrictions). IP address space overrides can be specified using one of the following formats: • [cidr]=[public|local|loopback] where [cidr] is an IP address range in CIDR notation. CIDR overrides apply to all ports. • [ip-address]:[port]=[public|local|loopback] IPv6 addresses must be specified in URL-safe (bracketed) format. For more information about Local Network Access, see https://wicg.github.io/local-network-access/. Example value: 100.64.0.0/10=public [2001:db8::]/32=local 192.168.0.1:8000=public [2001:DB8::8:800:200C:417A]:8080=local
LocalNetworkAccessRestrictionsEnabled Specifies whether to block requests from public websites to devices on a user's local network. (obsolete)
If you disable or don't configure this policy, Microsoft Edge handles these requests using the default behavior, which may include showing warnings in DevTools and allowing the request to proceed depending on the context.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- LocalNetworkAccessRestrictionsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 138-144, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 144. Local Network Access restrictions prevent public websites from making requests to devices on a user's local network without explicit user permission. If you enable this policy, Microsoft Edge blocks any request that would otherwise trigger a DevTools warning due to Local Network Access checks. These requests are denied without prompting the user. If you disable or don't configure this policy, Microsoft Edge handles these requests using the default behavior, which may include showing warnings in DevTools and allowing the request to proceed depending on the context. Note: This feature improves local network security by deprecating direct access to private IP addresses from public websites unless explicitly granted by the user. For more information about Local Network Access, see https://wicg.github.io/local-network-access/. Starting in version 140, Microsoft Edge introduces support for policies that manage Local Network Access behavior on a per-URL basis. You can configure exceptions to allow specific URLs to bypass Local Network Access restrictions. You can also block specific URLs from making Local Network Access requests.
LocalNetworkAccessRestrictionsTemporaryOptOut Specifies whether to opt out of Local Network Access restrictions
If you disable or don't configure this policy, Local Network Access requests follow the default handling behavior.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- LocalNetworkAccessRestrictionsTemporaryOptOut
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 143, Windows 7 or later
- Template
- msedge.admx
This policy allows for opting out of restrictions on requests to local network endpoints. If you enable this policy, Local Network Access requests will only display warnings in Edge DevTools when Local Network Access checks fail. If you disable or don't configure this policy, Local Network Access requests follow the default handling behavior. For more information about Local Network Access restrictions, see Local Network Access. To allow specific URL patterns that should automatically be granted Local Network Access permission, use the LocalNetworkAccessAllowedForUrls policy. Note: This opt-out policy is temporary and will be removed after Microsoft Edge version 152.
HappyEyeballsV3Enabled Use the Happy Eyeballs V3 algorithm for connection attempts
Disabled or not configured: Disables the algorithm.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- HappyEyeballsV3Enabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 137, Windows 7 or later
- Template
- msedge.admx
Controls whether Microsoft Edge uses the Happy Eyeballs V3 algorithm to optimize connection attempts. This algorithm improves reliability and performance in dual-stack (IPv4/IPv6) networks by racing connection attempts across IP versions and HTTP protocols (e.g., HTTP/3 vs. others). For more details, see https://datatracker.ietf.org/doc/draft-pauly-happy-happyeyeballs-v3. Enabled: Uses the algorithm for connection attempts. Disabled or not configured: Disables the algorithm. Note: This policy supports dynamic refresh. Important: This policy is temporary and will be removed in a future version.
Microsoft Edge / Password manager and protection
PasswordMonitorAllowed Allow users to be alerted if their passwords are found to be unsafe
If you don't configure the policy, users can turn this feature on or off.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PasswordMonitorAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 85, Windows 7 or later
- Template
- msedge.admx
Allow Microsoft Edge to monitor user passwords. If you enable this policy, the user gets alerted if any of their passwords stored in Microsoft Edge are found to be unsafe. Microsoft Edge will show an alert and this information will also be available in Settings > Passwords > Password Monitor. If you disable this policy, users aren't asked for permission to enable this feature. Their passwords aren't scanned, and they aren't alerted either. If you don't configure the policy, users can turn this feature on or off. To learn more about how Microsoft Edge finds unsafe passwords see https://go.microsoft.com/fwlink/?linkid=2133833 Additional guidance: This policy can be set as both Recommended and Mandatory, however with an important callout. Mandatory enabled: If the policy is set to Mandatory enabled, the UI in Settings will be disabled but remain in 'On' state, and a briefcase icon will be made visible next to it with this description displayed on hover - "This setting is managed by your organization." Recommended enabled: If the policy is set to Recommended enabled, the UI in Settings will remain in 'Off' state, but a briefcase icon will be made visible next to it with this description displayed on hover - "Your organization recommends a specific value for this setting and you have chosen a different value" Mandatory and Recommended disabled: Both these states will work the normal way, with the usual captions being shown to users.
PasswordGeneratorEnabled Allow users to get a strong password suggestion whenever they are creating an account online
If you enable or don't configure this policy, then Password Generator offers users a strong and unique password suggestion (via a dropdown) on Signup and Change Password pages.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PasswordGeneratorEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
Configures the Password Generator Settings toggle that enables/disables the feature for users. If you enable or don't configure this policy, then Password Generator offers users a strong and unique password suggestion (via a dropdown) on Signup and Change Password pages. If you disable this policy, users no longer see strong password suggestions on Signup or Change Password pages.
PasswordProtectionWarningTrigger Configure password protection warning trigger
If you disable or don't configure this policy, then the warning trigger isn't shown.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PasswordProtectionWarningTrigger
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
0Password protection warning is off1Password protection warning is triggered by password reuseAllows you to control when to trigger password protection warning. Password protection alerts users when they reuse their protected password on potentially suspicious sites. You can use the 'PasswordProtectionLoginURLs' (Configure the list of enterprise login URLs where the password protection service should capture salted hashes of a password) and 'PasswordProtectionChangePasswordURL' (Configure the change password URL) policies to configure which passwords to protect. Exemptions: Passwords for the sites listed in 'PasswordProtectionLoginURLs' and 'PasswordProtectionChangePasswordURL', and for the sites listed in 'SmartScreenAllowListDomains' (Configure the list of domains for which Microsoft Defender SmartScreen won't trigger warnings), don't trigger a password-protection warning. Set to PasswordProtectionWarningOff to not show password protection warnings. Set to PasswordProtectionWarningOnPasswordReuse to show password protection warnings when the users reuse their protected password on a non-allowlisted site. If you disable or don't configure this policy, then the warning trigger isn't shown. Policy options mapping: * PasswordProtectionWarningOff (0) = Password protection warning is off * PasswordProtectionWarningOnPasswordReuse (1) = Password protection warning is triggered by password reuse Use the preceding information when configuring this policy.
PasswordProtectionChangePasswordURL Configure the change password URL
If you disable this policy or don't configure it, then password protection service can't redirect users to a change password URL.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PasswordProtectionChangePasswordURL
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Configures the change password URL (HTTP and HTTPS schemes only). Password protection service will send users to this URL to change their password after seeing a warning in the browser. If you enable this policy, then password protection service sends users to this URL to change their password. If you disable this policy or don't configure it, then password protection service can't redirect users to a change password URL. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX. Example value: https://contoso.com/change_password.html
PasswordManagerBlocklist Configure the list of domains for which the password manager UI (Save and Fill) will be disabled
If you disable or don't configure this policy, password manager works as usual for all domains.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\PasswordManagerBlocklist
- Supported on
- Microsoft Edge version 99, Windows 7 or later
- Template
- msedge.admx
Configure the list of domains where Microsoft Edge should disable the password manager. This means that Save and Fill workflows are disabled, ensuring that passwords for those websites can't be saved or auto filled into web forms. If you enable this policy, the password manager is disabled for the specified set of domains. If you disable or don't configure this policy, password manager works as usual for all domains. If you configure this policy, that is, add domains for which password manager is blocked, users can't change or override the behavior in Microsoft Edge. In addition, users can't use password manager for those URLs. Example value: https://contoso.com/ https://login.contoso.com
PasswordProtectionLoginURLs Configure the list of enterprise login URLs where the password protection service should capture salted hashes of a password
If you disable this policy or don't configure it, no password fingerprints are captured.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\PasswordProtectionLoginURLs
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Configure the list of enterprise login URLs (HTTP and HTTPS schemes only) where Microsoft Edge should capture the salted hashes of passwords and use it for password reuse detection. If you enable this policy, the password protection service captures fingerprints of passwords on the defined URLs. If you disable this policy or don't configure it, no password fingerprints are captured. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX. Example value: https://contoso.com/login.html https://login.contoso.com
PrimaryPasswordSetting Configures a setting that asks users to enter their device password while using password autofill
If you set this policy to 'Automatically', disable this policy, or don't configure this policy, autofill won't have any authentication flow.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PrimaryPasswordSetting
- Stated default
- The frequency for authentication prompt is set to 'Ask permission once per browsing session' by default.
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
0Automatically1With device password2With custom primary password3Autofill offThis feature helps users add an additional layer of privacy to their online accounts by requiring device authentication (as a way of confirming the user's identity) before the saved password is autofilled into a web form. This layer ensures that non-authorized persons can't use saved passwords for autofill. This feature doesn't protect against locally running malware. This group policy configures the radio button selector that enables this feature for users. It also has a frequency control where users can specify how often they would like to be prompted for authentication. If you set this policy to 'Automatically', disable this policy, or don't configure this policy, autofill won't have any authentication flow. If you set this policy to 'WithDevicePassword', users have to enter their device password (or preferred mode of authentication under Windows) to prove their identity before their password is autofilled. Authentication modes include Windows Hello, PIN, face recognition, or fingerprint. The frequency for authentication prompt is set to 'Ask permission once per browsing session' by default. However, users can change it to the other option, which is 'Always ask permission'. If you set this policy to 'WithCustomPrimaryPassword', users are asked to create their custom password and to be redirected to Settings. After the custom password is set, users can authenticate themselves using the custom password and their passwords get autofilled after successful authentication. The frequency for authentication prompt is set to 'Ask permission once per browsing session' by default. However, users can change it to the other option, which is 'Always ask permission'. If you set this policy to 'AutofillOff', saved passwords are no longer suggested for autofill. The Custom Primary Password feature will be removed with Edge 149. From this version onward, the Custom Primary Password option will no longer be available. Users who currently have this setting enabled will be automatically migrated to the "Prompt for the device sign-in options" authentication method. Any associated group policies for Custom Primary Password will also be marked as obsolete. Policy options mapping: * Automatically (0) = Automatically * WithDevicePassword (1) = With device password * WithCustomPrimaryPassword (2) = With custom primary password * AutofillOff (3) = Autofill off Use the preceding information when configuring this policy.
DeletingUndecryptablePasswordsEnabled Enable deleting undecryptable passwords
Enabling this policy or leaving it unset means that users with undecryptable passwords saved to the built-in password manager will lose them.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DeletingUndecryptablePasswordsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 132, Windows 7 or later
- Template
- msedge.admx
This policy controls whether the built-in password manager can delete undecryptable passwords from its database. This is required to restore the full functionality of the built-in password manager, but it may include a permanent data loss. Undecryptable password values don't become decryptable on their own. If fixing them is possible, it usually requires complex user actions. Enabling this policy or leaving it unset means that users with undecryptable passwords saved to the built-in password manager will lose them. Passwords that are still in a working state remain untouched. Disabling this policy means users will have their password manager data untouched but will experience a broken password manager functionality. If the policy is set, users can't override it in Microsoft Edge.
PasswordExportEnabled Enable exporting saved passwords from Password Manager
If enabled or not configured, users can export saved passwords.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PasswordExportEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 136, Windows 7 or later
- Template
- msedge.admx
This policy controls whether the Export Password button in edge://wallet/passwords is enabled. If enabled or not configured, users can export saved passwords. If disabled, the Export Password button is unavailable, preventing password exports.
PasswordManagerPasskeysEnabled Enable saving passkeys to the password manager
If this policy is enabled or not configured, users can save passkeys in the built-in password manager when signed in to Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PasswordManagerPasskeysEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 145, Windows 7 or later
- Template
- msedge.admx
This policy controls whether users can save passkeys in the built-in password manager. It does not limit access to, or change the contents of, passkeys already saved in the password manager. If the PasswordManagerEnabled policy is Disabled, saving to the built-in password manager is disabled in general, including passkeys. In this case, this policy has no effect. If this policy is enabled or not configured, users can save passkeys in the built-in password manager when signed in to Microsoft Edge. If this policy is disabled, users cannot save new passkeys to the built-in password manager. Previously saved passkeys continue to work.
PasswordManagerEnabled Enable saving passwords to the password manager
If you enable or don't configure this policy, users can save and add their passwords in Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PasswordManagerEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enable Microsoft Edge to save user passwords. The next time a user visits a site with a saved password, Microsoft Edge will enter the password automatically. If you enable or don't configure this policy, users can save and add their passwords in Microsoft Edge. If you disable this policy, users can't save and add new passwords, but they can still use previously saved passwords.
PasswordDeleteOnBrowserCloseEnabled Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes
If you disable or don't configure this policy, the user's personal configuration is used.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PasswordDeleteOnBrowserCloseEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 117, Windows 7 or later
- Template
- msedge.admx
When this policy is enabled, the passwords saved with Edge Password Manager are exempted from deletion when the browser closes. This policy is only effective when the 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) policy is enabled. If you enable this policy, passwords aren't cleared when the browser closes. If you disable or don't configure this policy, the user's personal configuration is used.
PasswordManagerRestrictLengthEnabled Restrict the length of passwords that can be saved in the Password Manager
If you disable or don't configure this policy, Microsoft Edge lets the user save credentials with arbitrarily long usernames and/or passwords.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PasswordManagerRestrictLengthEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 104, Windows 7 or later
- Template
- msedge.admx
Make Microsoft Edge restrict the length of usernames and/or passwords that can be saved in the Password Manager. If you enable this policy, Microsoft Edge doesn't let the user save credentials with usernames and/or passwords longer than 256 characters. If you disable or don't configure this policy, Microsoft Edge lets the user save credentials with arbitrarily long usernames and/or passwords.
Microsoft Edge / PDF Reader
ViewXFAPDFInIEModeAllowedFileHash View XFA-based PDF files using IE Mode for allowed file hash.
If you disable or don't configure this policy, XFA PDFs won't be considered for opening via IE mode except the files from file origin mentioned in Policy 'ViewXFAPDFInIEModeAllowedOrigins' For more information, see - [Get-FileHash](https://go.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ViewXFAPDFInIEModeAllowedFileHash
- Supported on
- Microsoft Edge version 132, Windows 7 or later
- Template
- msedge.admx
XFA is a legacy technology that's deprecated by its original creators. It's not an ISO standard and as such, it doesn't align with the modern web architecture. Continued use poses potential risks and vulnerabilities. For more information, see 'ViewXFAPDFInIEModeAllowedOrigins' (View XFA-based PDF files using IE Mode for allowed file origin.). If you enable this policy, you can configure the list of base64 encoded SHA256 file hashes for which XFA PDF files automatically open in Microsoft Edge using IE Mode. If you disable or don't configure this policy, XFA PDFs won't be considered for opening via IE mode except the files from file origin mentioned in Policy 'ViewXFAPDFInIEModeAllowedOrigins' For more information, see - [Get-FileHash](https://go.microsoft.com/fwlink/?linkid=2294823), [Dot Net Convert API](https://go.microsoft.com/fwlink/?linkid=2294913). Example value: pZGm1Av0IEBKARczz7exkNYsZb8LzaMrV7J32a2fFG4= nFeL0Q+9HX7WFI3RsmSDFTlUtrbclXH67MTdXDwWuu4=
ViewXFAPDFInIEModeAllowedOrigins View XFA-based PDF files using IE Mode for allowed file origin.
If you disable or don't configure the policy, XFA PDFs won't be considered for opening via Internet Explorer mode.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ViewXFAPDFInIEModeAllowedOrigins
- Supported on
- Microsoft Edge version 132, Windows 7 or later
- Template
- msedge.admx
Internet Explorer (IE) mode uses the Adobe Acrobat Active-X PDF Plugin to open XFA-based PDF files. This policy works only if the Active-X plugin is already on the user's device, it's not installed as part of this policy. It's important to note that XFA is a legacy technology that's deprecated by its original creators. It's not an ISO standard and as such doesn't align with the modern web architecture. Continued use poses potential risks and vulnerabilities. Given the deprecated status of XFA technology and the lack of any investment by its creators, we strongly recommend that you start planning your transition to more advanced HTML\PDF form-based solutions. In the interim, this policy provides a workaround for users to view XFA PDF in Microsoft Edge. If you enable this policy, you can configure the list of origins from which XFA PDF files will be automatically opened in Microsoft Edge using IE Mode. If you disable or don't configure the policy, XFA PDFs won't be considered for opening via Internet Explorer mode. For detailed information on valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322 Alternatively, 'ViewXFAPDFInIEModeAllowedFileHash' (View XFA-based PDF files using IE Mode for allowed file hash.) can also be used to configure list of file hashes instead of URL origins, which enables those files to be automatically opened in Microsoft Edge using IE Mode. Example value: https://contesso.sharepoint.com/accounts/ https://contesso.sharepoint.com/transport/ file://account_forms/
Microsoft Edge / Performance
EfficiencyMode Configure when energy saver (previously named efficiency mode) should become active
By default, energy saver is set to 'BalancedSavings'. On devices with no battery, energy saver is disabled by default and does not become active.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EfficiencyMode
- Supported on
- Microsoft Edge version 96, Windows 7 or later
- Template
- msedge.admx
0Energy saver is always active1Energy saver is never active2Energy saver is active when the device is unplugged3Energy saver is active when the device is unplugged and the battery is low4When the device is unplugged, energy saver takes moderate steps to save battery. When the device is unplugged and the battery is low, energy saver takes extra steps to save battery.5When the device is unplugged or unplugged and the battery is low, energy saver takes extra steps to save battery.This policy setting lets you configure when energy saver becomes active. By default, energy saver is set to 'BalancedSavings'. On devices with no battery, energy saver is disabled by default and does not become active. Please note that Windows Energy Saver settings can influence when energy saver becomes active on all devices. Individual sites may be blocked from participating in energy saver by configuring the policy 'SleepingTabsBlockedForUrls' (Block sleeping tabs on specific sites). Set this policy to 'AlwaysActive' and energy saver is always active. Set this policy to 'NeverActive' and energy saver never becomes active. Set this policy to 'ActiveWhenUnplugged' and energy saver becomes active when the device is unplugged. Set this policy to 'ActiveWhenUnpluggedBatteryLow' and energy saver becomes active when the device is unplugged and the battery is low. Set this policy to 'BalancedSavings' and when the device is unplugged, energy saver takes moderate steps to save battery. When the device is unplugged and the battery is low, energy saver takes extra steps to save battery. Set this policy to 'MaximumSavings' and when the device is unplugged or unplugged and the battery is low, energy saver takes extra steps to save battery. If the device does not have a battery, energy saver never becomes active in any mode other than 'AlwaysActive' unless the setting or 'EfficiencyModeEnabled' (Efficiency mode enabled) policy is enabled. This policy has no effect if the 'EfficiencyModeEnabled' policy is disabled. Learn more about energy saver: https://go.microsoft.com/fwlink/?linkid=2173921 Learn more about energy saver: https://learn.microsoft.com/en-us/windows-hardware/design/component-guidelines/energy-saver Policy options mapping: * AlwaysActive (0) = Energy saver is always active * NeverActive (1) = Energy saver is never active * ActiveWhenUnplugged (2) = Energy saver is active when the device is unplugged * ActiveWhenUnpluggedBatteryLow (3) = Energy saver is active when the device is unplugged and the battery is low * BalancedSavings (4) = When the device is unplugged, energy saver takes moderate steps to save battery. When the device is unplugged and the battery is low, energy saver takes extra steps to save battery. * MaximumSavings (5) = When the device is unplugged or unplugged and the battery is low, energy saver takes extra steps to save battery. Use the preceding information when configuring this policy.
EfficiencyModeEnabled Efficiency mode enabled
If you don't configure this policy, efficiency mode will be enabled for devices with a battery and disabled otherwise.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EfficiencyModeEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, efficiency mode is enabled for devices with a battery and is disabled otherwise.
- Supported on
- Microsoft Edge version 106, Windows 7 or later
- Template
- msedge.admx
Enables efficiency mode which helps extend battery life by saving computer resources. By default, efficiency mode is enabled for devices with a battery and is disabled otherwise. If you enable this policy, efficiency mode becomes active according to the setting chosen by the user. You can configure the efficiency mode setting using the 'EfficiencyMode' (Configure when energy saver (previously named efficiency mode) should become active) policy. If the device doesn't have a battery, efficiency mode is always active. If you disable this policy, efficiency mode is never active. The 'EfficiencyMode' and 'EfficiencyModeOnPowerEnabled' (Enable efficiency mode when the device is connected to a power source) policies will have no effect. If you don't configure this policy, efficiency mode will be enabled for devices with a battery and disabled otherwise. Users can choose the efficiency mode option they want in edge://settings/system. Learn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921
EfficiencyModeOnPowerEnabled Enable efficiency mode when the device is connected to a power source
If you disable or don't configure this policy, efficiency mode will never become active when the device is connected to a power source.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- EfficiencyModeOnPowerEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 106, Windows 7 or later
- Template
- msedge.admx
Allows efficiency mode to become active when the device is connected to a power source. On devices with no battery, this policy has no effect. If you enable this policy, efficiency mode will become active when the device is connected to a power source. If you disable or don't configure this policy, efficiency mode will never become active when the device is connected to a power source. This policy has no effect if the 'EfficiencyModeEnabled' (Efficiency mode enabled) policy is disabled. Learn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921
RAMResourceControlsEnabled Enable RAM (memory) resource controls
If you enable or don't configure this policy, users can enable resource control and set the amount of RAM that Microsoft Edge can use.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RAMResourceControlsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 143, Windows 7 or later
- Template
- msedge.admx
This policy controls whether users can access the RAM (memory) resource control feature. This feature lets users set an individual limit on how much RAM (memory) the browser can use. To set a specific memory limit, use the 'TotalMemoryLimitMb' (Set limit on megabytes of memory a single Microsoft Edge instance can use) policy. If you enable or don't configure this policy, users can enable resource control and set the amount of RAM that Microsoft Edge can use. Browser performance may be affected by low limits. If you disable this policy, users can't use resource control.
StartupBoostEnabled Enable startup boost
If you don't configure this policy, startup boost may initially be off or on.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- StartupBoostEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 88, Windows 7 or later
- Template
- msedge.admx
Allows Microsoft Edge processes to start at OS sign-in and restart in background after the last browser window is closed. If Microsoft Edge is running in background mode, the browser might not close when the last window is closed and the browser won't be restarted in background when the window closes. See the 'BackgroundModeEnabled' (Continue running background apps after Microsoft Edge closes) policy for information about what happens after configuring Microsoft Edge background mode behavior. If you enable this policy, startup boost is turned on. If you disable this policy, startup boost is turned off. If you don't configure this policy, startup boost may initially be off or on. The user can configure its behavior in edge://settings/system. Learn more about startup boost: https://go.microsoft.com/fwlink/?linkid=2147018
ExtensionsPerformanceDetectorEnabled Extensions Performance Detector enabled
If you enable or don't configure this policy, users receive Extensions Performance Detector notifications from Browser Essentials.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ExtensionsPerformanceDetectorEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 130, Windows 7 or later
- Template
- msedge.admx
This policy controls if users can access the Extensions Performance Detector Recommended Action feature in Browser Essentials. This feature alerts extension users if their extensions are causing performance regressions in the browser and allows them to take action to resolve the issue. If you enable or don't configure this policy, users receive Extensions Performance Detector notifications from Browser Essentials. When there's an active alert, users are able to view the impact of extensions on their browser's performance and make an informed decision to disable impacting extensions. The detector will exclude browser-managed extensions, such as Google Docs offline, component extensions, and organization-managed extensions (that is, extensions that can't be disabled). If you disable this policy, users won't receive notifications or be able to view the Extensions Performance Detector Recommended Action.
PerformanceDetectorEnabled Performance Detector Enabled
If you enable or don't configure this policy, performance detector is turned on.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PerformanceDetectorEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 107, Windows 7 or later
- Template
- msedge.admx
The performance detector detects tab performance issues and recommends actions to fix the performance issues. If you enable or don't configure this policy, performance detector is turned on. If you disable this policy, performance detector is turned off. The user can configure its behavior in edge://settings/system. Learn more about performance detector: https://aka.ms/EdgePerformanceDetector
PinBrowserEssentialsToolbarButton Pin browser essentials toolbar button
If you enable or don't configure this policy, the Browser essentials button is pinned on the toolbar.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PinBrowserEssentialsToolbarButton
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 114, Windows 7 or later
- Template
- msedge.admx
This policy lets you configure whether to pin the Browser essentials button on the toolbar. When the button is pinned, it always appears on the toolbar. When the button isn't pinned, it only appears when there's an alert. An example of this kind of alert is the performance detector alert that indicates the browser is using high CPU or memory. If you enable or don't configure this policy, the Browser essentials button is pinned on the toolbar. If you disable this policy, the Browser essentials button isn't pinned on the toolbar. Learn more about browser essentials: https://go.microsoft.com/fwlink/?linkid=2240439
Microsoft Edge / Permit or deny screen capture
ScreenCaptureAllowedByOrigins Allow Desktop, Window, and Tab capture by these origins
Leaving the policy unset means that sites won't be considered for an override at this scope of Capture.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ScreenCaptureAllowedByOrigins
- Supported on
- Microsoft Edge version 97, Windows 7 or later
- Template
- msedge.admx
Setting the policy lets you set a list of URL patterns that can use Desktop, Window, and Tab Capture. Leaving the policy unset means that sites won't be considered for an override at this scope of Capture. This policy isn't considered if a site matches a URL pattern in any of the following policies: 'WindowCaptureAllowedByOrigins' (Allow Window and Tab capture by these origins), 'TabCaptureAllowedByOrigins' (Allow Tab capture by these origins), 'SameOriginTabCaptureAllowedByOrigins' (Allow Same Origin Tab capture by these origins). If a site matches a URL pattern in this policy, the 'ScreenCaptureAllowed' (Allow or deny screen capture) isn't considered. For detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored. Example value: https://www.example.com [*.]example.edu
SameOriginTabCaptureAllowedByOrigins Allow Same Origin Tab capture by these origins
Leaving the policy unset means that sites won't be considered for an override at this scope of capture.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\SameOriginTabCaptureAllowedByOrigins
- Supported on
- Microsoft Edge version 97, Windows 7 or later
- Template
- msedge.admx
Setting the policy lets you set a list of URL patterns that can capture tabs with their same Origin. Leaving the policy unset means that sites won't be considered for an override at this scope of capture. If a site matches a URL pattern in this policy, the following policies won't be considered: 'TabCaptureAllowedByOrigins' (Allow Tab capture by these origins), 'WindowCaptureAllowedByOrigins' (Allow Window and Tab capture by these origins), 'ScreenCaptureAllowedByOrigins' (Allow Desktop, Window, and Tab capture by these origins), 'ScreenCaptureAllowed' (Allow or deny screen capture). For detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored. Example value: https://www.example.com [*.]example.edu
TabCaptureAllowedByOrigins Allow Tab capture by these origins
Leaving the policy unset means that sites aren't considered for an override at this scope of capture.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\TabCaptureAllowedByOrigins
- Supported on
- Microsoft Edge version 97, Windows 7 or later
- Template
- msedge.admx
Setting the policy lets you set a list of URL patterns that can use Tab Capture. Leaving the policy unset means that sites aren't considered for an override at this scope of capture. This policy is not considered if a site matches a URL pattern in the 'SameOriginTabCaptureAllowedByOrigins' (Allow Same Origin Tab capture by these origins) policy. If a site matches a URL pattern in this policy, the following policies aren't considered: 'WindowCaptureAllowedByOrigins' (Allow Window and Tab capture by these origins), 'ScreenCaptureAllowedByOrigins' (Allow Desktop, Window, and Tab capture by these origins), 'ScreenCaptureAllowed' (Allow or deny screen capture). For detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored. Example value: https://www.example.com [*.]example.edu
WindowCaptureAllowedByOrigins Allow Window and Tab capture by these origins
Leaving the policy unset means that sites won't be considered for an override at this scope of Capture.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\WindowCaptureAllowedByOrigins
- Supported on
- Microsoft Edge version 97, Windows 7 or later
- Template
- msedge.admx
Setting the policy lets you set a list of URL patterns that can use Window and Tab Capture. Leaving the policy unset means that sites won't be considered for an override at this scope of Capture. This policy isn't considered if a site matches a URL pattern in any of the following policies: 'TabCaptureAllowedByOrigins' (Allow Tab capture by these origins), 'SameOriginTabCaptureAllowedByOrigins' (Allow Same Origin Tab capture by these origins). If a site matches a URL pattern in this policy, the following policies aren't considered: 'ScreenCaptureAllowedByOrigins' (Allow Desktop, Window, and Tab capture by these origins), 'ScreenCaptureAllowed' (Allow or deny screen capture). For detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin; so, any path in the URL pattern is ignored. Example value: https://www.example.com [*.]example.edu
Microsoft Edge / Printing
PrintPreviewStickySettings Configure the sticky print preview settings
If you disable or don't configure this policy, print preview settings aren't impacted.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PrintPreviewStickySettings
- Supported on
- Microsoft Edge version 110, Windows 7 or later
- Template
- msedge.admx
Configuring this policy sets the print preview settings as the most recent choice in Print Preview instead of the default print preview settings. Each item of this policy expects a boolean: Layout specifies if the webpage layout should be kept sticky or not in print preview settings. If you set this to True, the webpage layout uses the recent choice; otherwise, it sets to default value. Size specifies if the page size should be kept sticky or not in print preview settings. If you set this to True, the page size uses the recent choice; otherwise, it sets to default value. Scale Type specifies if the scaling percentage and scale type should be kept sticky or not in print preview settings. If you set this to True, the scale percentage and scale type both use the recent choice; otherwise, it will set to default value. Margins specifies if the page margin should be kept sticky or not in print preview settings. If you set this to True, the page margins use the recent choice; otherwise, it sets to default value. If you enable this policy, the selected values use the most recent choice in Print Preview. If you disable or don't configure this policy, print preview settings aren't impacted. Example value: { "layout": false, "margins": true, "scaleType": false, "size": true } Compact example value: {"layout": false, "margins": true, "scaleType": false, "size": true}
PrintingBackgroundGraphicsDefault Default background graphics printing mode
Policy options mapping: * enabled (enabled) = Enable background graphics printing mode by default * disabled (disabled) = Disable background graphics printing mode by default Use the preceding information when configuring this policy.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PrintingBackgroundGraphicsDefault
- Supported on
- Microsoft Edge version 89, Windows 7 or later
- Template
- msedge.admx
Enable background graphics printing mode by defaultDisable background graphics printing mode by defaultOverrides the last used setting for printing background graphics. If you enable this setting, background graphics printing is enabled. If you disable this setting, background graphics printing is disabled. Policy options mapping: * enabled (enabled) = Enable background graphics printing mode by default * disabled (disabled) = Disable background graphics printing mode by default Use the preceding information when configuring this policy. Example value: enabled
DefaultPrinterSelection Default printer selection rules
If you don't configure this policy or no matching printers are found within the timeout, the printer defaults to the built-in PDF printer or no printer, if the PDF printer isn't available.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- DefaultPrinterSelection
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Overrides Microsoft Edge default printer selection rules. This policy determines the rules for selecting the default printer in Microsoft Edge, which happens the first time a user tries to print a page. When this policy is set, Microsoft Edge tries to find a printer that matches all of the specified attributes and uses it as default printer. If there are multiple printers that meet the criteria, the first printer that matches is used. If you don't configure this policy or no matching printers are found within the timeout, the printer defaults to the built-in PDF printer or no printer, if the PDF printer isn't available. The value is parsed as a JSON object, conforming to the following schema: { "type": "object", "properties": { "idPattern": { "description": "Regular expression to match printer id.", "type": "string" }, "namePattern": { "description": "Regular expression to match printer display name.", "type": "string" } } } Omitting a field means all values match; for example, if you don't specify connectivity Print Preview starts discovering all kinds of local printers. Regular expression patterns must follow the JavaScript RegExp syntax and matches are case sensitive. Example value: { "idPattern": ".*public", "namePattern": ".*Color" }
PrintingPaperSizeDefault Default printing page size
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PrintingPaperSizeDefault
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
Overrides default printing page size. Name should contain one of the listed formats or 'custom' if required paper size isn't in the list. If 'custom' value is provided custom_size property should be specified. It describes the desired height and width in micrometers. Otherwise custom_size property shouldn't be specified. Policy that violates these rules is ignored. If the page size is unavailable on the printer chosen by the user, this policy is ignored. Example value: { "custom_size": { "height": 297000, "width": 210000 }, "name": "custom" } Compact example value: {"custom_size": {"height": 297000, "width": 210000}, "name": "custom"}
PrinterTypeDenyList Disable printer types on the deny list
If you don't configure this policy, or the printer list is empty, all printer types are discoverable.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\PrinterTypeDenyList
- Supported on
- Microsoft Edge version 88, Windows 7 or later
- Template
- msedge.admx
The printer types on the deny list aren't discovered or have their capabilities fetched. Placing all printer types on the deny list effectively disables printing because there's no print destination for documents. If you don't configure this policy, or the printer list is empty, all printer types are discoverable. Printer destinations include extension printers and local printers. Extension printers are also known as print provider destinations, and include any destination that belongs to a Microsoft Edge extension. Local printers are also known as native printing destinations, and include destinations available to the local machine and shared network printers. In Microsoft version 93 or later, if you set this policy to 'pdf' it also disables the 'save as Pdf' option from the right click context menu. In Microsoft version 103 or later, if you set this policy to 'onedrive' it also disables the 'save as Pdf (OneDrive)' option from print preview. Policy options mapping: * privet (privet) = Zeroconf-based (mDNS + DNS-SD) protocol destinations * extension (extension) = Extension-based destinations * pdf (pdf) = The 'Save as PDF' destination. (93 or later, also disables from context menu) * local (local) = Local printer destinations * onedrive (onedrive) = Save as PDF (OneDrive) printer destinations. (103 or later) Use the preceding information when configuring this policy. Example value: local privet
PrintingEnabled Enable printing
If you enable this policy or don't configure it, users can print.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PrintingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Enables printing in Microsoft Edge and prevents users from changing this setting. If you enable this policy or don't configure it, users can print. If you disable this policy, users can't print from Microsoft Edge. Printing is disabled in the wrench menu, extensions, JavaScript applications, and so on. Users can still print from plug-ins that bypass Microsoft Edge while printing. For example, certain Adobe Flash applications have the print option in their context menu, which isn't covered by this policy.
PrintingLPACSandboxEnabled Enable Printing LPAC Sandbox
Setting this policy to Enabled or leaving it unset enables the LPAC Sandbox for printing services when the system configuration supports it.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PrintingLPACSandboxEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 129, Windows 7 or later
- Template
- msedge.admx
Setting this policy to Enabled or leaving it unset enables the LPAC Sandbox for printing services when the system configuration supports it. Setting this policy to Disabled has a detrimental effect on Microsoft Edge's security because services used for printing might run in a weaker sandbox configuration. Only turn this policy off if there are compatibility issues with third party software that prevent printing services from operating correctly inside the LPAC Sandbox.
OopPrintDriversAllowed Out-of-process print drivers allowed
Enabled or Not Set: Microsoft Edge uses a separate service process for these printing tasks.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- OopPrintDriversAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 134, Windows 7 or later
- Template
- msedge.admx
This policy determines whether Microsoft Edge handles interactions with printer drivers through a separate service process. Using a service process for tasks like querying available printers, retrieving print driver settings, and submitting documents to local printers improves browser stability and prevents UI freezing during Print Preview. Enabled or Not Set: Microsoft Edge uses a separate service process for these printing tasks. Disabled: Microsoft Edge performs these printing tasks within the browser process. Note: This policy will be deprecated in the future once the transition to out-of-process print drivers is fully implemented.
PrintHeaderFooter Print headers and footers
If you don't configure this policy, users can decide whether to print headers and footers.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PrintHeaderFooter
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Force 'headers and footers' to be on or off in the printing dialog. If you don't configure this policy, users can decide whether to print headers and footers. If you disable this policy, users can't print headers and footers. If you enable this policy, users always print headers and footers.
PrintPdfAsImageDefault Print PDF as Image Default
If you disable or don't configure this policy, Microsoft Edge won't default to setting the Print as image option in the Print Preview when printing a PDF.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PrintPdfAsImageDefault
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 106, Windows 7 or later
- Template
- msedge.admx
Controls if Microsoft Edge makes the Print as image option the default when printing PDFs. If you enable this policy, Microsoft Edge defaults to setting the Print as image option in the Print Preview when printing a PDF. If you disable or don't configure this policy, Microsoft Edge won't default to setting the Print as image option in the Print Preview when printing a PDF.
PrintPostScriptMode Print PostScript Mode
If you don't configure this policy, Microsoft Edge remains in Default mode.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PrintPostScriptMode
- Supported on
- Microsoft Edge version 96, Windows 7 or later
- Template
- msedge.admx
0Default1Type42Controls how Microsoft Edge prints on Microsoft Windows. Printing to a PostScript printer on Microsoft Windows different PostScript generation methods can affect printing performance. If you set this policy to Default, Microsoft Edge uses a set of default options when generating PostScript. Text in particular, is always rendered using Type 3 fonts. If you set this policy to Type42, Microsoft Edge renders text using Type 42 fonts if possible. This should increase printing speed for some PostScript printers. If you don't configure this policy, Microsoft Edge remains in Default mode. Policy options mapping: * Default (0) = Default * Type42 (1) = Type42 Use the preceding information when configuring this policy.
PrintStickySettings Print preview sticky settings
If you set this policy to 'EnableAll' or don't configure it, Microsoft Edge applies the last used print preview settings for both PDF and webpages. This policy is only available if you enable or don't configure the 'PrintingEnabled' (Enable printing) policy.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PrintStickySettings
- Supported on
- Microsoft Edge version 98, Windows 7 or later
- Template
- msedge.admx
0Enable sticky settings for PDF and Webpages1Disable sticky settings for PDF and Webpages2Disable sticky settings for PDF3Disable sticky settings for WebpagesSpecifies whether print preview should apply last used settings for Microsoft Edge PDF and webpages. If you set this policy to 'EnableAll' or don't configure it, Microsoft Edge applies the last used print preview settings for both PDF and webpages. If you set this policy to 'DisableAll', Microsoft Edge doesn't apply the last used print preview settings for both PDF and webpages. If you set this policy to 'DisablePdf', Microsoft Edge doesn't apply the last used print preview settings for PDF printing and retains it for webpages. If you set this policy to 'DisableWebpage', Microsoft Edge doesn't apply the last used print preview settings for webpage printing and retain it for PDF. This policy is only available if you enable or don't configure the 'PrintingEnabled' (Enable printing) policy. Policy options mapping: * EnableAll (0) = Enable sticky settings for PDF and Webpages * DisableAll (1) = Disable sticky settings for PDF and Webpages * DisablePdf (2) = Disable sticky settings for PDF * DisableWebpage (3) = Disable sticky settings for Webpages Use the preceding information when configuring this policy.
PrintRasterizationMode Print Rasterization Mode
If you set this policy to 'Full' or don't configure it, Microsoft Edge performs full page rasterization if necessary.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PrintRasterizationMode
- Supported on
- Microsoft Edge version 90, Windows 7 or later
- Template
- msedge.admx
0Full page rasterization1Avoid rasterization if possibleControls how Microsoft Edge prints on Windows. When printing to a non-PostScript printer on Windows, some print jobs need to be rasterized to print correctly. If you set this policy to 'Full' or don't configure it, Microsoft Edge performs full page rasterization if necessary. If you set this policy to 'Fast', Microsoft Edge reduces the amount of rasterization, which can decrease print job sizes and increase printing speed. Policy options mapping: * Full (0) = Full page rasterization * Fast (1) = Avoid rasterization if possible Use the preceding information when configuring this policy.
PrintRasterizePdfDpi Print Rasterize PDF DPI
If you set this policy to zero or don't configure it, the system default resolution is used during rasterization of page images.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PrintRasterizePdfDpi
- Supported on
- Microsoft Edge version 96, Windows 7 or later
- Template
- msedge.admx
Controls print image resolution when Microsoft Edge prints PDFs with rasterization. When printing a PDF using the Print to image option, it can be beneficial to specify a print resolution other than a device's printer setting or the PDF default. A high resolution significantly increases the processing and printing time while a low resolution can lead to poor imaging quality. If you set this policy, it allows a particular resolution to be specified for use when rasterizing PDFs for printing. If you set this policy to zero or don't configure it, the system default resolution is used during rasterization of page images.
UseSystemPrintDialog Print using system print dialog
If you don't configure or disable this policy, print commands trigger the Microsoft Edge print preview screen.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- UseSystemPrintDialog
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Shows the system print dialog instead of print preview. If you enable this policy, Microsoft Edge opens the system print dialog instead of the built-in print preview when a user prints a page. If you don't configure or disable this policy, print commands trigger the Microsoft Edge print preview screen.
PrintingAllowedBackgroundGraphicsModes Restrict background graphics printing mode
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PrintingAllowedBackgroundGraphicsModes
- Supported on
- Microsoft Edge version 89, Windows 7 or later
- Template
- msedge.admx
Allow printing with and without background graphicsAllow printing only with background graphicsAllow printing only without background graphicsRestricts background graphics printing mode. If this policy isn't set there's no restriction on printing background graphics. Policy options mapping: * any (any) = Allow printing with and without background graphics * enabled (enabled) = Allow printing only with background graphics * disabled (disabled) = Allow printing only without background graphics Use the preceding information when configuring this policy. Example value: enabled
PrintPreviewUseSystemDefaultPrinter Set the system default printer as the default printer
If you disable this policy or don't configure it, Print Preview uses the most recently used printer as the default destination choice.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PrintPreviewUseSystemDefaultPrinter
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Tells Microsoft Edge to use the system default printer as the default choice in Print Preview instead of the most recently used printer. If you disable this policy or don't configure it, Print Preview uses the most recently used printer as the default destination choice. If you enable this policy, Print Preview uses the OS system default printer as the default destination choice.
PrintingWebpageLayout Sets layout for printing
If you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PrintingWebpageLayout
- Supported on
- Microsoft Edge version 93, Windows 7 or later
- Template
- msedge.admx
0Sets layout option as portrait1Sets layout option as landscapeConfiguring this policy sets the layout for printing webpages. If you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout. If you enable this policy, the selected option is set as the layout option. Policy options mapping: * portrait (0) = Sets layout option as portrait * landscape (1) = Sets layout option as landscape Use the preceding information when configuring this policy.
Microsoft Edge / Private Network Request Settings
InsecurePrivateNetworkRequestsAllowedForUrls Allow the listed sites to make requests to more-private network endpoints from in an insecure manner (obsolete)
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\InsecurePrivateNetworkRequestsAllowedForUrls
- Supported on
- Microsoft Edge version 92-137, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 137. List of URL patterns. Requests initiated from websites served by matching origins aren't subject to Private Network Access checks. If this policy isn't set, this policy behaves as if set to the empty list. For origins not covered by the patterns specified here, the global default value is used either from the 'InsecurePrivateNetworkRequestsAllowed' (Specifies whether to allow websites to make requests to any network endpoint in an insecure manner.) policy, if it's set, or the user's personal configuration otherwise. For detailed information on valid URL patterns, see [Filter format for URL list-based policies](/DeployEdge/edge-learnmmore-url-list-filter%20format). This policy is obsolete. The previous blanket override has been replaced by the permission-based Local Network Access model, which blocks cross-space requests until users grant explicit consent. Example value: http://www.example.com:8080 [*.]example.edu
InsecurePrivateNetworkRequestsAllowed Specifies whether to allow websites to make requests to any network endpoint in an insecure manner. (obsolete)
When this policy is disabled or not configured, the default behavior for requests to more-private network endpoints depend on the user's personal configuration for the BlockInsecurePrivateNetworkRequests, PrivateNetworkAccessSendPreflights, and PrivateNetworkAccessRespectPreflightResults feature flags.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- InsecurePrivateNetworkRequestsAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 92-137, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 137. Controls whether websites are allowed to make requests to more-private network endpoints. When this policy is enabled, all Private Network Access checks are disabled for all origins. This may allow attackers to perform cross-site request forgery (CSRF) attacks on private network servers. When this policy is disabled or not configured, the default behavior for requests to more-private network endpoints depend on the user's personal configuration for the BlockInsecurePrivateNetworkRequests, PrivateNetworkAccessSendPreflights, and PrivateNetworkAccessRespectPreflightResults feature flags. These flags may be controlled by experimentation or set via the command line. This policy relates to the Private Network Access specification. See https://wicg.github.io/private-network-access/ for more details. A network endpoint is more private than another if: 1) Its IP address is localhost and the other isn't. 2) Its IP address is private and the other is public. In the future, depending on spec evolution, this policy might apply to all cross-origin requests directed at private IPs or localhost. When this policy enabled, websites are allowed to make requests to any network endpoint, subject to other cross-origin checks. This policy is obsolete. The previous blanket override has been replaced by the permission-based Local Network Access model, which blocks cross-space requests until users grant explicit consent.
PrivateNetworkAccessRestrictionsEnabled Specifies whether to apply restrictions to requests to more private network endpoints (obsolete)
When this policy is Disabled or unset, all Private Network Access warnings aren't enforced and the requests aren't blocked.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PrivateNetworkAccessRestrictionsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 131-137, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 137. Specifies whether to apply restrictions to requests to more private network endpoints When this policy is Enabled, anytime when a warning is supposed to be displayed in the DevTools due to Private Network Access checks failing, the request is blocked. When this policy is Disabled or unset, all Private Network Access warnings aren't enforced and the requests aren't blocked. See https://wicg.github.io/private-network-access/ for Private Network Access restrictions. Note: A network endpoint is more private than another if: 1) Its IP address is localhost and the other isn't. 2) Its IP address is private and the other is public. This policy is obsolete. The earlier blanket override has been replaced by the permission-based Local Network Access model, which blocks cross-space requests until users give explicit consent.
Microsoft Edge / Profile settings
ProfileTypeInProfileButtonEnabled Controls the display of the profile button label for the work or school profile
If you disable this policy or leave it not configured, the label isn't shown.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ProfileTypeInProfileButtonEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 136, Windows 7 or later
- Template
- msedge.admx
Controls whether the label for the work or school profile type is shown in the profile button. This policy doesn't apply when the OrganizationalBrandingOnWorkProfileUIEnabled policy is enabled. If you enable this policy, the label for the work or school profile type appears in the profile button. If you disable this policy or leave it not configured, the label isn't shown.
Microsoft Edge / Protected Content
ProtectedContentIdentifiersAllowed Allows web pages to use identifiers for the purpose of protected content playback
If you enable this policy or do not configure it, sites are allowed to use protected content identifiers.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ProtectedContentIdentifiersAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 147, Windows 7 or later
- Template
- msedge.admx
This policy controls whether sites can use hardware-specific device identifiers to enable hardware-secure DRM (for example, Widevine L1 or PlayReady SL3000), which may be required for high-resolution protected content playback. If you enable this policy or do not configure it, sites are allowed to use protected content identifiers. If you disable this policy, sites are not allowed to use protected content identifiers.
Microsoft Edge / Proxy server
ProxyServer Configure address or URL of proxy server (deprecated)
If you disable or don't configure this policy, users can choose their own proxy settings while in this proxy mode.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ProxyServer
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. This policy is deprecated, use 'ProxySettings' (Proxy settings) instead. It doesn't work in Microsoft Edge version 91. Specifies the URL of the proxy server. This policy is applied only if the 'ProxySettings' policy isn't specified and you selected fixed_servers in the 'ProxyMode' (Configure proxy server settings) policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy. If you enable this policy, the proxy server configured by this policy is used for all URLs. If you disable or don't configure this policy, users can choose their own proxy settings while in this proxy mode. Leave this policy unconfigured if you specified any other method for setting proxy policies. For more options and detailed examples, see https://go.microsoft.com/fwlink/?linkid=2094936. Example value: 123.123.123.123:8080
ProxyBypassList Configure proxy bypass rules (deprecated)
If you don't configure this policy, no list of hosts is created for which Microsoft Edge bypasses a proxy.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ProxyBypassList
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. This policy is deprecated, use 'ProxySettings' (Proxy settings) instead. It doesn't work in Microsoft Edge version 91. Defines a list of hosts for which Microsoft Edge bypasses any proxy. This policy is applied only if the 'ProxySettings' policy isn't specified and you selected either fixed_servers or pac_script in the 'ProxyMode' (Configure proxy server settings) policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy. If you enable this policy, you can create a list of hosts for which Microsoft Edge doesn't use a proxy. If you don't configure this policy, no list of hosts is created for which Microsoft Edge bypasses a proxy. Leave this policy unconfigured if you specified any other method for setting proxy policies. For more detailed examples, go to https://go.microsoft.com/fwlink/?linkid=2094936. Example value: https://www.contoso.com, https://www.fabrikam.com
ProxyMode Configure proxy server settings (deprecated)
If you don't configure this policy, users can choose their own proxy settings.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ProxyMode
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Never use a proxyAuto detect proxy settingsUse a .pac proxy scriptUse fixed proxy serversUse system proxy settingsDEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. This policy is deprecated and doesn't work in Microsoft Edge version 91. Use 'ProxySettings' (Proxy settings) instead. If you set this policy to Enabled, you can specify the proxy server Microsoft Edge uses and prevents users from changing proxy settings. Microsoft Edge ignores all proxy-related options specified from the command line. The policy is only applied if the 'ProxySettings' policy isn't specified. Other options are ignored if you choose one of the following options: * direct = Never use a proxy server and always connect directly * system = Use system proxy settings * auto_detect = Auto detect the proxy server If you choose to use: * fixed_servers = Fixed proxy servers. You can specify further options with 'ProxyServer' (Configure address or URL of proxy server) and 'ProxyBypassList' (Configure proxy bypass rules). * pac_script = A .pac proxy script. Use 'ProxyPacUrl' (Set the proxy .pac file URL) to set the URL to a proxy .pac file. For detailed examples, go to https://go.microsoft.com/fwlink/?linkid=2094936. If you don't configure this policy, users can choose their own proxy settings. Policy options mapping: * ProxyDisabled (direct) = Never use a proxy * ProxyAutoDetect (auto_detect) = Auto detect proxy settings * ProxyPacScript (pac_script) = Use a .pac proxy script * ProxyFixedServers (fixed_servers) = Use fixed proxy servers * ProxyUseSystem (system) = Use system proxy settings Use the preceding information when configuring this policy. Example value: direct
ProxySettings Proxy settings
If you don't configure this policy, users can choose their own proxy settings.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ProxySettings
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Configures the proxy settings for Microsoft Edge. If you enable this policy, Microsoft Edge ignores all proxy-related options specified from the command line. If you don't configure this policy, users can choose their own proxy settings. This policy overrides the following individual policies: 'ProxyMode' (Configure proxy server settings) 'ProxyPacUrl' (Set the proxy .pac file URL) 'ProxyServer' (Configure address or URL of proxy server) 'ProxyBypassList' (Configure proxy bypass rules) Setting the 'ProxySettings' (Proxy settings) policy accepts the following fields: * ProxyMode, which lets you specify the proxy server used by Microsoft Edge and prevents users from changing proxy settings * ProxyPacUrl, a URL to a proxy .pac file or a PAC script encoded as a data URL with MIME type application/x-ns-proxy-autoconfig * ProxyPacMandatory, a boolean flag that prevents the network stack from falling back to direct connections with invalid or unavailable PAC script * ProxyServer, a URL for the proxy server * ProxyBypassList, a list of proxy hosts that Microsoft Edge bypasses For ProxyMode, the following values when chosen lead to the following results: * direct, a proxy is never used and all other fields are ignored. * system, the systems's proxy is used and all other fields are ignored. * auto_detect, all other fields are ignored. * fixed_servers, the ProxyServer and ProxyBypassList fields are used. * pac_script, the ProxyPacUrl, ProxyPacMandatory and ProxyBypassList fields are used. For more detailed examples, see https://go.microsoft.com/fwlink/?linkid=2094936. Example value: { "ProxyBypassList": "https://www.example1.com,https://www.example2.com,https://internalsite/", "ProxyMode": "pac_script", "ProxyPacMandatory": false, "ProxyPacUrl": "https://internal.site/example.pac", "ProxyServer": "123.123.123.123:8080" } Compact example value: {"ProxyBypassList": "https://www.example1.com,https://www.example2.com,https://internalsite/", "ProxyMode": "pac_script", "ProxyPacMandatory": false, "ProxyPacUrl": "https://internal.site/example.pac", "ProxyServer": "123.123.123.123:8080"}
ProxyPacUrl Set the proxy .pac file URL (deprecated)
If you disable or don't configure this policy, no PAC file is specified.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ProxyPacUrl
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. This policy is deprecated; use 'ProxySettings' (Proxy settings) instead. It doesn't work in Microsoft Edge version 91. Specifies the URL for a proxy auto-config (PAC) file. This policy is applied only if the 'ProxySettings' policy isn't specified, and if you've selected pac_script in the 'ProxyMode' (Configure proxy server settings) policy. If you've selected any other mode for configuring proxy policies, don't enable or configure this policy. If you enable this policy, specify the URL for a PAC file, which defines how the browser automatically chooses the appropriate proxy server for fetching a particular website. If you disable or don't configure this policy, no PAC file is specified. Leave this policy unconfigured if you've specified any other method for setting proxy policies. For detailed examples, see https://go.microsoft.com/fwlink/?linkid=2094936. Example value: https://internal.contoso.com/example.pac
Microsoft Edge / Related Website Sets Settings
RelatedWebsiteSetsEnabled Enable Related Website Sets (deprecated)
If this policy set to True or unset, the Related Website Sets feature is enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RelatedWebsiteSetsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 121, Windows 7 or later
- Template
- msedge.admx
DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. This policy lets you control the enablement of the Related Website Sets feature. Related Website Sets (RWS) is a way for an organisation to declare relationships among sites, so that Microsoft Edge allows limited third-party cookie access for specific purposes across those sites. If this policy set to True or unset, the Related Website Sets feature is enabled. If this policy is set to False, the Related Website Sets feature is disabled. This policy is deprecated as of Microsoft Edge version 144 with the deprecation of Related Website Sets.
RelatedWebsiteSetsOverrides Override Related Website Sets. (deprecated)
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RelatedWebsiteSetsOverrides
- Supported on
- Microsoft Edge version 121, Windows 7 or later
- Template
- msedge.admx
DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. This policy provides a way to override the list of sets Microsoft Edge uses for Related Website Sets Each set in the browser's list of Related Website Sets must meet the requirements of a Related Website Set. A Related Website Set must contain a primary site and one or more member sites. A set can also contain a list of service sites that it owns, and a map from a site to all its ccTLD variants. For more information on how Microsoft Edge uses Related Website Sets, see https://github.com/WICG/first-party-sets. All sites in a Related Website Set must be a registrable domain served over HTTPS. Each site in a Related Website Set must also be unique, which means a site can't be listed more than once in a Related Website Set. When this policy is given an empty dictionary, Microsoft Edge uses the public list of Related Website Sets. For all sites in a Related Website Set from the replacements list, if a site is also present on a Related Website Set in the browser's list, then that site will be removed from the browser's Related Website Set. After this step, the policy's Related Website Set is added to the Microsoft Edge's list of Related Website Sets. For all sites in a Related Website Set from the additions list, if a site is also present on a Related Website Set in Microsoft Edge's list, then the browser's Related Website Set is updated so that the new Related Website Set can be added to the browser's list. After the browser's list has been updated, the policy's Related Website Set is added to the browser's list of Related Website Sets. The browser's list of Related Website Sets requires that for all sites in its list, no site is in more than one set. This requirement is also required for both the replacements list and the additions list. Similarly, a site can't be in both the replacements list and the additions list. Wildcards (*) aren't supported as a policy value, or as a value within any Related Website Set in these lists. This policy is deprecated as of Microsoft Edge version 144 with the deprecation of Related Website Sets. Example value: { "additions": [ { "associatedSites": [ "https://associate2.test" ], "ccTLDs": { "https://associate2.test": [ "https://associate2.com" ] }, "primary": "https://primary2.test", "serviceSites": [ "https://associate2-content.test" ] } ], "replacements": [ { "associatedSites": [ "https://associate1.test" ], "ccTLDs": { "https://associate1.test": [ "https://associate1.co.uk" ] }, "primary": "https://primary1.test", "serviceSites": [ "https://associate1-content.test" ] } ] } Compact example value: {"additions": [{"associatedSites": ["https://associate2.test"], "ccTLDs": {"https://associate2.test": ["https://associate2.com"]}, "primary": "https://primary2.test", "serviceSites": ["https://associate2-content.test"]}], "replacements": [{"associatedSites": ["https://associate1.test"], "ccTLDs": {"https://associate1.test": ["https://associate1.co.uk"]}, "primary": "https://primary1.test", "serviceSites": ["https://associate1-content.test"]}]}
Microsoft Edge / Scareware Blocker settings
ScarewareBlockerProtectionEnabled Configure Microsoft Edge Scareware blocker protection
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ScarewareBlockerProtectionEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 134, Windows 7 or later
- Template
- msedge.admx
This policy setting allows administrators to control whether Microsoft Edge enables Scareware blocker, an AI-powered feature for protecting users from potential tech scams. To support this feature, Microsoft Edge downloads a machine learning model file from Microsoft to the device. If you enable or don’t configure this policy, Microsoft Edge Scareware blocker uses local AI to detect potential tech scams. If you disable this policy, Microsoft Edge Scareware blocker is disabled. The machine learning model file doesn't download to the device, and if downloaded, a deletion occurs. When this policy is enabled, the policies 'ScarewareBlockerBlocksDetectedSitesEnabled' (Configure Microsoft Edge scareware blocker to block sites detected as potential tech scams), 'ScarewareBlockerSendDetectedSitesToSmartScreenEnabled' (Configure Microsoft Edge Scareware blocker to share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen), and 'ScarewareBlockerAllowListDomains' (Configure the list of domains where Microsoft Edge Scareware blockers don't run) are used to configure the behavior of the Scareware blocker feature. If both of those policies are disabled, enabling this policy has no effect. When this policy is disabled, the policies 'ScarewareBlockerBlocksDetectedSitesEnabled', 'ScarewareBlockerSendDetectedSitesToSmartScreenEnabled', and 'ScarewareBlockerAllowListDomains' have no effect.
ScarewareBlockerBlocksDetectedSitesEnabled Configure Microsoft Edge scareware blocker to block sites detected as potential tech scams
If you enable or don't configure this policy, Microsoft Edge blocks sites detected as potential tech scams.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ScarewareBlockerBlocksDetectedSitesEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 142, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Microsoft Edge blocks sites that are detected as potential tech scams. This policy only takes effect if ScarewareBlockerProtectionEnabled is enabled. If you enable or don't configure this policy, Microsoft Edge blocks sites detected as potential tech scams. If you disable this policy, Microsoft Edge doesn't block sites detected as potential tech scams.
ScarewareBlockerSendDetectedSitesToSmartScreenEnabled Configure Microsoft Edge Scareware blocker to share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen
If you disable or don't configure this policy, Microsoft Edge doesn't share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ScarewareBlockerSendDetectedSitesToSmartScreenEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 142, Windows 7 or later
- Template
- msedge.admx
This policy controls whether Microsoft Edge shares URLs of sites that are detected as potential tech scams with Microsoft Defender SmartScreen. This policy only takes effect if ScarewareBlockerProtectionEnabled is enabled. If you enable this policy, Microsoft Edge shares URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen. If you disable or don't configure this policy, Microsoft Edge doesn't share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.
ScarewareBlockerAllowListDomains Configure the list of domains where Microsoft Edge Scareware blockers don't run
If you disable or don't configure this policy, Microsoft Edge Scareware blocker analyzes all sites.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\ScarewareBlockerAllowListDomains
- Supported on
- Microsoft Edge version 142, Windows 7 or later
- Template
- msedge.admx
This policy configures the list of trusted domains for Microsoft Edge Scareware blocker. When a website's source URL matches any domain in this list, Microsoft Edge Scareware blocker doesn't analyze that site. This policy takes effect only if the ScarewareBlockerProtectionEnabled policy is enabled. If you enable this policy, Microsoft Edge Scareware blocker trusts the specified domains. If you disable or don't configure this policy, Microsoft Edge Scareware blocker analyzes all sites. Example value: mydomain.com myuniversity.edu
Microsoft Edge / Sleeping tabs settings
SleepingTabsBlockedForUrls Block sleeping tabs on specific sites
If you don't configure this policy, all sites are eligible to be put to sleep unless the user's personal configuration blocks them.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\SleepingTabsBlockedForUrls
- Supported on
- Microsoft Edge version 88, Windows 7 or later
- Template
- msedge.admx
Define a list of sites, based on URL patterns, that aren't allowed to be put to sleep by sleeping tabs. Sites in this list are also excluded from other performance optimizations like efficiency mode and tab discard. If the policy 'SleepingTabsEnabled' (Configure sleeping tabs) is disabled, this list isn't used and no sites are put to sleep automatically. If you don't configure this policy, all sites are eligible to be put to sleep unless the user's personal configuration blocks them. Example value: https://www.contoso.com [*.]contoso.edu
AutoDiscardSleepingTabsEnabled Configure auto discard sleeping tabs
If the 'SleepingTabsEnabled' (Configure sleeping tabs) policy is enabled, then this feature is enabled by default. If the 'SleepingTabsEnabled' is disabled, then this feature is disabled by default and can't be enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- AutoDiscardSleepingTabsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 120, Windows 7 or later
- Template
- msedge.admx
Setting this policy enables inactive (sleeping) tabs to be automatically discarded after 1.5 days of inactivity. This is done to save memory. When the user switches back to a discarded tab, the tab needs to be reloaded. If the 'SleepingTabsEnabled' (Configure sleeping tabs) policy is enabled, then this feature is enabled by default. If the 'SleepingTabsEnabled' is disabled, then this feature is disabled by default and can't be enabled. If enabled, idle background tabs will be discarded after 1.5 days. If disabled, idle background tab won't be discarded after 1.5 days. Tabs can still be discarded for other reasons if this policy is disabled.
SleepingTabsEnabled Configure sleeping tabs
If this policy is not configured, users can choose whether to enable sleeping tabs.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SleepingTabsEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, sleeping tabs is turned on.
- Supported on
- Microsoft Edge version 88, Windows 7 or later
- Template
- msedge.admx
This policy setting lets you configure whether to turn on sleeping tabs. Sleeping tabs reduces CPU, battery, and memory usage by putting idle background tabs to sleep. Microsoft Edge uses heuristics to avoid putting tabs to sleep that do useful work in the background, such as display notifications, play sound, and stream video. By default, sleeping tabs is turned on. Individual sites may be blocked from being put to sleep by configuring the policy 'SleepingTabsBlockedForUrls' (Block sleeping tabs on specific sites). If this policy is enabled, sleeping tabs are turned on. If this policy is disabled, sleeping tabs are turned off. However, during moderate memory pressure, the system may freeze (sleep) tabs before discarding them. If this policy is not configured, users can choose whether to enable sleeping tabs.
SleepingTabsTimeout Set the background tab inactivity timeout for sleeping tabs
Tabs are only put to sleep automatically when the policy 'SleepingTabsEnabled' (Configure sleeping tabs) is enabled or isn't configured, and the user has enabled the sleeping tabs setting. If you don't configure this policy, users can choose the timeout value.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SleepingTabsTimeout
- Stated default
- By default, this timeout is 7,200 seconds (2 hours).
- Supported on
- Microsoft Edge version 88, Windows 7 or later
- Template
- msedge.admx
3030 seconds of inactivity3005 minutes of inactivity90015 minutes of inactivity180030 minutes of inactivity36001 hour of inactivity72002 hours of inactivity108003 hours of inactivity216006 hours of inactivity4320012 hours of inactivityThis policy setting lets you configure the timeout, in seconds, after which inactive background tabs are automatically put to sleep if sleeping tabs is enabled. By default, this timeout is 7,200 seconds (2 hours). Tabs are only put to sleep automatically when the policy 'SleepingTabsEnabled' (Configure sleeping tabs) is enabled or isn't configured, and the user has enabled the sleeping tabs setting. If you don't configure this policy, users can choose the timeout value. Policy options mapping: * 30Seconds (30) = 30 seconds of inactivity * 5Minutes (300) = 5 minutes of inactivity * 15Minutes (900) = 15 minutes of inactivity * 30Minutes (1800) = 30 minutes of inactivity * 1Hour (3600) = 1 hour of inactivity * 2Hours (7200) = 2 hours of inactivity * 3Hours (10800) = 3 hours of inactivity * 6Hours (21600) = 6 hours of inactivity * 12Hours (43200) = 12 hours of inactivity Use the preceding information when configuring this policy.
Microsoft Edge / SmartScreen settings
SmartScreenEnabled Configure Microsoft Defender SmartScreen
If you don't configure this setting, users can choose whether to use Microsoft Defender SmartScreen.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SmartScreenEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, Microsoft Defender SmartScreen is turned on.
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Microsoft Security BaselineSmartScreenEnabled = 1
This policy setting lets you configure whether to turn on Microsoft Defender SmartScreen. Microsoft Defender SmartScreen provides warning messages to help protect your users from potential phishing scams and malicious software. By default, Microsoft Defender SmartScreen is turned on. If you enable this setting, Microsoft Defender SmartScreen is turned on. If you disable this setting, Microsoft Defender SmartScreen is turned off. If you don't configure this setting, users can choose whether to use Microsoft Defender SmartScreen. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.
SmartScreenPuaEnabled Configure Microsoft Defender SmartScreen to block potentially unwanted apps
If you don't configure this setting, users can choose whether to use potentially unwanted app blocking with Microsoft Defender SmartScreen.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SmartScreenPuaEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- Potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off by default.
- Supported on
- Microsoft Edge version 80, Windows 7 or later
- Template
- msedge.admx
Microsoft Security BaselineSmartScreenPuaEnabled = 1
This policy setting lets you configure whether to turn on blocking for potentially unwanted apps with Microsoft Defender SmartScreen. Potentially unwanted app blocking with Microsoft Defender SmartScreen provides warning messages to help protect users from adware, coin miners, bundleware, and other low-reputation apps that are hosted by websites. Potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off by default. If you enable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned on. If you disable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off. If you don't configure this setting, users can choose whether to use potentially unwanted app blocking with Microsoft Defender SmartScreen. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are managed via Mobile Device Management (MDM) or joined to a domain via MCX.
SmartScreenAllowListDomains Configure the list of domains for which Microsoft Defender SmartScreen won't trigger warnings
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\SmartScreenAllowListDomains
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Configures the list of Microsoft Defender SmartScreen trusted domains. This means: - Microsoft Defender SmartScreen won't check for potentially malicious resources like phishing software and other malware if the source URLs match these domains. - The Microsoft Defender SmartScreen download protection service won't check downloads hosted on these domains. If you enable this policy, Microsoft Defender SmartScreen trusts these domains. If you disable or don't set this policy, default Microsoft Defender SmartScreen protection is applied to all resources. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10/11 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via mobile device management (MDM) or joined to a domain via MCX. Note: If your organization has enabled Microsoft Defender for Endpoint, this policy and any allowlists created with the policy are ignored. You must configure your allowlists and blocklists in Microsoft 365 Defender portal using "Indicators" (Settings > Endpoints > Indicators). Example value: mydomain.com myuniversity.edu
ExemptSmartScreenDownloadWarnings Disable SmartScreen AppRep based warnings for specified file types on specified domains
If you disable this policy or don't configure it, files that trigger SmartScreen AppRep download warnings show warnings to the user.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ExemptSmartScreenDownloadWarnings
- Supported on
- Microsoft Edge version 118, Windows 7 or later
- Template
- msedge.admx
You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that are exempted from SmartScreen AppRep warnings. For example, if the `vbe` extension is associated with "contoso.com," users can't see a SmartScreen AppRep warning when downloading `vbe` files from "contoso.com." They can, however, see a download warning when downloading `vbe` files from "fabrikam.com." Files with file type extensions specified for domains identified by this policy are still subject to file type extension-based security warnings and mixed-content download warnings. If you disable this policy or don't configure it, files that trigger SmartScreen AppRep download warnings show warnings to the user. If you enable this policy: * The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322. * The file type extension entered must be in lower-cased ASCII. The leading separator shouldn't be included when listing the file type extension; so, `vbe` should be used instead of `.vbe`. Example: The following example prevents SmartScreen AppRep warnings on msi, exe, and vbe extensions for *.contoso.com domains. It might show the user a SmartScreen AppRep warning on any other domain for exe and msi files but not for vbe files. [ { "file_extension": "msi", "domains": ["contoso.com"] }, { "file_extension": "exe", "domains": ["contoso.com"] }, { "file_extension": "vbe", "domains": ["*"] } ] Note: While the preceding example shows the suppression of SmartScreen AppRep download warnings for `vbe` files for all domains, applying suppression of such warnings for all domains isn't recommended due to security concerns. The ability to suppress warnings for all domains is shown in the example merely to demonstrate the ability to do so. Example value: [ { "domains": [ "https://contoso.com", "contoso2.com" ], "file_extension": "msi" }, { "domains": [ "*" ], "file_extension": "vbe" } ]
SmartScreenDnsRequestsEnabled Enable Microsoft Defender SmartScreen DNS requests
If you enable or don't configure this setting, Microsoft Defender SmartScreen can make DNS requests.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SmartScreenDnsRequestsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 97, Windows 7 or later
- Template
- msedge.admx
This policy lets you configure whether to enable DNS requests made by Microsoft Defender SmartScreen. Note: Disabling DNS requests prevent Microsoft Defender SmartScreen from getting IP addresses, and potentially impact the IP-based protections provided. If you enable or don't configure this setting, Microsoft Defender SmartScreen can make DNS requests. If you disable this setting, Microsoft Defender SmartScreen can't make any DNS requests. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are managed via MDM or joined to a domain via MCX.
NewSmartScreenLibraryEnabled Enable new SmartScreen library (obsolete)
If you enable or don't configure this policy, Microsoft Edge uses the new SmartScreen library (libSmartScreenN). Before Microsoft Edge version 103, if you don't configure this policy, Microsoft Edge uses the old SmartScreen library (libSmartScreen).
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NewSmartScreenLibraryEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 95-107, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 107. This policy doesn't work because it was only intended to be a short-term mechanism to support the update to a new SmartScreen client. Allows the Microsoft Edge browser to load the new SmartScreen library (libSmartScreenN) for any SmartScreen checks on site URLs or application downloads. If you enable or don't configure this policy, Microsoft Edge uses the new SmartScreen library (libSmartScreenN). If you disable this policy, Microsoft Edge uses the old SmartScreen library (libSmartScreen). Before Microsoft Edge version 103, if you don't configure this policy, Microsoft Edge uses the old SmartScreen library (libSmartScreen). This policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management. This also includes macOS instances that are that are managed via MDM or joined to a domain via MCX.
SmartScreenForTrustedDownloadsEnabled Force Microsoft Defender SmartScreen checks on downloads from trusted sources
If you enable or don't configure this setting, Microsoft Defender SmartScreen checks the download's reputation regardless of source.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SmartScreenForTrustedDownloadsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 78, Windows 7 or later
- Template
- msedge.admx
This policy setting lets you configure whether Microsoft Defender SmartScreen checks download reputation from a trusted source. In Windows, the policy determines a trusted source by checking its Internet zone. If the source comes from the local system, intranet, or trusted sites zone, then the download is considered trusted and safe. If you enable or don't configure this setting, Microsoft Defender SmartScreen checks the download's reputation regardless of source. If you disable this setting, Microsoft Defender SmartScreen doesn't check the download's reputation when downloading from a trusted source. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management.
PreventSmartScreenPromptOverride Prevent bypassing Microsoft Defender SmartScreen prompts for sites
If you disable or don't configure this setting, users can ignore Microsoft Defender SmartScreen warnings and continue to the site.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PreventSmartScreenPromptOverride
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Microsoft Security BaselinePreventSmartScreenPromptOverride = 1 (SmartScreenPromptOverride off)
This policy setting lets you decide whether users can override the Microsoft Defender SmartScreen warnings about potentially malicious websites. If you enable this setting, users can't ignore Microsoft Defender SmartScreen warnings and they're blocked from continuing to the site. If you disable or don't configure this setting, users can ignore Microsoft Defender SmartScreen warnings and continue to the site. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.
PreventSmartScreenPromptOverrideForFiles Prevent bypassing of Microsoft Defender SmartScreen warnings about downloads
If you disable or don't configure this policy, users can ignore Microsoft Defender SmartScreen warnings and complete unverified downloads.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- PreventSmartScreenPromptOverrideForFiles
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Microsoft Security BaselinePreventSmartScreenPromptOverrideForFiles = 1 (SmartScreenPromptOverrideForFiles off)
This policy lets you determine whether users can override Microsoft Defender SmartScreen warnings about unverified downloads. If you enable this policy, users in your organization can't ignore Microsoft Defender SmartScreen warnings, and they're prevented from completing the unverified downloads. If you disable or don't configure this policy, users can ignore Microsoft Defender SmartScreen warnings and complete unverified downloads. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.
Microsoft Edge / Startup, home page and new tab page
RestoreOnStartup Action to take on Microsoft Edge startup
Disabling this setting is the same as leaving it not configured.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RestoreOnStartup
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
5Open a new tab1Restore the last session4Open a list of URLs6Open a list of URLs and restore the last sessionSpecify how Microsoft Edge behaves when it starts. If you want a new tab to always open on startup, choose 'RestoreOnStartupIsNewTabPage'. If you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'RestoreOnStartupIsLastSession'. The browsing session is restored as it was. This option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies). If you want to open a specific set of URLs, choose 'RestoreOnStartupIsURLs'. Starting in Microsoft Edge version 125, if you want to reopen URLs that were open the last time Microsoft Edge closed and open a specific set of URLs, choose 'RestoreOnStartupIsLastSessionAndURLs'. Disabling this setting is the same as leaving it not configured. Users can change it in Microsoft Edge. This policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is only available on instances that are managed via MDM or joined to a domain via MCX. Policy options mapping: * RestoreOnStartupIsNewTabPage (5) = Open a new tab * RestoreOnStartupIsLastSession (1) = Restore the last session * RestoreOnStartupIsURLs (4) = Open a list of URLs * RestoreOnStartupIsLastSessionAndURLs (6) = Open a list of URLs and restore the last session Use the preceding information when configuring this policy.
NewTabPageContentEnabled Allow Microsoft content on the new tab page
If you enable or don't configure this policy, Microsoft Edge displays Microsoft content on the new tab page.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NewTabPageContentEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 91, Windows 7 or later
- Template
- msedge.admx
This policy applies for Microsoft Edge to all profile types, namely unsigned local user profiles, profiles signed in using a Microsoft Account, profiles signed in using Active Directory, and profiles signed in using Microsoft Entra ID. The Enterprise new tab page for profiles signed in using Microsoft Entra ID can be configured in the Microsoft 365 admin portal, but this policy setting takes precedence; therefore, any Microsoft 365 admin portal configurations are ignored. If you enable or don't configure this policy, Microsoft Edge displays Microsoft content on the new tab page. The user can choose different display options for the content. These options include, but aren't limited to: "Content off", "Content visible on scroll", "Headings only", and "Content visible". Enabling this policy doesn't force content to be visible - the users can keep setting their own preferred content position. If you disable this policy, Microsoft Edge doesn't display Microsoft content on the new tab page. The Content control in the NTP settings flyout is disabled and set to "Content off", and the Layout control in the NTP settings flyout is disabled and set to "Custom". Related policies: 'NewTabPageAllowedBackgroundTypes' (Configure the background types allowed for the new tab page layout), 'NewTabPageQuickLinksEnabled' (Allow quick links on the new tab page)
NewTabPageQuickLinksEnabled Allow quick links on the new tab page
If you enable or don't configure this policy, Microsoft Edge displays quick links on the new tab page, and the user can interact with the control, turning quick links on and off.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NewTabPageQuickLinksEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 91, Windows 7 or later
- Template
- msedge.admx
If you enable or don't configure this policy, Microsoft Edge displays quick links on the new tab page, and the user can interact with the control, turning quick links on and off. Enabling this policy doesn't force quick links to be visible - the user can continue to turn quick links on and off. If you disable this policy, Microsoft Edge hides quick links on the new tab page and disables the quick links control in the NTP settings flyout. This policy only applies for Microsoft Edge local user profiles, profiles signed in using a Microsoft Account, and profiles signed in using Active Directory. To configure the Enterprise new tab page for profiles signed in using Azure Active Directory, use the M365 admin portal. Related policies: 'NewTabPageAllowedBackgroundTypes' (Configure the background types allowed for the new tab page layout), 'NewTabPageContentEnabled' (Allow Microsoft content on the new tab page)
RestoreOnStartupUserURLsEnabled Allow users to add and remove their own sites during startup when the RestoreOnStartupURLs policy is configured.
If you disable or don't configure this policy, there's no change to how the 'RestoreOnStartup' and RestoreOnStartupURLs policies work.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- RestoreOnStartupUserURLsEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 107, Windows 7 or later
- Template
- msedge.admx
This policy only works if you set the 'RestoreOnStartup' (Action to take on Microsoft Edge startup) policy to 'Open a list of URLs' (4) and the RestoreOnStartupURLs policy as mandatory. If you enable this policy, users are allowed to add and remove their own URLs to open when starting Microsoft Edge while maintaining the admin specified mandatory list of sites specified by setting 'RestoreOnStartup' policy to open a list of URLS and providing the list of sites in the RestoreOnStartupURLs policy. If you disable or don't configure this policy, there's no change to how the 'RestoreOnStartup' and RestoreOnStartupURLs policies work.
NewTabPageAllowedBackgroundTypes Configure the background types allowed for the new tab page layout
If you don't configure this policy, all background image types on the new tab page are enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NewTabPageAllowedBackgroundTypes
- Supported on
- Microsoft Edge version 86, Windows 7 or later
- Template
- msedge.admx
1Disable daily background image type2Disable custom background image type3Disable all background image typesYou can configure which types of background image that are allowed on the new tab page layout in Microsoft Edge. If you don't configure this policy, all background image types on the new tab page are enabled. Policy options mapping: * DisableImageOfTheDay (1) = Disable daily background image type * DisableCustomImage (2) = Disable custom background image type * DisableAll (3) = Disable all background image types Use the preceding information when configuring this policy.
HomepageLocation Configure the home page URL
If you disable or don't configure this policy, users can choose their own home page, as long as the 'HomepageIsNewTabPage' policy isn't enabled.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- HomepageLocation
- Stated default
- By default, the Home button opens the new tab page (as configured by the user or with the policy 'NewTabPageLocation' (Configure the new tab page URL)), and the user is able to choose between the URL configured by this policy and the new tab page.
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Configures the default home page URL in Microsoft Edge. The home page is the page opened by the Home button. 'RestoreOnStartup' (Action to take on Microsoft Edge startup) policies control the pages that open on startup. You can either set a URL here or set the home page to open the new tab page 'edge://newtab'. By default, the Home button opens the new tab page (as configured by the user or with the policy 'NewTabPageLocation' (Configure the new tab page URL)), and the user is able to choose between the URL configured by this policy and the new tab page. If you enable this policy, users can't change their home page URL, but they can choose the behavior for the Home button to open either the set URL or the new tab page. If you wish to enforce the usage of the set URL, you must also configure 'HomepageIsNewTabPage' (Set the new tab page as the home page)=Disabled. If you disable or don't configure this policy, users can choose their own home page, as long as the 'HomepageIsNewTabPage' policy isn't enabled. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX. Example value: https://www.contoso.com
NewTabPageSetFeedType Configure the Microsoft Edge new tab page experience (obsolete)
If you disable or don't configure this policy, users with an Azure Active Directory browser sign-in are offered the Office 365 new tab page feed experience, and the standard new tab page feed experience.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NewTabPageSetFeedType
- Supported on
- Microsoft Edge version 79-92, Windows 7 or later
- Template
- msedge.admx
0Microsoft News feed experience1Office 365 feed experienceOBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 92. This policy is obsolete because the new version of the enterprise new tab page no longer requires choosing between different content types. Instead, the content that's presented to the user can be controlled via the Microsoft 365 admin center. To get to the Microsoft 365 admin center, sign in at https://admin.microsoft.com with your admin account. Lets you choose either the Microsoft News or Office 365 feed experience for the new tab page. If you set this policy to 'News', users see the Microsoft News feed experience on the new tab page. If you set this policy to 'Office', users with an Azure Active Directory browser sign-in see the Office 365 feed experience on the new tab page. If you disable or don't configure this policy, users with an Azure Active Directory browser sign-in are offered the Office 365 new tab page feed experience, and the standard new tab page feed experience. Users without an Azure Active Directory browser sign-in to see the standard new tab page experience. If you enable this policy *and* the 'NewTabPageLocation' (Configure the new tab page URL) policy, 'NewTabPageLocation' has precedence. Policy options mapping: * News (0) = Microsoft News feed experience * Office (1) = Office 365 feed experience Use the preceding information when configuring this policy.
NewTabPageLocation Configure the new tab page URL
If you don't configure this policy, the default new tab page is used.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NewTabPageLocation
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Configures the default URL for the new tab page. The recommended version of this policy doesn't currently work and functions exactly like the mandatory version. This policy determines the page that opens when new tabs are created (including when new windows are opened). It also affects the startup page if this page opens to the new tab page. This policy doesn't determine which page opens on startup; that factor is controlled by the 'RestoreOnStartup' (Action to take on Microsoft Edge startup) policy. It also doesn't affect the home page if this home page opens to the new tab page. If you don't configure this policy, the default new tab page is used. If you configure this policy *and* the 'NewTabPageSetFeedType' (Configure the Microsoft Edge new tab page experience) policy, this policy takes precedence. If a blank tab is preferred, "about:blank" is the correct URL to use, not "about://blank". This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or joined to instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX. Example value: https://www.fabrikam.com
ConfigureNTPFeedTabVisibility Configure whether the Discover or Work feed tabs are shown on the Copilot new tab page.
If you set this policy to 'EnableBothWorkDiscover' (0) or don't configure this policy, Microsoft Edge shows both the Work and Discover feed tabs on the Copilot new tab page.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ConfigureNTPFeedTabVisibility
- Stated default
- By default, both Work and Discover tabs are enabled.
- Supported on
- Microsoft Edge version 148, Windows 7 or later
- Template
- msedge.admx
0Enable both Work and Discover tabs1Enable only Work tab2Enable only Discover tabThis policy configures whether the Discover or Work feed tabs are shown on the Copilot new tab page. By default, both Work and Discover tabs are enabled. If you set this policy to 'EnableBothWorkDiscover' (0) or don't configure this policy, Microsoft Edge shows both the Work and Discover feed tabs on the Copilot new tab page. If you set this policy to 'EnableOnlyWork' (1), Microsoft Edge shows only the Work feed tab on the Copilot new tab page. If you set this policy to 'EnableOnlyDiscover' (2), Microsoft Edge shows only the Discover feed tab on the Copilot new tab page. Policy options mapping: * EnableBothWorkDiscover (0) = Enable both Work and Discover tabs * EnableOnlyWork (1) = Enable only Work tab * EnableOnlyDiscover (2) = Enable only Discover tab Use the preceding information when configuring this policy.
NewTabPageBingChatEnabled Disable Bing chat entry-points on Microsoft Edge Enterprise new tab page
If you enable or don't configure this policy, these Bing Chat entry points continue to appear on the new tab page.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NewTabPageBingChatEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, the Microsoft Edge new tab page includes three Bing Chat entry points: one inside the search box, one in the Bing autosuggest dropdown when users select or begin typing in the box, and one as a suggested prompt below the box.
- Supported on
- Microsoft Edge version 117, Windows 7 or later
- Template
- msedge.admx
By default, the Microsoft Edge new tab page includes three Bing Chat entry points: one inside the search box, one in the Bing autosuggest dropdown when users select or begin typing in the box, and one as a suggested prompt below the box. If you enable or don't configure this policy, these Bing Chat entry points continue to appear on the new tab page. If you disable this policy, all Bing Chat entry points are removed from the new tab page.
NewTabPagePrerenderEnabled Enable preload of the new tab page for faster rendering
If you don't configure this policy, preloading is enabled and a user can change this setting.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NewTabPagePrerenderEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 85, Windows 7 or later
- Template
- msedge.admx
If you configure this policy, preloading the New tab page is enabled, and users can't change this setting. If you don't configure this policy, preloading is enabled and a user can change this setting.
NewTabPageAppLauncherEnabled Hide App Launcher on Microsoft Edge new tab page
If you enable or don't configure this policy, there's no change on the Microsoft Edge new tab page and App Launcher is there for users.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NewTabPageAppLauncherEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, the App Launcher is shown every time a user opens a new tab page.
- Supported on
- Microsoft Edge version 108, Windows 7 or later
- Template
- msedge.admx
By default, the App Launcher is shown every time a user opens a new tab page. If you enable or don't configure this policy, there's no change on the Microsoft Edge new tab page and App Launcher is there for users. If you disable this policy, App Launcher doesn't appear and users can't launch Microsoft 365 apps from Microsoft Edge new tab page via the App Launcher.
NewTabPageCompanyLogoEnabled Hide the company logo on the Microsoft Edge new tab page
If you enable or don't configure this policy, there's no change on the Microsoft Edge new tab page and the company logo is there for users.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NewTabPageCompanyLogoEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- By default, the company logo is shown on the new tab page if the company logo is configured in Admin Portal.
- Supported on
- Microsoft Edge version 117, Windows 7 or later
- Template
- msedge.admx
By default, the company logo is shown on the new tab page if the company logo is configured in Admin Portal. If you enable or don't configure this policy, there's no change on the Microsoft Edge new tab page and the company logo is there for users. If you disable this policy, the company logo doesn't appear on Microsoft Edge new tab page.
NewTabPageHideDefaultTopSites Hide the default top sites from the new tab page
If you set this policy to false or don't configure it, the default top site tiles remain visible.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NewTabPageHideDefaultTopSites
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Hides the default top sites from the new tab page in Microsoft Edge. If you set this policy to true, the default top site tiles are hidden. If you set this policy to false or don't configure it, the default top site tiles remain visible.
NewTabPageCompanyLogo Set new tab page company logo (obsolete)
If you disable or don't configure this policy, Microsoft Edge shows no company logo or a Microsoft logo on the new tab page.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NewTabPageCompanyLogo
- Supported on
- Microsoft Edge version 79-85, Windows 7 or later
- Template
- msedge.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 85. This policy didn't work as expected due to changes in operational requirements. Therefore, it's obsolete and shouldn't be used. Specifies the company logo that's to be used on the new tab page in Microsoft Edge. The policy should be configured as a string that expresses the logo(s) in JSON format. For example: { "default_logo": { "url": "https://www.contoso.com/logo.png", "hash": "cd0aa9856147b6c5b4ff2b7dfee5da20aa38253099ef1b4a64aced233c9afe29" }, "light_logo": { "url": "https://www.contoso.com/light_logo.png", "hash": "517d286edb416bb2625ccfcba9de78296e90da8e32330d4c9c8275c4c1c33737" } } You configure this policy by specifying the URL from which Microsoft Edge can download the logo and its cryptographic hash (SHA-256), which is used to verify the integrity of the download. The logo must be in PNG or SVG format, and its file size must not exceed 16 MB. The logo is downloaded and cached, and it will be redownloaded whenever the URL or the hash changes. The URL must be accessible without any authentication. The 'default_logo' is required and used when there's no background image. If 'light_logo' is provided, it's used when the user's new tab page has a background image. We recommend a horizontal logo with a transparent background that's left-aligned and vertically centered. The logo should have a minimum height of 32 pixels and an aspect ratio from 1:1 to 4:1. The 'default_logo' should have proper contrast against a white/black background, while the 'light_logo' should have proper contrast against a background image. If you enable this policy, Microsoft Edge downloads and shows the specified logo(s) on the new tab page. Users can't override or hide the logo(s). If you disable or don't configure this policy, Microsoft Edge shows no company logo or a Microsoft logo on the new tab page. For help with determining the SHA-256 hash, see [Get-FileHash](/powershell/module/microsoft.powershell.utility/get-filehash). Example value: { "default_logo": { "hash": "cd0aa9856147b6c5b4ff2b7dfee5da20aa38253099ef1b4a64aced233c9afe29", "url": "https://www.contoso.com/logo.png" }, "light_logo": { "hash": "517d286edb416bb2625ccfcba9de78296e90da8e32330d4c9c8275c4c1c33737", "url": "https://www.contoso.com/light_logo.png" } } Compact example value: {"default_logo": {"hash": "cd0aa9856147b6c5b4ff2b7dfee5da20aa38253099ef1b4a64aced233c9afe29", "url": "https://www.contoso.com/logo.png"}, "light_logo": {"hash": "517d286edb416bb2625ccfcba9de78296e90da8e32330d4c9c8275c4c1c33737", "url": "https://www.contoso.com/light_logo.png"}}
NewTabPageManagedQuickLinks Set new tab page quick links
By default, Microsoft Edge displays quick links on the new tab page from user-added shortcuts and top sites based on browsing history.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NewTabPageManagedQuickLinks
- Supported on
- Microsoft Edge version 79, Windows 7 or later
- Template
- msedge.admx
By default, Microsoft Edge displays quick links on the new tab page from user-added shortcuts and top sites based on browsing history. With this policy, you can configure up to three quick link tiles on the new tab page, expressed as a JSON object: [ { "url": "https://www.contoso.com", "title": "Contoso Portal", "pinned": true/false }, ... ] The 'url' field is required; 'title' and 'pinned' are optional. If 'title' isn't provided, the URL is used as the default title. If 'pinned' isn't provided, the default value is false. Microsoft Edge presents these tiles in the order listed, from left to right, with all pinned tiles displayed ahead of nonpinned tiles. If you set this policy as mandatory, the 'pinned' field is ignored and all tiles are pinned. The tiles can't be deleted by the user and always appear at the front of the quick links list. If you set this policy as recommended, pinned tiles remain in the list but the user has the ability to edit and delete them. Quick link tiles that aren't pinned behave like default top sites and are pushed off the list if other websites are visited more frequently. When applying nonpinned links via this policy to an existing browser profile, the links don't appear at all, depending on how they rank compared to the user's browsing history. Example value: [ { "pinned": true, "title": "Contoso Portal", "url": "https://contoso.com" }, { "title": "Fabrikam", "url": "https://fabrikam.com" } ]
NewTabPageCompanyLogoBackplateColor Set the company logo backplate color on the new tab page.
If this policy isn't configured, the default neutralStrokeActive (#cecece) color is used as the backplate color.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- NewTabPageCompanyLogoBackplateColor
- Stated default
- By default, the new tab page sets the company logo backplate color to the neutralStrokeActive (#cecece) constant.
- Supported on
- Microsoft Edge version 135, Windows 7 or later
- Template
- msedge.admx
By default, the new tab page sets the company logo backplate color to the neutralStrokeActive (#cecece) constant. You can configure this policy with a color hex code to change the company logo backplate color on the new tab page. If this policy isn't configured, the default neutralStrokeActive (#cecece) color is used as the backplate color. Example value: #cecece
SetNTPDefaultFeedTab Set the default Copilot new tab page feed tab to Work or Discover
If you set this policy to 'Work' (0) or don't configure this policy, Microsoft Edge sets the default feed tab to Work. ) is set to 'EnableBothWorkDiscover' (0) or isn't configured.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- SetNTPDefaultFeedTab
- Supported on
- Microsoft Edge version 148, Windows 7 or later
- Template
- msedge.admx
0Work1DiscoverThis policy sets the default feed tab on the Copilot new tab page to Work or Discover. If you set this policy to 'Work' (0) or don't configure this policy, Microsoft Edge sets the default feed tab to Work. If you set this policy to 'Discover' (1), Microsoft Edge sets the default feed tab to Discover. This policy only takes effect when 'ConfigureNTPFeedTabVisibility' (Configure whether the Discover or Work feed tabs are shown on the Copilot new tab page.) is set to 'EnableBothWorkDiscover' (0) or isn't configured. If only one feed tab is visible, this policy has no effect. Policy options mapping: * NTPDefaultFeedTabWork (0) = Work * NTPDefaultFeedTabDiscover (1) = Discover Use the preceding information when configuring this policy.
HomepageIsNewTabPage Set the new tab page as the home page
If you don't configure this policy, users can choose whether the set URL or the new tab page is their home page.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- HomepageIsNewTabPage
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Configures the default home page in Microsoft Edge. You can set the home page to a URL you specify or to the new tab page. If you enable this policy, the Home button is set to the new tab page as configured by the user or with the policy 'NewTabPageLocation' (Configure the new tab page URL) and the URL set with the policy 'HomepageLocation' (Configure the home page URL) is not taken into consideration. If you disable this policy, the Home button is the set URL as configured by the user or as configured in the policy 'HomepageLocation'. If you don't configure this policy, users can choose whether the set URL or the new tab page is their home page. This policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.
ShowHomeButton Show Home button on toolbar
If you don't configure the policy, users can choose whether to show the home button.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- ShowHomeButton
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Shows the Home button on Microsoft Edge's toolbar. Enable this policy to always show the Home button. Disable it to never show the button. If you don't configure the policy, users can choose whether to show the home button.
RestoreOnStartupURLs Sites to open when the browser starts
If you don't configure this policy, no site is opened on startup.
- Registry key
- Software\Policies\Microsoft\Edge
- List subkey
- Software\Policies\Microsoft\Edge\RestoreOnStartupURLs
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Specify a list of websites to open automatically when the browser starts. If you don't configure this policy, no site is opened on startup. This policy only works if you also set the 'RestoreOnStartup' (Action to take on Microsoft Edge startup) policy to 'Open a list of URLs' (4). This policy is available only on specific Windows instances. These instances include devices that are joined to a Microsoft Active Directory domain, devices joined to Microsoft Azure Active Directory`, or devices enrolled for device management. Example value: https://contoso.com https://www.fabrikam.com
Microsoft Edge / WebRtc settings
WebRtcPostQuantumKeyAgreement Enable post-quantum key agreement for WebRTC
If you don't configure this policy, post-quantum key agreement won't be offered for WebRTC.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebRtcPostQuantumKeyAgreement
- Enabled / Disabled
- 1 / 0
- Stated default
- A future version of Microsoft Edge may enable this feature by default.
- Supported on
- Microsoft Edge version 141, Windows 7 or later
- Template
- msedge.admx
This policy controls the use of post-quantum key agreement for WebRTC in Microsoft Edge. If you enable this policy, Microsoft Edge will offer post-quantum key agreement for WebRTC. If you disable this policy, post-quantum key agreement won't be offered for WebRTC. If you don't configure this policy, post-quantum key agreement won't be offered for WebRTC. A future version of Microsoft Edge may enable this feature by default. Offering a post-quantum key agreement is backwards compatible. Existing datagram transport layer security (DTLS) peers and networking middleware are expected to ignore the new option and continue using previous options. However, devices that don't correctly implement DTLS may malfunction when offered the new option. For example, they may disconnect in response to unrecognized options or larger message sizes. Such devices aren’t post-quantum-ready and may interfere with an organization's post-quantum transition. If this issue occurs, administrators should contact the device vendor for a fix. This policy is temporary and will be removed in a future release.
WebRtcLocalhostIpHandling Restrict exposure of local IP address by WebRTC
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebRtcLocalhostIpHandling
- Supported on
- Microsoft Edge version 77, Windows 7 or later
- Template
- msedge.admx
Allow all interfaces. This exposes the local IP addressAllow public and private interfaces over http default route. This exposes the local IP addressAllow public interface over http default route. This doesn't expose the local IP addressUse TCP unless proxy server supports UDP. This doesn't expose the local IP addressAllows you to set whether or not WebRTC exposes the user's local IP address. If you set this policy to "AllowAllInterfaces" or "AllowPublicAndPrivateInterfaces", WebRTC exposes the local IP address. If you set this policy to "AllowPublicInterfaceOnly" or "DisableNonProxiedUdp", WebRTC doesn't expose the local IP address. If you don't set this policy, or if you disable it, WebRTC exposes the local IP address. Note that this policy doesn't provide an option to exclude specific domains. Policy options mapping: * AllowAllInterfaces (default) = Allow all interfaces. This exposes the local IP address * AllowPublicAndPrivateInterfaces (default_public_and_private_interfaces) = Allow public and private interfaces over http default route. This exposes the local IP address * AllowPublicInterfaceOnly (default_public_interface_only) = Allow public interface over http default route. This doesn't expose the local IP address * DisableNonProxiedUdp (disable_non_proxied_udp) = Use TCP unless proxy server supports UDP. This doesn't expose the local IP address Use the preceding information when configuring this policy. Example value: default
WebRtcIPHandlingUrl WebRTC IP Handling Policy for URL Patterns
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge
- Value name
- WebRtcIPHandlingUrl
- Supported on
- Microsoft Edge version 135, Windows 7 or later
- Template
- msedge.admx
Controls which IP addresses and network interfaces WebRTC can use when establishing connections for specific URL patterns. How It Works: Accepts a list of URL patterns, each paired with a handling type. WebRTC evaluates patterns sequentially; the first match determines the handling type. If no match is found, WebRTC defaults to the WebRtcLocalhostIpHandling WebRtcLocalhostIpHandling. policy. This policy applies only to origins—URL path components are ignored. Wildcards (*) are supported in URL patterns. Supported Handling Values: default – Uses all available network interfaces. default_public_and_private_interfaces – WebRTC uses all public and private interfaces. default_public_interface_only – WebRTC uses only public interfaces. disable_non_proxied_udp – WebRTC uses UDP SOCKS proxying or falls back to TCP proxying. More Information: Valid input patterns: https://go.microsoft.com/fwlink/?linkid=2095322 Handling types: https://tools.ietf.org/html/rfc8828.html#section-5.2 Example value: [ { "url": "https://www.example.com", "handling": "default_public_and_private_interfaces" }, { "url": "https://[*.]example.edu", "handling": "default_public_interface_only" }, { "url": "*", "handling": "disable_non_proxied_udp" } ]
Microsoft Edge Update
UpdaterExperimentationAndConfigurationServiceControl Control updater's communication with the Experimentation and Configuration Service
If you don't configure this policy, on a managed device the behavior is same as policy 'disabled'. If you don't configure this policy, on an unmanaged device the behavior is same as policy 'enabled'.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- UpdaterExperimentationAndConfigurationServiceControl
- List subkey
- Software\Policies\Microsoft\EdgeUpdate
- Supported on
- Microsoft Edge Update 1.3.145.1 and later
- Template
- msedgeupdate.admx
0Disable communication with the Experimentation and Configuration Service1Enable communication and download experimentsIn Microsoft Edge Update, the Experimentation and Configuration Service is used to deploy experimentation payload. Experimentation payload consists of a list of early in development features that Microsoft is enabling for testing and feedback. If you enable (1) this policy, experimentation payload is downloaded from the Experimentation and Configuration Service. If you disable (0) this policy, communication with the Experimentation and Configuration Service is stopped completely. If you don't configure this policy, on a managed device the behavior is same as policy 'disabled'. If you don't configure this policy, on an unmanaged device the behavior is same as policy 'enabled'.
Microsoft Edge Update / Applications
InstallDefault Allow installation default
This only affects the installation of Microsoft Edge software when the 'Allow installation' policy is set to Not Configured.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- InstallDefault
- List subkey
- Software\Policies\Microsoft\EdgeUpdate
- Supported on
- Microsoft Edge Update 1.2.145.5 and later
- Template
- msedgeupdate.admx
1Always allow Installs (recommended)0Installs disabledYou can specify the default behavior of all channels to allow or block Microsoft Edge on domain-joined devices. You can override this policy for individual channels by enabling (1) the 'Allow installation' policy for specific channels. If you disable (2) this policy, the installation of Microsoft Edge is blocked. This only affects the installation of Microsoft Edge software when the 'Allow installation' policy is set to Not Configured. This policy doesn't prevent Microsoft Edge Update from running or prevent users from installing Microsoft Edge software using other methods. This policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.
Allowsxs Allow Microsoft Edge Side by Side browser experience
If this policy is set to “Not configured”, Microsoft Edge (Chromium-based) will replace Microsoft Edge (Edge HTML) after the Microsoft Edge (Chromium-based) stable channel and the November 2019 security updates are installed. This is the same behavior as the “Not Configured” setting.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- Allowsxs
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge Update 1.2.145.5 and later
- Template
- msedgeupdate.admx
This policy lets a user run Microsoft Edge (Edge HTML) and Microsoft Edge (Chromium-based) side-by-side. If this policy is set to “Not configured”, Microsoft Edge (Chromium-based) will replace Microsoft Edge (Edge HTML) after the Microsoft Edge (Chromium-based) stable channel and the November 2019 security updates are installed. This is the same behavior as the “Disabled” setting. The “Disabled” (0) setting blocks a side-by-side experience and Microsoft Edge (Chromium-based) will replace Microsoft Edge (Edge HTML) after the Microsoft Edge (Chromium-based) stable channel and the November 2019 security updates are installed. This is the same behavior as the “Not Configured” setting. When this policy is “Enabled” (1), Microsoft Edge (Chromium-based) and Microsoft Edge (Edge HTML) can run side-by-side after Microsoft Edge (Chromium-based) is installed. For this group policy to take affect, it must be configured before the automatic install of Microsoft Edge (Chromium-based) by Windows Update. Note: A user can block the automatic update of Microsoft Edge (Chromium-based) by using the Microsoft Edge (Chromium-based) Blocker Toolkit. Starting with Windows 10 version 20H2 Microsoft Edge Legacy and the side-by-side browser experience are not supported.
CreateDesktopShortcutDefault Create Desktop Shortcut upon install default
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- CreateDesktopShortcutDefault
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge Update 1.3.128.0 and later
- Template
- msedgeupdate.admx
Lets you specify the default behavior for all channels for creating a desktop shortcut when Microsoft Edge is installed. If you enable (1) this policy a desktop shortcut is created when Microsoft Edge is installed. If you disable (0) this policy, no desktop shortcut will be created when Microsoft Edge is installed. If you don’t configure this policy a desktop shortcut to Microsoft Edge will be created during installation. If Microsoft Edge is already installed, this policy will have no effect.
MeteredUpdatesDefault Let users update all apps on metered connections
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- MeteredUpdatesDefault
- Supported on
- Microsoft Edge Update 1.3.179.5 and later
- Template
- msedgeupdate.admx
1Default Metered Updates Disabled2Default Metered Updates AllowedSpecifies whether Microsoft Edge Update will update on connections marked as metered, such as cellular connections or others where data usage is controlled for all apps. If you don't enable and configure this policy, updates occur based the 'Download Updates over metered connections' toggle in the About Page of the Microsoft Edge browser. If a user doesn't make a choice, the Windows setting is used. You can find out more about the Windows setting here: https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-update#allowautowindowsupdatedownloadovermeterednetwork Always allow updates (2): Updates are always downloaded when found, either by automatic update check or by a manual update check. Updates disabled (1): Updates are not downloaded when using a metered connection.
RemoveDesktopShortcutDefault Remove Desktop Shortcuts upon update default
If you don't configure this policy or disable it (0), nothing will happen to existing Microsoft Edge desktop shortcuts.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- RemoveDesktopShortcutDefault
- List subkey
- Software\Policies\Microsoft\EdgeUpdate
- Supported on
- Microsoft Edge Update 1.3.155.1 and later
- Template
- msedgeupdate.admx
1Force delete system-level Desktop Shortcuts2Force delete system-level and user-level Desktop Shortcuts0Prevent Desktop Shortcut creation on installLets you specify the default behavior for all channels for creating a desktop shortcut when Microsoft Edge is installed. If you set this policy to "Force delete system-level Desktop Shortcuts" (1), any existing system-level Microsoft Edge desktop shortcuts will be deleted when the browser updates or the machine reboots. If you set this policy to "Force delete system-level and user-level Desktop Shortcuts" (2), any existing system-level Microsoft Edge desktop shortcuts will be deleted when the browser updates or the machine reboots and any existing user-level desktop shortcuts will be deleted when the browser updates. This includes user-level desktop shortcuts that users might have made themselves. If you don't configure this policy or disable it (0), nothing will happen to existing Microsoft Edge desktop shortcuts.
UpdateDefault Update policy override default
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- UpdateDefault
- List subkey
- Software\Policies\Microsoft\EdgeUpdate
- Supported on
- Microsoft Edge Update 1.2.145.5 and later
- Template
- msedgeupdate.admx
1Always allow updates (recommended)2Manual updates only3Automatic silent updates only0Updates disabledLets you specify the default behavior for all channels concerning the way Microsoft Edge Update handles available updates for Microsoft Edge. Can be overridden for individual channels by specifying the 'Update policy override' policy for those specific channels. If you enable this policy, Microsoft Edge Update handles Microsoft Edge updates according to how you configure the following options: - Updates disabled (0): Updates are never applied. - Always allow updates (1) (recommended): Updates are always applied when found, either by periodic update check or by a manual update check. - Manual updates only (2): Updates are applied only when the user runs a manual update check. - Automatic silent updates only (3): Updates are applied only when they're found by the periodic update check. If you select manual updates, make sure you periodically check for updates by using the app's manual update mechanism, if available. If you disable updates, periodically check for updates, and distribute them to users. If you don't enable and configure this policy, Microsoft Edge Update handles available updates as specified by the 'Update policy override' policy. This policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.
Microsoft Edge Update / Applications / Microsoft Edge
Install{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} Allow installation
If you don't configure this policy for a channel, the 'Allow installation default' policy configuration determines whether users can install that channel of Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- Install{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
- Supported on
- Microsoft Edge Update 1.2.145.5 and later
- Template
- msedgeupdate.admx
1Always allow Installs (recommended)0Installs disabled5Force Installs (Machine-Wide)4Always allow Machine-Wide Installs, but not Per-User Installs6Force Installs (Per-User)Specifies whether a Microsoft Edge channel can be installed on domain-joined devices. If you enable (1) this policy for a channel, Microsoft Edge will not be blocked from installation. If you disable (0) this policy for a channel (or set it to 'Installs disabled'), Microsoft Edge will be blocked from installation. If you don't configure this policy for a channel, the 'Allow installation default' policy configuration determines whether users can install that channel of Microsoft Edge. If you set this policy to Always allow Machine-Wide Installs but not Per-User Installs (4), Microsoft Edge will only be deployed machine-wide. If you set this policy to Force Installs (Machine-Wide) (5), Microsoft Edge may only be deployed machine-wide if Microsoft Edge Update is pre-installed. Requires Microsoft Edge Update 1.3.155.43 or higher. If you set this policy to Force Installs (Per-User) (6), Microsoft Edge may only be deployed on a Per-User basis to all machines if Microsoft Edge Update is pre-installed Per-User. Requires Microsoft Edge Update 1.3.155.43 or higher. This policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.
EdgePreview{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} Allow users in the Windows Insider Program to be enrolled in Edge Preview
- If you don't configure this policy, users in the Windows Insider Program are enrolled in Edge Preview via Microsoft Edge Update by default.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- EdgePreview{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge Update 1.3.168.21 and later
- Template
- msedgeupdate.admx
Lets you specify whether users in the Windows Insider Program are enrolled in Edge Preview via Microsoft Edge Update. - If you enable (1) this policy, users in the Windows Insider Program are enrolled in Edge Preview via Microsoft Edge Update. - If you disable (0) this policy, users in the Windows Insider Program cannot be enrolled in Edge Preview via Microsoft Edge Update. - If you don't configure this policy, users in the Windows Insider Program are enrolled in Edge Preview via Microsoft Edge Update by default.
CreateDesktopShortcut{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} Create Desktop Shortcut upon install
If you don't configure this policy for a channel, the 'Create Desktop Shortcut upon install default' policy configuration determines shortcut creation when Microsoft Edge is installed.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- CreateDesktopShortcut{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge Update 1.3.128.0 and later
- Template
- msedgeupdate.admx
If you enable (1) this policy a desktop shortcut is created when Microsoft Edge is installed. If you disable (0) this policy, no desktop shortcut will be created when Microsoft Edge is installed. If you don’t configure this policy a desktop shortcut to Microsoft Edge will be created during installation. If Microsoft Edge is already installed, this policy will have no effect. If you don't configure this policy for a channel, the 'Create Desktop Shortcut upon install default' policy configuration determines shortcut creation when Microsoft Edge is installed.
EdgePreviewEnrollmentType{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} Edge preview enrollment type
If you set this policy to Allow Opt-out (1) or don't configure it, the channel in the Edge Stable application will be determined by TargetChannel.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- EdgePreviewEnrollmentType{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
- List subkey
- Software\Policies\Microsoft\EdgeUpdate
- Supported on
- Microsoft Edge Update 1.3.221.3 and later
- Template
- msedgeupdate.admx
1Allow Opt-out3RequiredSpecifies how a device is enrolled in Edge Preview. This policy is only effective if the TargetChannel policy is set to Beta or Dev. If you set this policy to Allow Opt-out (1) or don't configure it, the channel in the Edge Stable application will be determined by TargetChannel. End users will be able to exit the Edge Preview experience, to return to the Stable channel, at any time. If you set this policy to Required (3), the channel within the Edge Stable application is determined by TargetChannel. End users won't be able to leave the Edge Preview experience. This policy is available on Microsoft Edge version 143.0.3650.66 or later, and applies only to Windows devices joined to a Microsoft® Active Directory® domain. For more details, see: https://go.microsoft.com/fwlink/?linkid=2348937.
MeteredUpdates{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} Let users update on metered connections
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- MeteredUpdates{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
- Supported on
- Microsoft Edge Update 1.3.179.5 and later
- Template
- msedgeupdate.admx
1Metered Disable updates2Metered Updates AllowedSpecifies whether Microsoft Edge Update will update on connections marked as metered, such as cellular connections or others where data usage is controlled for the Microsoft Edge browser. If you don't enable and configure this policy, updates occur based the 'Download Updates over metered connections' toggle in the About Page of the Microsoft Edge browser. If a user doesn't make a choice, the Windows setting is used. You can find out more about the Windows setting here: https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-update#allowautowindowsupdatedownloadovermeterednetwork Always allow updates (2): Updates are always downloaded when found, either by automatic update check or by a manual update check. Disable updates (1): Updates are not downloaded when using a metered connection.
RemoveDesktopShortcut{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} Remove Desktop Shortcuts upon update
If you don't configure this policy or disable it (0), nothing will happen to existing Microsoft Edge desktop shortcuts. If you don't configure this policy for a channel, the 'Remove Desktop Shortcuts upon update default' policy configuration determines desktop shortcut removal.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- RemoveDesktopShortcut{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
- List subkey
- Software\Policies\Microsoft\EdgeUpdate
- Supported on
- Microsoft Edge Update 1.3.155.1 and later
- Template
- msedgeupdate.admx
1Force delete system-level Desktop Shortcuts2Force delete system-level and user-level Desktop Shortcuts0Prevent Desktop Shortcut creation on installIf you set this policy to "Force delete system-level Desktop Shortcuts" (1), any existing system-level Microsoft Edge desktop shortcuts will be deleted when the browser updates or the machine reboots. If you set this policy to "Force delete system-level and user-level Desktop Shortcuts" (2), any existing system-level Microsoft Edge desktop shortcuts will be deleted when the browser updates or the machine reboots and any existing user-level desktop shortcuts will be deleted when the browser updates. This includes user-level desktop shortcuts that users might have made themselves. If you don't configure this policy or disable it (0), nothing will happen to existing Microsoft Edge desktop shortcuts. If you don't configure this policy for a channel, the 'Remove Desktop Shortcuts upon update default' policy configuration determines desktop shortcut removal.
RollbackToTargetVersion{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} Rollback to Target version
If you disable (0) this policy or don't configure it, installs that have a version higher than that specified by 'Target version override' will be left as-is.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- RollbackToTargetVersion{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge Update 1.3.133.3 and later
- Template
- msedgeupdate.admx
Specifies that Microsoft Edge Update should rollback installations of Microsoft Edge to the version indicated in 'Target version override'. This policy has no effect unless 'Target version override' is set and 'Update policy override' is set to one of the ON states (Always allow updates, Automatic silent updates only, Manual updates only). If you disable (0) this policy or don't configure it, installs that have a version higher than that specified by 'Target version override' will be left as-is. If you enable (1) this policy, installs that have a current version higher than specified by the 'Target version override' will be downgraded to the target version. We recommend that users install the latest version of the Microsoft Edge browser to ensure protection by the latest security updates. Rollback to an earlier version risks exposure to known security issues. This policy is meant to be used as a temporary fix to address issues in a Microsoft Edge browser update. Before temporarily rolling back your browser version, we recommend that you turn on Sync (https://go.microsoft.com/fwlink/?linkid=2133032) for all users in your organization. If you don't turn on Sync, there is a risk of permanent browsing data loss. Use this policy at your own risk. Note: All versions available for rollback can be viewed here https://aka.ms/EdgeEnterprise. This policy applies to Microsoft Edge version 86 or later. See https://go.microsoft.com/fwlink/?linkid=2133918 for more information. This policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.
Uninstall{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} Specify uninstall behavior for Microsoft Edge
If the policy is 'Not configured' (default setting), a user's Windows region setting determines whether they can uninstall Microsoft Edge on a domain-joined device.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- Uninstall{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
- Supported on
- Microsoft Edge Update 1.3.193.5 and later
- Template
- msedgeupdate.admx
1Enabled2Enabled and delete user data3Disabled0Not ConfiguredYou can specify whether Microsoft Edge (stable channel) is uninstalled, or is blocked from being uninstalled, on domain-joined devices in the European Economic Area (EEA). If this policy is set to 'Enabled', Microsoft Edge will be automatically uninstalled on all devices in the EEA where this policy is deployed. User data will be kept on the device. Microsoft Edge will be uninstalled the next time Microsoft Edge Update automatically checks for updates. If Microsoft Edge is uninstalled from the devices, applications, widgets (for example, News, Search, and Weather) or any other Progressive Web Applications (PWAs) that depend on Microsoft Edge will no longer be available. If this policy is set to 'Enabled and delete user data' (Setting '2'), Microsoft Edge will be automatically uninstalled on all devices in the EEA where this policy is deployed, and user data will be deleted from the device. If this policy is set to 'Disabled' (Setting '3'), all users in the EEA are prevented from uninstalling Microsoft Edge where this policy is deployed. If the policy is 'Not configured' (default setting), a user's Windows region setting determines whether they can uninstall Microsoft Edge on a domain-joined device. Only users in EEA countries will be able to uninstall Microsoft Edge if they choose to do so. Users outside of this area will not be able to uninstall Microsoft Edge. This policy is available only on Home, Pro, Pro Education, Pro for Workstations, Enterprise, Education, and Enterprise multi-session editions of Windows 10 22H2 and Windows 11 23H2 and later versions. This policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain. If Microsoft Edge needs to be reinstalled: - You can set the 'Install' Policy to Force Installs (Machine-Wide) to reinstall Microsoft Edge. - If you set the Install policy to Force Installs (Machine-Wide), and also set the Uninstall policy to Enabled, the Force Installs (Machine-Wide) policy will override the Uninstall policy.
TargetChannel{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} Target Channel override
If you disable or don't configure this policy, Microsoft Edge will update to the latest version available for the default channel.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- TargetChannel{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
- List subkey
- Software\Policies\Microsoft\EdgeUpdate
- Supported on
- Microsoft Edge Update 1.3.147.1 and later
- Template
- msedgeupdate.admx
StableBetaDevExtended StableSpecifies which Microsoft Edge update channel to use This policy controls which update channel Microsoft Edge will follow. If you enable this policy, Microsoft Edge will be updated to the channel you configure: - Stable: Updated to the latest stable version. - Beta: Updated to the latest beta version. - Dev: Updated to the latest dev version. - Extended Stable: Updated to the latest extended stable version, which follows a longer release cadence than Stable. For more information, visit https://go.microsoft.com/fwlink/?linkid=2163508. If you disable or don't configure this policy, Microsoft Edge will update to the latest version available for the default channel. This policy is supported only on Windows devices that are joined to a Microsoft® Active Directory® domain.
TargetVersionPrefix{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} Target version override
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- TargetVersionPrefix{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
- Supported on
- Microsoft Edge Update 1.3.119.43 and later
- Template
- msedgeupdate.admx
When this policy is enabled, and auto-update is enabled, Microsoft Edge will be updated to the version specified by this policy value. The policy value must be a specific Microsoft Edge version, e.g. 83.0.499.12. If a device has newer version of Microsoft Edge than the value specified, Microsoft Edge will remain on the newer version and not downgrade to the specified version. If the specified version does not exist, or is improperly formatted, then Microsoft Edge will remain on its current version and not update to future versions automatically. See https://go.microsoft.com/fwlink/?linkid=2136707 for more information. This policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.
Update{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} Update policy override
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- Update{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
- Supported on
- Microsoft Edge Update 1.2.145.5 and later
- Template
- msedgeupdate.admx
1Always allow updates (recommended)2Manual updates only3Automatic silent updates only0Updates disabledSpecifies how Microsoft Edge Update handles available updates from Microsoft Edge. If you enable this policy, Microsoft Edge Update handles Microsoft Edge updates according to how you configure the following options: - Updates disabled (0): Updates are never applied. - Always allow updates (1) (Recommended): Updates are always applied when found, either by periodic update check or by a manual update check. - Manual updates only (2): Updates are applied only when the user runs a manual update check. (Not all apps provide an interface for this option.) - Automatic silent updates only (3): Updates are applied only when they're found by the periodic update check. If you select manual updates, make sure you periodically check for updates by using the app's manual update mechanism, if available. If you disable updates, periodically check for updates, and distribute them to users. If you don't enable and configure this policy, Microsoft Edge Update handles available updates as specified by the 'Update policy override default' policy. See https://go.microsoft.com/fwlink/?linkid=2136406 for more information. This policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.
Microsoft Edge Update / Applications / Microsoft Edge Beta
Install{2CD8A007-E189-409D-A2C8-9AF4EF3C72AA} Allow installation
If you don't configure this policy for a channel, the 'Allow installation default' policy configuration determines whether users can install that channel of Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- Install{2CD8A007-E189-409D-A2C8-9AF4EF3C72AA}
- Supported on
- Microsoft Edge Update 1.2.145.5 and later
- Template
- msedgeupdate.admx
1Always allow Installs (recommended)0Installs disabled5Force Installs (Machine-Wide)4Always allow Machine-Wide Installs, but not Per-User Installs6Force Installs (Per-User)Specifies whether a Microsoft Edge channel can be installed on domain-joined devices. If you enable (1) this policy for a channel, Microsoft Edge will not be blocked from installation. If you disable (0) this policy for a channel (or set it to 'Installs disabled'), Microsoft Edge will be blocked from installation. If you don't configure this policy for a channel, the 'Allow installation default' policy configuration determines whether users can install that channel of Microsoft Edge. If you set this policy to Always allow Machine-Wide Installs but not Per-User Installs (4), Microsoft Edge Beta will only be deployed machine-wide. If you set this policy to Force Installs (Machine-Wide) (5), Microsoft Edge Beta may only be deployed machine-wide if Microsoft Edge Update is pre-installed. Requires Microsoft Edge Update 1.3.155.43 or higher. If you set this policy to Force Installs (Per-User) (6), Microsoft Edge Beta may only be deployed on a Per-User basis to all machines if Microsoft Edge Update is pre-installed Per-User. Requires Microsoft Edge Update 1.3.155.43 or higher. This policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.
CreateDesktopShortcut{2CD8A007-E189-409D-A2C8-9AF4EF3C72AA} Create Desktop Shortcut upon install
If you don't configure this policy for a channel, the 'Create Desktop Shortcut upon install default' policy configuration determines shortcut creation when Microsoft Edge is installed.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- CreateDesktopShortcut{2CD8A007-E189-409D-A2C8-9AF4EF3C72AA}
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge Update 1.3.128.0 and later
- Template
- msedgeupdate.admx
If you enable (1) this policy a desktop shortcut is created when Microsoft Edge is installed. If you disable (0) this policy, no desktop shortcut will be created when Microsoft Edge is installed. If you don’t configure this policy a desktop shortcut to Microsoft Edge will be created during installation. If Microsoft Edge is already installed, this policy will have no effect. If you don't configure this policy for a channel, the 'Create Desktop Shortcut upon install default' policy configuration determines shortcut creation when Microsoft Edge is installed.
MeteredUpdates{2CD8A007-E189-409D-A2C8-9AF4EF3C72AA} Let users update on metered connections
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- MeteredUpdates{2CD8A007-E189-409D-A2C8-9AF4EF3C72AA}
- Supported on
- Microsoft Edge Update 1.3.179.5 and later
- Template
- msedgeupdate.admx
1Metered Disable updates2Metered Updates AllowedSpecifies whether Microsoft Edge Update will update on connections marked as metered, such as cellular connections or others where data usage is controlled for the Microsoft Edge browser. If you don't enable and configure this policy, updates occur based the 'Download Updates over metered connections' toggle in the About Page of the Microsoft Edge browser. If a user doesn't make a choice, the Windows setting is used. You can find out more about the Windows setting here: https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-update#allowautowindowsupdatedownloadovermeterednetwork Always allow updates (2): Updates are always downloaded when found, either by automatic update check or by a manual update check. Disable updates (1): Updates are not downloaded when using a metered connection.
RemoveDesktopShortcut{2CD8A007-E189-409D-A2C8-9AF4EF3C72AA} Remove Desktop Shortcuts upon update
If you don't configure this policy or disable it (0), nothing will happen to existing Microsoft Edge desktop shortcuts. If you don't configure this policy for a channel, the 'Remove Desktop Shortcuts upon update default' policy configuration determines desktop shortcut removal.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- RemoveDesktopShortcut{2CD8A007-E189-409D-A2C8-9AF4EF3C72AA}
- List subkey
- Software\Policies\Microsoft\EdgeUpdate
- Supported on
- Microsoft Edge Update 1.3.155.1 and later
- Template
- msedgeupdate.admx
1Force delete system-level Desktop Shortcuts2Force delete system-level and user-level Desktop Shortcuts0Prevent Desktop Shortcut creation on installIf you set this policy to "Force delete system-level Desktop Shortcuts" (1), any existing system-level Microsoft Edge desktop shortcuts will be deleted when the browser updates or the machine reboots. If you set this policy to "Force delete system-level and user-level Desktop Shortcuts" (2), any existing system-level Microsoft Edge desktop shortcuts will be deleted when the browser updates or the machine reboots and any existing user-level desktop shortcuts will be deleted when the browser updates. This includes user-level desktop shortcuts that users might have made themselves. If you don't configure this policy or disable it (0), nothing will happen to existing Microsoft Edge desktop shortcuts. If you don't configure this policy for a channel, the 'Remove Desktop Shortcuts upon update default' policy configuration determines desktop shortcut removal.
RollbackToTargetVersion{2CD8A007-E189-409D-A2C8-9AF4EF3C72AA} Rollback to Target version
If you disable (0) this policy or don't configure it, installs that have a version higher than that specified by 'Target version override' will be left as-is.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- RollbackToTargetVersion{2CD8A007-E189-409D-A2C8-9AF4EF3C72AA}
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge Update 1.3.133.3 and later
- Template
- msedgeupdate.admx
Specifies that Microsoft Edge Update should rollback installations of Microsoft Edge to the version indicated in 'Target version override'. This policy has no effect unless 'Target version override' is set and 'Update policy override' is set to one of the ON states (Always allow updates, Automatic silent updates only, Manual updates only). If you disable (0) this policy or don't configure it, installs that have a version higher than that specified by 'Target version override' will be left as-is. If you enable (1) this policy, installs that have a current version higher than specified by the 'Target version override' will be downgraded to the target version. We recommend that users install the latest version of the Microsoft Edge browser to ensure protection by the latest security updates. Rollback to an earlier version risks exposure to known security issues. This policy is meant to be used as a temporary fix to address issues in a Microsoft Edge browser update. Before temporarily rolling back your browser version, we recommend that you turn on Sync (https://go.microsoft.com/fwlink/?linkid=2133032) for all users in your organization. If you don't turn on Sync, there is a risk of permanent browsing data loss. Use this policy at your own risk. Note: All versions available for rollback can be viewed here https://aka.ms/EdgeEnterprise. This policy applies to Microsoft Edge version 86 or later. See https://go.microsoft.com/fwlink/?linkid=2133918 for more information. This policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.
TargetVersionPrefix{2CD8A007-E189-409D-A2C8-9AF4EF3C72AA} Target version override
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- TargetVersionPrefix{2CD8A007-E189-409D-A2C8-9AF4EF3C72AA}
- Supported on
- Microsoft Edge Update 1.3.119.43 and later
- Template
- msedgeupdate.admx
When this policy is enabled, and auto-update is enabled, Microsoft Edge will be updated to the version specified by this policy value. The policy value must be a specific Microsoft Edge version, e.g. 83.0.499.12. If a device has newer version of Microsoft Edge than the value specified, Microsoft Edge will remain on the newer version and not downgrade to the specified version. If the specified version does not exist, or is improperly formatted, then Microsoft Edge will remain on its current version and not update to future versions automatically. See https://go.microsoft.com/fwlink/?linkid=2136707 for more information. This policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.
Update{2CD8A007-E189-409D-A2C8-9AF4EF3C72AA} Update policy override
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- Update{2CD8A007-E189-409D-A2C8-9AF4EF3C72AA}
- Supported on
- Microsoft Edge Update 1.2.145.5 and later
- Template
- msedgeupdate.admx
1Always allow updates (recommended)2Manual updates only3Automatic silent updates only0Updates disabledSpecifies how Microsoft Edge Update handles available updates from Microsoft Edge. If you enable this policy, Microsoft Edge Update handles Microsoft Edge updates according to how you configure the following options: - Updates disabled (0): Updates are never applied. - Always allow updates (1) (Recommended): Updates are always applied when found, either by periodic update check or by a manual update check. - Manual updates only (2): Updates are applied only when the user runs a manual update check. (Not all apps provide an interface for this option.) - Automatic silent updates only (3): Updates are applied only when they're found by the periodic update check. If you select manual updates, make sure you periodically check for updates by using the app's manual update mechanism, if available. If you disable updates, periodically check for updates, and distribute them to users. If you don't enable and configure this policy, Microsoft Edge Update handles available updates as specified by the 'Update policy override default' policy. See https://go.microsoft.com/fwlink/?linkid=2136406 for more information. This policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.
Microsoft Edge Update / Applications / Microsoft Edge Canary
Install{65C35B14-6C1D-4122-AC46-7148CC9D6497} Allow installation
If you don't configure this policy for a channel, the 'Allow installation default' policy configuration determines whether users can install that channel of Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- Install{65C35B14-6C1D-4122-AC46-7148CC9D6497}
- Supported on
- Microsoft Edge Update 1.2.145.5 and later
- Template
- msedgeupdate.admx
1Always allow Installs (recommended)0Installs disabled6Force Installs (Per-User)Specifies whether a Microsoft Edge channel can be installed on domain-joined devices. If you enable (1) this policy for a channel, Microsoft Edge will not be blocked from installation. If you disable (0) this policy for a channel (or set it to 'Installs disabled'), Microsoft Edge will be blocked from installation. If you don't configure this policy for a channel, the 'Allow installation default' policy configuration determines whether users can install that channel of Microsoft Edge. If you set this policy to Force Installs (Per-User) (6), Microsoft Edge Canary may only be deployed on a Per-User basis to all machines if Microsoft Edge Update is pre-installed Per-User. Requires Microsoft Edge Update 1.3.155.43 or higher. This policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.
CreateDesktopShortcut{65C35B14-6C1D-4122-AC46-7148CC9D6497} Create Desktop Shortcut upon install
If you don't configure this policy for a channel, the 'Create Desktop Shortcut upon install default' policy configuration determines shortcut creation when Microsoft Edge is installed.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- CreateDesktopShortcut{65C35B14-6C1D-4122-AC46-7148CC9D6497}
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge Update 1.3.128.0 and later
- Template
- msedgeupdate.admx
If you enable (1) this policy a desktop shortcut is created when Microsoft Edge is installed. If you disable (0) this policy, no desktop shortcut will be created when Microsoft Edge is installed. If you don’t configure this policy a desktop shortcut to Microsoft Edge will be created during installation. If Microsoft Edge is already installed, this policy will have no effect. If you don't configure this policy for a channel, the 'Create Desktop Shortcut upon install default' policy configuration determines shortcut creation when Microsoft Edge is installed.
MeteredUpdates{65C35B14-6C1D-4122-AC46-7148CC9D6497} Let users update on metered connections
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- MeteredUpdates{65C35B14-6C1D-4122-AC46-7148CC9D6497}
- Supported on
- Microsoft Edge Update 1.3.179.5 and later
- Template
- msedgeupdate.admx
1Metered Disable updates2Metered Updates AllowedSpecifies whether Microsoft Edge Update will update on connections marked as metered, such as cellular connections or others where data usage is controlled for the Microsoft Edge browser. If you don't enable and configure this policy, updates occur based the 'Download Updates over metered connections' toggle in the About Page of the Microsoft Edge browser. If a user doesn't make a choice, the Windows setting is used. You can find out more about the Windows setting here: https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-update#allowautowindowsupdatedownloadovermeterednetwork Always allow updates (2): Updates are always downloaded when found, either by automatic update check or by a manual update check. Disable updates (1): Updates are not downloaded when using a metered connection.
RemoveDesktopShortcut{65C35B14-6C1D-4122-AC46-7148CC9D6497} Remove Desktop Shortcuts upon update
If you don't configure this policy or disable it (0), nothing will happen to existing Microsoft Edge desktop shortcuts. If you don't configure this policy for a channel, the 'Remove Desktop Shortcuts upon update default' policy configuration determines desktop shortcut removal.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- RemoveDesktopShortcut{65C35B14-6C1D-4122-AC46-7148CC9D6497}
- List subkey
- Software\Policies\Microsoft\EdgeUpdate
- Supported on
- Microsoft Edge Update 1.3.155.1 and later
- Template
- msedgeupdate.admx
1Force delete system-level Desktop Shortcuts2Force delete system-level and user-level Desktop Shortcuts0Prevent Desktop Shortcut creation on installIf you set this policy to "Force delete system-level Desktop Shortcuts" (1), any existing system-level Microsoft Edge desktop shortcuts will be deleted when the browser updates or the machine reboots. If you set this policy to "Force delete system-level and user-level Desktop Shortcuts" (2), any existing system-level Microsoft Edge desktop shortcuts will be deleted when the browser updates or the machine reboots and any existing user-level desktop shortcuts will be deleted when the browser updates. This includes user-level desktop shortcuts that users might have made themselves. If you don't configure this policy or disable it (0), nothing will happen to existing Microsoft Edge desktop shortcuts. If you don't configure this policy for a channel, the 'Remove Desktop Shortcuts upon update default' policy configuration determines desktop shortcut removal.
RollbackToTargetVersion{65C35B14-6C1D-4122-AC46-7148CC9D6497} Rollback to Target version
If you disable (0) this policy or don't configure it, installs that have a version higher than that specified by 'Target version override' will be left as-is.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- RollbackToTargetVersion{65C35B14-6C1D-4122-AC46-7148CC9D6497}
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge Update 1.3.133.3 and later
- Template
- msedgeupdate.admx
Specifies that Microsoft Edge Update should rollback installations of Microsoft Edge to the version indicated in 'Target version override'. This policy has no effect unless 'Target version override' is set and 'Update policy override' is set to one of the ON states (Always allow updates, Automatic silent updates only, Manual updates only). If you disable (0) this policy or don't configure it, installs that have a version higher than that specified by 'Target version override' will be left as-is. If you enable (1) this policy, installs that have a current version higher than specified by the 'Target version override' will be downgraded to the target version. We recommend that users install the latest version of the Microsoft Edge browser to ensure protection by the latest security updates. Rollback to an earlier version risks exposure to known security issues. This policy is meant to be used as a temporary fix to address issues in a Microsoft Edge browser update. Before temporarily rolling back your browser version, we recommend that you turn on Sync (https://go.microsoft.com/fwlink/?linkid=2133032) for all users in your organization. If you don't turn on Sync, there is a risk of permanent browsing data loss. Use this policy at your own risk. Note: All versions available for rollback can be viewed here https://aka.ms/EdgeEnterprise. This policy applies to Microsoft Edge version 86 or later. See https://go.microsoft.com/fwlink/?linkid=2133918 for more information. This policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.
TargetVersionPrefix{65C35B14-6C1D-4122-AC46-7148CC9D6497} Target version override
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- TargetVersionPrefix{65C35B14-6C1D-4122-AC46-7148CC9D6497}
- Supported on
- Microsoft Edge Update 1.3.119.43 and later
- Template
- msedgeupdate.admx
When this policy is enabled, and auto-update is enabled, Microsoft Edge will be updated to the version specified by this policy value. The policy value must be a specific Microsoft Edge version, e.g. 83.0.499.12. If a device has newer version of Microsoft Edge than the value specified, Microsoft Edge will remain on the newer version and not downgrade to the specified version. If the specified version does not exist, or is improperly formatted, then Microsoft Edge will remain on its current version and not update to future versions automatically. See https://go.microsoft.com/fwlink/?linkid=2136707 for more information. This policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.
Update{65C35B14-6C1D-4122-AC46-7148CC9D6497} Update policy override
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- Update{65C35B14-6C1D-4122-AC46-7148CC9D6497}
- Supported on
- Microsoft Edge Update 1.2.145.5 and later
- Template
- msedgeupdate.admx
1Always allow updates (recommended)2Manual updates only3Automatic silent updates only0Updates disabledSpecifies how Microsoft Edge Update handles available updates from Microsoft Edge. If you enable this policy, Microsoft Edge Update handles Microsoft Edge updates according to how you configure the following options: - Updates disabled (0): Updates are never applied. - Always allow updates (1) (Recommended): Updates are always applied when found, either by periodic update check or by a manual update check. - Manual updates only (2): Updates are applied only when the user runs a manual update check. (Not all apps provide an interface for this option.) - Automatic silent updates only (3): Updates are applied only when they're found by the periodic update check. If you select manual updates, make sure you periodically check for updates by using the app's manual update mechanism, if available. If you disable updates, periodically check for updates, and distribute them to users. If you don't enable and configure this policy, Microsoft Edge Update handles available updates as specified by the 'Update policy override default' policy. See https://go.microsoft.com/fwlink/?linkid=2136406 for more information. This policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.
Microsoft Edge Update / Applications / Microsoft Edge Dev
Install{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10} Allow installation
If you don't configure this policy for a channel, the 'Allow installation default' policy configuration determines whether users can install that channel of Microsoft Edge.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- Install{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}
- Supported on
- Microsoft Edge Update 1.2.145.5 and later
- Template
- msedgeupdate.admx
1Always allow Installs (recommended)0Installs disabled5Force Installs (Machine-Wide)4Always allow Machine-Wide Installs, but not Per-User Installs6Force Installs (Per-User)Specifies whether a Microsoft Edge channel can be installed on domain-joined devices. If you enable (1) this policy for a channel, Microsoft Edge will not be blocked from installation. If you disable (0) this policy for a channel (or set it to 'Installs disabled'), Microsoft Edge will be blocked from installation. If you don't configure this policy for a channel, the 'Allow installation default' policy configuration determines whether users can install that channel of Microsoft Edge. If you set this policy to Always allow Machine-Wide Installs but not Per-User Installs (4), Microsoft Edge Dev will only be deployed machine-wide. If you set this policy to Force Installs (Machine-Wide) (5), Microsoft Edge Dev may only be deployed machine-wide if Microsoft Edge Update is pre-installed. Requires Microsoft Edge Update 1.3.155.43 or higher. If you set this policy to Force Installs (Per-User) (6), Microsoft Edge Dev may only be deployed on a Per-User basis to all machines if Microsoft Edge Update is pre-installed Per-User. Requires Microsoft Edge Update 1.3.155.43 or higher. This policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.
CreateDesktopShortcut{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10} Create Desktop Shortcut upon install
If you don't configure this policy for a channel, the 'Create Desktop Shortcut upon install default' policy configuration determines shortcut creation when Microsoft Edge is installed.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- CreateDesktopShortcut{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge Update 1.3.128.0 and later
- Template
- msedgeupdate.admx
If you enable (1) this policy a desktop shortcut is created when Microsoft Edge is installed. If you disable (0) this policy, no desktop shortcut will be created when Microsoft Edge is installed. If you don’t configure this policy a desktop shortcut to Microsoft Edge will be created during installation. If Microsoft Edge is already installed, this policy will have no effect. If you don't configure this policy for a channel, the 'Create Desktop Shortcut upon install default' policy configuration determines shortcut creation when Microsoft Edge is installed.
MeteredUpdates{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10} Let users update on metered connections
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- MeteredUpdates{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}
- Supported on
- Microsoft Edge Update 1.3.179.5 and later
- Template
- msedgeupdate.admx
1Metered Disable updates2Metered Updates AllowedSpecifies whether Microsoft Edge Update will update on connections marked as metered, such as cellular connections or others where data usage is controlled for the Microsoft Edge browser. If you don't enable and configure this policy, updates occur based the 'Download Updates over metered connections' toggle in the About Page of the Microsoft Edge browser. If a user doesn't make a choice, the Windows setting is used. You can find out more about the Windows setting here: https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-update#allowautowindowsupdatedownloadovermeterednetwork Always allow updates (2): Updates are always downloaded when found, either by automatic update check or by a manual update check. Disable updates (1): Updates are not downloaded when using a metered connection.
RemoveDesktopShortcut{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10} Remove Desktop Shortcuts upon update
If you don't configure this policy or disable it (0), nothing will happen to existing Microsoft Edge desktop shortcuts. If you don't configure this policy for a channel, the 'Remove Desktop Shortcuts upon update default' policy configuration determines desktop shortcut removal.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- RemoveDesktopShortcut{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}
- List subkey
- Software\Policies\Microsoft\EdgeUpdate
- Supported on
- Microsoft Edge Update 1.3.155.1 and later
- Template
- msedgeupdate.admx
1Force delete system-level Desktop Shortcuts2Force delete system-level and user-level Desktop Shortcuts0Prevent Desktop Shortcut creation on installIf you set this policy to "Force delete system-level Desktop Shortcuts" (1), any existing system-level Microsoft Edge desktop shortcuts will be deleted when the browser updates or the machine reboots. If you set this policy to "Force delete system-level and user-level Desktop Shortcuts" (2), any existing system-level Microsoft Edge desktop shortcuts will be deleted when the browser updates or the machine reboots and any existing user-level desktop shortcuts will be deleted when the browser updates. This includes user-level desktop shortcuts that users might have made themselves. If you don't configure this policy or disable it (0), nothing will happen to existing Microsoft Edge desktop shortcuts. If you don't configure this policy for a channel, the 'Remove Desktop Shortcuts upon update default' policy configuration determines desktop shortcut removal.
RollbackToTargetVersion{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10} Rollback to Target version
If you disable (0) this policy or don't configure it, installs that have a version higher than that specified by 'Target version override' will be left as-is.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- RollbackToTargetVersion{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge Update 1.3.133.3 and later
- Template
- msedgeupdate.admx
Specifies that Microsoft Edge Update should rollback installations of Microsoft Edge to the version indicated in 'Target version override'. This policy has no effect unless 'Target version override' is set and 'Update policy override' is set to one of the ON states (Always allow updates, Automatic silent updates only, Manual updates only). If you disable (0) this policy or don't configure it, installs that have a version higher than that specified by 'Target version override' will be left as-is. If you enable (1) this policy, installs that have a current version higher than specified by the 'Target version override' will be downgraded to the target version. We recommend that users install the latest version of the Microsoft Edge browser to ensure protection by the latest security updates. Rollback to an earlier version risks exposure to known security issues. This policy is meant to be used as a temporary fix to address issues in a Microsoft Edge browser update. Before temporarily rolling back your browser version, we recommend that you turn on Sync (https://go.microsoft.com/fwlink/?linkid=2133032) for all users in your organization. If you don't turn on Sync, there is a risk of permanent browsing data loss. Use this policy at your own risk. Note: All versions available for rollback can be viewed here https://aka.ms/EdgeEnterprise. This policy applies to Microsoft Edge version 86 or later. See https://go.microsoft.com/fwlink/?linkid=2133918 for more information. This policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.
TargetVersionPrefix{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10} Target version override
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- TargetVersionPrefix{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}
- Supported on
- Microsoft Edge Update 1.3.119.43 and later
- Template
- msedgeupdate.admx
When this policy is enabled, and auto-update is enabled, Microsoft Edge will be updated to the version specified by this policy value. The policy value must be a specific Microsoft Edge version, e.g. 83.0.499.12. If a device has newer version of Microsoft Edge than the value specified, Microsoft Edge will remain on the newer version and not downgrade to the specified version. If the specified version does not exist, or is improperly formatted, then Microsoft Edge will remain on its current version and not update to future versions automatically. See https://go.microsoft.com/fwlink/?linkid=2136707 for more information. This policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.
Update{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10} Update policy override
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- Update{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}
- Supported on
- Microsoft Edge Update 1.2.145.5 and later
- Template
- msedgeupdate.admx
1Always allow updates (recommended)2Manual updates only3Automatic silent updates only0Updates disabledSpecifies how Microsoft Edge Update handles available updates from Microsoft Edge. If you enable this policy, Microsoft Edge Update handles Microsoft Edge updates according to how you configure the following options: - Updates disabled (0): Updates are never applied. - Always allow updates (1) (Recommended): Updates are always applied when found, either by periodic update check or by a manual update check. - Manual updates only (2): Updates are applied only when the user runs a manual update check. (Not all apps provide an interface for this option.) - Automatic silent updates only (3): Updates are applied only when they're found by the periodic update check. If you select manual updates, make sure you periodically check for updates by using the app's manual update mechanism, if available. If you disable updates, periodically check for updates, and distribute them to users. If you don't enable and configure this policy, Microsoft Edge Update handles available updates as specified by the 'Update policy override default' policy. See https://go.microsoft.com/fwlink/?linkid=2136406 for more information. This policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.
Microsoft Edge Update / Microsoft Edge WebView2 Runtime
Install{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5} Allow installation
If you don't configure this policy, the WebView2 Runtime will be installed through Microsoft Edge Update.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- Install{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}
- Supported on
- Microsoft Edge Update 1.3.127.1 and later
- Template
- msedgeupdate.admx
1Always allow Installs (recommended)0Installs disabled5Force Installs (Machine-Wide)4Always allow Machine-Wide Installs, but not Per-User InstallsLets you specify whether the WebView2 Runtime can be installed using Microsoft Edge Update. If you enable (1) this policy, users can install the WebView2 Runtime through Microsoft Edge Update. If you disable (0) this policy (or set it to 'Installs disabled'), users cannot install the WebView2 Runtime through Microsoft Edge Update. If you set this policy to Always allow Machine-Wide Installs but not Per-User Installs (4), the WebView2 Runtime will only be deployed machine-wide. If you set the policy to Force Installs (Machine-Wide) (5), users can install the WebView2 Runtime to all machines where Microsoft Edge Update is pre-installed. Requires Microsoft Edge Update 1.3.155.43 or higher. If you don't configure this policy, the WebView2 Runtime will be installed through Microsoft Edge Update.
Update{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5} Update policy override
Automatic updates are enabled by default.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- Update{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}
- Supported on
- Microsoft Edge Update 1.3.127.1 and later
- Template
- msedgeupdate.admx
1Always allow updates (recommended)0Updates disabledLets you specify whether or not automatic updates are enabled for the WebView2 Runtime. The WebView2 Runtime is a component used by applications to display web content. Automatic updates are enabled by default. Disabling automatic updates for the WebView2 Runtime might cause compatibility issues with applications that depend on this component. If you enable this policy, Microsoft Edge Update handles the WebView2 Runtime updates according to how you configure the following options: - Always allow updates (1): Updates are automatically downloaded and applied - Updates disabled (0): Updates are never downloaded or applied If you don't enable this policy, updates are automatically downloaded and applied.
Microsoft Edge Update / Preferences
AutoUpdateCheckPeriodMinutes Auto-update check period override
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- AutoUpdateCheckPeriodMinutes
- List subkey
- Software\Policies\Microsoft\EdgeUpdate
- Supported on
- Microsoft Edge Update 1.2.145.5 and later
- Template
- msedgeupdate.admx
Minimum number of minutes between automatic update checks. Set this policy to the value 0 to disable all periodic network traffic by Microsoft Edge Update. This is not recommended, as it prevents Microsoft Edge Update itself from receiving stability and security updates. The 'Update policy override default' and per-application 'Update policy override' settings should be used to manage application updates rather than this setting. The values for this policy can range from 0 to 43200.
UpdatesSuppressedStartHour, UpdatesSuppressedStartMin, UpdatesSuppressedDurationMin Time period in each day to suppress auto-update check
If you disable or don't configure this policy, update checks aren't suppressed during any specific period.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- UpdatesSuppressedStartHour, UpdatesSuppressedStartMin, UpdatesSuppressedDurationMin
- List subkey
- Software\Policies\Microsoft\EdgeUpdate
- Supported on
- Microsoft Edge Update 1.3.33.5 and later
- Template
- msedgeupdate.admx
If you enable this policy, update checks are suppressed each day starting at Hour:Minute for a period of Duration (in minutes). Duration isn't affected by daylight saving time. For example, if the start time is 22:00 and the duration is 480 minutes, updates will be suppressed for exactly 8 hours, regardless of whether daylight saving time starts or ends during this period. If you disable or don't configure this policy, update checks aren't suppressed during any specific period. The values for this policy can range from 0 to 23 for hours, 0 to 59 for minutes and 0 to 960 for duration in minutes.
Microsoft Edge Update / Proxy Server
ProxyServer Address or URL of proxy server
Don't configure this policy if you have selected a proxy setting other than manual in the 'Choose how to specify a proxy server settings' policy.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- ProxyServer
- Supported on
- Microsoft Edge Update 1.3.21.81 and later
- Template
- msedgeupdate.admx
Allows you to specify the URL of the proxy server for Microsoft Edge Update to use. If you enable this policy, you can set the proxy server URL used by Microsoft Edge Update in your organization. This policy is applied only if you have selected manual proxy settings in the 'Choose how to specify a proxy server settings' policy. Don't configure this policy if you have selected a proxy setting other than manual in the 'Choose how to specify a proxy server settings' policy.
ProxyMode Choose how to specify proxy server settings
If you disable or don't configure this policy, no proxy server settings are configured, but users in your organization can choose their own proxy settings for Microsoft Edge Update.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- ProxyMode
- List subkey
- Software\Policies\Microsoft\EdgeUpdate
- Supported on
- Microsoft Edge Update 1.3.21.81 and later
- Template
- msedgeupdate.admx
Never use a proxyAuto detect proxy settingsUse a .pac proxy scriptUse fixed proxy serversUse system proxy settingsAllows you to specify the proxy server settings that are used by Microsoft Edge Update. If you enable this policy, you can choose between the following proxy server options: - If you choose to never use a proxy server and always connect directly, all other options are ignored. - If you choose to use system proxy settings or auto-detect the proxy server, all other options are ignored. - If you choose fixed server proxy mode, you can specify further options in 'Address or URL of a proxy server' policy. - If you choose to use a .pac proxy script, you must specify the URL for the script in 'URL to proxy .pac file' policy. If you enable this policy, users in your organization can't change the proxy settings in Microsoft Edge Update. If you disable or don't configure this policy, no proxy server settings are configured, but users in your organization can choose their own proxy settings for Microsoft Edge Update.
ProxyPacUrl URL to a proxy .pac file
Don't configure this policy if you have selected a proxy setting other than manual in the 'Choose how to specify a proxy server settings' policy.
- Registry key
- Software\Policies\Microsoft\EdgeUpdate
- Value name
- ProxyPacUrl
- Supported on
- Microsoft Edge Update 1.3.21.81 and later
- Template
- msedgeupdate.admx
Allows you to specify a URL for a proxy auto-config (PAC) file. If you enable this policy, you can specify a URL for a PAC file to automate how Microsoft Edge Update selects the appropriate proxy server for fetching a particular website. This policy is applied only if you have specified manual proxy settings in the 'Choose how to specify a proxy server settings' policy. Don't configure this policy if you have selected a proxy setting other than manual in the 'Choose how to specify a proxy server settings' policy.
Microsoft Edge WebView2
NewBaseUrlInheritanceBehaviorAllowed Allows enabling the feature NewBaseUrlInheritanceBehavior (obsolete)
If you enable or don't configure this policy, it allows enabling NewBaseUrlInheritanceBehavior.
- Registry key
- Software\Policies\Microsoft\Edge\WebView2
- Value name
- NewBaseUrlInheritanceBehaviorAllowed
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 123-135, Windows 7 or later
- Template
- msedgewebview2.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 135. NewBaseUrlInheritanceBehavior is a Microsoft Edge feature that causes about:blank and about:srcdoc frames to consistently inherit their base url values via snapshots of their initiator's base url. If you disable this policy, it prevents users or Microsoft Edge variations from enabling NewBaseUrlInheritanceBehavior, in case compatibility issues are discovered. If you enable or don't configure this policy, it allows enabling NewBaseUrlInheritanceBehavior. The policy became obsolete starting from Microsoft Edge version 136, but the NewBaseUrlInheritanceBehaviorAllowed feature was removed in Microsoft Edge version 123.
RSAKeyUsageForLocalAnchorsEnabled Check RSA key usage for server certificates issued by local trust anchors (obsolete)
If this policy isn't configured, Microsoft Edge behaves as if the policy is enabled.
- Registry key
- Software\Policies\Microsoft\Edge\WebView2
- Value name
- RSAKeyUsageForLocalAnchorsEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- This policy is available for administrators to preview the behavior of a future release, which will enable this check by default.
- Supported on
- Microsoft Edge version 123-135, Windows 7 or later
- Template
- msedgewebview2.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 135. The X.509 key usage extension declares how the key in a certificate can be used. These instructions ensure certificates aren't used in an unintended context, which protects against a class of cross-protocol attacks on HTTPS and other protocols. HTTPS clients must verify that server certificates match the connection's TLS parameters. Starting in Microsoft Edge 124, this check is always enabled. Microsoft Edge 123 and earlier have the following behavior: If this policy is set to enabled, Microsoft Edge performs this key check. This helps prevent attacks where an attacker manipulates the browser into interpreting a key in ways that the certificate owner didn't intend. If this policy is set to disabled, Microsoft Edge skips this key check-in HTTPS connections that negotiate TLS 1.2 and use an RSA certificate that chains to a local trust anchor. Examples of local trust anchors include policy-provided or user-installed root certificates. In all other cases, the check is performed independent of this policy's setting. If this policy isn't configured, Microsoft Edge behaves as if the policy is enabled. This policy is available for administrators to preview the behavior of a future release, which will enable this check by default. At that point, this policy will remain temporarily available for administrators that need more time to update their certificates to meet the new RSA key usage requirements. Connections that fail this check will fail with the error ERR_SSL_KEY_USAGE_INCOMPATIBLE. Sites that fail with this error likely have a misconfigured certificate. Modern ECDHE_RSA cipher suites use the "digitalSignature" key usage option, while legacy RSA decryption cipher suites use the "keyEncipherment" key usage option. If uncertain, administrators should include both in RSA certificates meant for HTTPS. The policy has been obsoleted starting from Microsoft Edge version 136, but the key check has been always enabled since Microsoft Edge version 124.
ExperimentationAndConfigurationServiceControl Control communication with the Experimentation and Configuration Service
If you don't configure this policy on a managed device, the behavior on Beta and Stable channels is the same as the 'ConfigurationsOnlyMode'. If you don't configure this policy on an unmanaged device, the behavior is the same as the 'FullMode'.
- Registry key
- Software\Policies\Microsoft\Edge\WebView2
- Value name
- ExperimentationAndConfigurationServiceControl
- Supported on
- Microsoft Edge version 97, Windows 7 or later
- Template
- msedgewebview2.admx
2Retrieve configurations and experiments1Retrieve configurations only0Disable communication with the Experimentation and Configuration ServiceThe Experimentation and Configuration Service is used to deploy Experimentation and Configuration payloads to the client. Experimentation payload consists of a list of early-in-development features that Microsoft is enabling for testing and feedback. Configuration payload consists of a list of recommended settings that Microsoft wants to deploy to optimize the user experience. Configuration payload may also contain a list of actions to take on certain domains for compatibility reasons. For example, the browser may override the User Agent string on a website if that website is broken. Each of these actions is intended to be temporary while Microsoft tries to resolve the issue with the site owner. If you set this policy to 'FullMode', the full payload is downloaded from the Experimentation and Configuration Service. This includes both the experimentation and configuration payloads. If you set this policy to 'ConfigurationsOnlyMode', only the configuration payload is downloaded. If you set this policy to 'RestrictedMode', the communication with the Experimentation and Configuration Service is stopped completely. Microsoft doesn't recommend this setting. If you don't configure this policy on a managed device, the behavior on Beta and Stable channels is the same as the 'ConfigurationsOnlyMode'. On Canary and Dev channels, the behavior is the same as 'FullMode'. If you don't configure this policy on an unmanaged device, the behavior is the same as the 'FullMode'. Policy options mapping: * FullMode (2) = Retrieve configurations and experiments * ConfigurationsOnlyMode (1) = Retrieve configurations only * RestrictedMode (0) = Disable communication with the Experimentation and Configuration Service Use the preceding information when configuring this policy.
XSLTEnabled Control the availability of the XSLT feature
If you don't configure this policy, XSLT availability is determined by the browser's default configuration and any applicable field trials.
- Registry key
- Software\Policies\Microsoft\Edge\WebView2
- Value name
- XSLTEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 147, Windows 7 or later
- Template
- msedgewebview2.admx
Controls whether the XSLT feature (the XSLTProcessor JavaScript API and the XSL processing instruction) is available in Microsoft Edge. If you enable this policy, XSLT is available regardless of the browser's default configuration. If you disable this policy, XSLT is unavailable regardless of the browser's default configuration. If you don't configure this policy, XSLT availability is determined by the browser's default configuration and any applicable field trials. This policy is temporary and will be removed in a future version of Microsoft Edge.
ForcePermissionPolicyUnloadDefaultEnabled Controls whether unload event handlers can be disabled.
If you disable this policy or don't configure it, unload event handlers are gradually deprecated in-line with the deprecation rollout, and sites that don't set Permissions-Policy header stop firing `unload` events.
- Registry key
- Software\Policies\Microsoft\Edge\WebView2
- Value name
- ForcePermissionPolicyUnloadDefaultEnabled
- Enabled / Disabled
- 1 / 0
- Stated default
- Currently, the policy allows them by default. In the future, they move to being disallowed by default, and sites must explicitly enable them using Permissions-Policy headers.
- Supported on
- Microsoft Edge version 118, Windows 7 or later
- Template
- msedgewebview2.admx
unload event handlers are being deprecated. Whether they fire depends on the unload Permissions-Policy. Currently, the policy allows them by default. In the future, they move to being disallowed by default, and sites must explicitly enable them using Permissions-Policy headers. This enterprise policy can be used to opt out of this gradual deprecation by forcing the default to stay enabled. Pages might depend on unload event handlers to save data or to signal the end of a user session to the server. This dependency isn't recommended because it's unreliable and impacts performance by blocking use of BackForwardCache. Recommended alternatives exist, but the unload event has been used for a long time. Some applications might still rely on them. If you disable this policy or don't configure it, unload event handlers are gradually deprecated in-line with the deprecation rollout, and sites that don't set Permissions-Policy header stop firing `unload` events. If you enable this policy, the unload event handlers continue to work by default.
NewPDFReaderWebView2List Enable built-in PDF reader powered by Adobe Acrobat for WebView2
If you disable the policy for the specified WebView2 applications or don't configure it, they will use the existing PDF reader to open all PDF files.
- Registry key
- Software\Policies\Microsoft\Edge\WebView2
- List subkey
- Software\Policies\Microsoft\Edge\WebView2\NewPDFReaderWebView2List
- Supported on
- Microsoft Edge version 116, Windows 7 or later
- Template
- msedgewebview2.admx
This policy configures WebView2 applications to launch the new version of the PDF reader that's powered by Adobe Acrobat's PDF reader. The new PDF reader ensures that there's no loss of functionality and delivers an enhanced PDF experience. This experience includes richer rendering, improved performance, strong security for PDF file handling, and greater accessibility. If this policy is specified for an application, it is possible that it may impact other related applications as well. The policy is applied to all WebView2s sharing the same WebView2 user data folder. These WebView2s could potentially belong to multiple applications if those applications, which are likely from the same product family, are designed to share the same user data folder. Use a name-value pair to enable the new PDF reader for the application. Set the name to the Application User Model ID or the executable file name. You can use the "*" wildcard as value name to apply to all applications. Set the Value to true to enable the new reader or set it to false to use the existing one. If you enable this policy for the specified WebView2 applications, they will use the new Adobe Acrobat powered PDF reader to open all PDF files. If you disable the policy for the specified WebView2 applications or don't configure it, they will use the existing PDF reader to open all PDF files. Example value: {"name": "app1.exe", "value": true} {"name": "app_id_for_app2", "value": true} {"name": "*", "value": false}
HttpAllowlist HTTP Allowlist
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge\WebView2
- List subkey
- Software\Policies\Microsoft\Edge\WebView2\HttpAllowlist
- Supported on
- Microsoft Edge version 123, Windows 7 or later
- Template
- msedgewebview2.admx
Setting the policy specifies a list of hostnames or hostname patterns (such as '[*.]example.com') that won't be upgraded to HTTPS. Organizations can use this policy to maintain access to servers that don't support HTTPS, without needing to disable "HttpsUpgradesEnabled". Supplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase. Blanket host wildcards (that is, "*" or "[*]") aren't allowed. Instead, HTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their specific policies. Note: This policy doesn't apply to HSTS upgrades. Example value: testserver.example.com [*.]example.org
Microsoft Edge WebView2 / Loader Override Settings
DowngradeVersion Configure per-application WebView2 downgrade version
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge\WebView2
- List subkey
- Software\Policies\Microsoft\Edge\WebView2\DowngradeVersion
- Supported on
- Microsoft Edge version 149, Windows 7 or later
- Template
- msedgewebview2.admx
This policy lets you specify the major version of the WebView2 Runtime that specific applications should use in enterprise downgrade scenarios. Configure the policy by setting the value name to the Application User Model ID or the executable file name (for example, teams.exe). Set the value to the target major version number using digits only (for example, 145). Full version strings (for example, 145.0.1234.56), wildcard values (for example, 145.*), and values that contain non-digit characters or separators are not supported. The WebView2 loader scans the runtime installation directory for an already-installed folder that matches the specified major version (for example, 145 matches 145.0.1234.56). If no matching folder is found, the policy has no effect and the runtime defaults to the BrowserExecutableFolder policy or the Evergreen runtime (the default auto-updating runtime). Example value: Name: teams.exe, Value: 145 Name: outlook.exe, Value: 146
BrowserExecutableFolder Configure the location of the browser executable folder
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge\WebView2
- List subkey
- Software\Policies\Microsoft\Edge\WebView2\BrowserExecutableFolder
- Supported on
- Microsoft Edge version 87, Windows 7 or later
- Template
- msedgewebview2.admx
This policy configures WebView2 applications to use the WebView2 Runtime in the specified path. The folder should contain the following files: msedgewebview2.exe, msedge.dll, and so on. To set the value for the folder path, provide a Value name and Value pair. Set value name to the Application User Model ID or the executable file name. You can use the "*" wildcard as value name to apply to all applications. Example value: Name: *, Value: C:\Program Files\Microsoft Edge WebView2 Runtime Redistributable 85.0.541.0 x64
ChannelSearchKind Configure the WebView2 release channel search kind
By default the channel search kind is 0, which is equivalent to the "Most Stable" search kind in the corresponding WebView2 API; This indicates that WebView2 environment creation should search for a release channel from the most to least stable: WebView2 Runtime, Beta, Dev, and Canary.
- Registry key
- Software\Policies\Microsoft\Edge\WebView2
- List subkey
- Software\Policies\Microsoft\Edge\WebView2\ChannelSearchKind
- Supported on
- Microsoft Edge version 121, Windows 7 or later
- Template
- msedgewebview2.admx
This policy configures the channel search kind for WebView2 applications. By default the channel search kind is 0, which is equivalent to the "Most Stable" search kind in the corresponding WebView2 API; This indicates that WebView2 environment creation should search for a release channel from the most to least stable: WebView2 Runtime, Beta, Dev, and Canary. To reverse the default search order and use the "Least Stable" search kind, set this policy to 1. To set the value for the channel search kind, provide a Value name and Value pair. Set value name to the Application User Model ID or the executable file name. You can use the "*" wildcard as value name to apply to all applications. Example value: Name: WebView2APISample.exe, Value: 1
ReleaseChannels Configure the WebView2 release channels
By default, environment creation searches for channels from most to least stable, using the first channel found on the device.
- Registry key
- Software\Policies\Microsoft\Edge\WebView2
- List subkey
- Software\Policies\Microsoft\Edge\WebView2\ReleaseChannels
- Supported on
- Microsoft Edge version 121, Windows 7 or later
- Template
- msedgewebview2.admx
This policy configures the release channel options for WebView2 applications. To configure these options, set the value to a comma-separated string of integers, which map to the `COREWEBVIEW2_RELEASE_CHANNELS` values from the corresponding WebView2 API. These values are: WebView2 Runtime (0), Beta (1), Dev (2), and Canary (3). By default, environment creation searches for channels from most to least stable, using the first channel found on the device. When `ReleaseChannels` is provided, environment creation will only search for the channels specified in the set. For example, the values "0,2" and "2,0" indicate that environment creation should only search for Dev channel and the WebView2 Runtime, using the order indicated by `ChannelSearchKind`. Environment creation attempts to interpret each integer and treats any invalid entry as the Stable channel. Set `ChannelSearchKind` to reverse the search order so environment creation searches for least stable build first. If both `BrowserExecutableFolder` and `ReleaseChannels` are provided, the `BrowserExecutableFolder` takes precedence, regardless of whether the channel of `BrowserExecutableFolder` is included in the `ReleaseChannels`. To set the value for release channels, provide a Value name and Value pair. Set the value name to the Application User Model ID or the executable file name. You can use the "*" wildcard as value name to apply to all applications. Example value: Name: WebView2APISample.exe, Value: 0,1,2
ReleaseChannelPreference Set the release channel search order preference (deprecated)
Default behaviour not stated in the ADMX — unset means Edge's built-in behaviour applies.
- Registry key
- Software\Policies\Microsoft\Edge\WebView2
- List subkey
- Software\Policies\Microsoft\Edge\WebView2\ReleaseChannelPreference
- Supported on
- Microsoft Edge version 87, Windows 7 or later
- Template
- msedgewebview2.admx
DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release. This policy is deprecated in favor of ChannelSearchKind, which has the same functionality, and will become obsolete in 124 release. The default channel search order is WebView2 Runtime, Beta, Dev, and Canary. To reverse the default search order, set this policy to 1. To set the value for the release channel preference, provide a Value name and Value pair. Set value name to the Application User Model ID or the executable file name. You can use the "*" wildcard as value name to apply to all applications. Example value: Name: *, Value: 1
Microsoft Edge WebView2 / Network settings
BlockTruncatedCookies Block truncated cookies (obsolete)
If you enable or don't configure this policy, the new behavior is enabled.
- Registry key
- Software\Policies\Microsoft\Edge\WebView2
- Value name
- BlockTruncatedCookies
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 123-131, Windows 7 or later
- Template
- msedgewebview2.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 131. This policy provides a temporary opt-out for changes to how Microsoft Edge handles cookies set via JavaScript that contain certain control characters (NULL, carriage return, and line feed). Previously, the presence of any of these characters in a cookie string would cause it to be truncated but still set. Now, the presence of these characters will cause the whole cookie string to be ignored. If you enable or don't configure this policy, the new behavior is enabled. If you disable this policy, the old behavior is enabled. This policy is obsolete because this policy was originally implemented as a safety measure if there was a breakage, but none have been reported.
ZstdContentEncodingEnabled Enable zstd content encoding support (obsolete)
If this policy is not configured, the default behavior is to enable support for zstd content encoding.
- Registry key
- Software\Policies\Microsoft\Edge\WebView2
- Value name
- ZstdContentEncodingEnabled
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 125-137, Windows 7 or later
- Template
- msedgewebview2.admx
OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 137. This policy controls whether Microsoft Edge supports Zstandard (zstd) content encoding. If this policy is enabled, Microsoft Edge advertises zstd in the Accept-Encoding request header and can decompress responses encoded with zstd. If this policy is disabled, Microsoft Edge doesn't advertise or support zstd content encoding. If this policy is not configured, the default behavior is to enable support for zstd content encoding. NOTE: This policy is obsolete starting with Microsoft Edge version 138 because Microsoft Edge now always supports zstd content encoding.
AccessControlAllowMethodsInCORSPreflightSpecConformant Make Access-Control-Allow-Methods matching in CORS preflight spec conformant
If you enable or don't configure this policy, request methods aren't uppercased, unless matching case-insensitively with DELETE, GET, HEAD, OPTIONS, POST, or PUT.
- Registry key
- Software\Policies\Microsoft\Edge\WebView2
- Value name
- AccessControlAllowMethodsInCORSPreflightSpecConformant
- Enabled / Disabled
- 1 / 0
- Supported on
- Microsoft Edge version 123, Windows 7 or later
- Template
- msedgewebview2.admx
This policy controls whether request methods are uppercased when matching with Access-Control-Allow-Methods response headers in CORS preflight. If you disable this policy, request methods are uppercased. This is the behavior on or before Microsoft Edge 108. If you enable or don't configure this policy, request methods aren't uppercased, unless matching case-insensitively with DELETE, GET, HEAD, OPTIONS, POST, or PUT. This would reject fetch(url, {method: 'Foo'}) + "Access-Control-Allow-Methods: FOO" response header, and would accept fetch(url, {method: 'Foo'}) + "Access-Control-Allow-Methods: Foo" response header. Note: request methods "post" and "put" aren't affected, while "patch" is affected. This policy is intended to be temporary and will be removed in the future.
No policies match those filters.