• ManageEngine Products

Securing zone levels in Internet Explorer

Managing and configuring Internet Explorer can be complicated. This is especially true when users meddle with the numerous settings it houses. Users may even unknowingly enable the execution of malicious codes. This highlights the importance of securing Internet Explorer.

In this blog, we’ll talk about restricting users from changing security settings, setting trusted sites, preventing them from changing security zone policies, adding or deleting sites from security zones, and removing the Security tab altogether to ensure that users have a secure environment when using their browser.

Restricting users from changing security settings

A security zone is a list of websites at the same security level. These zones can be thought of as invisible boundaries that prevent certain web-based applications from performing unauthorized actions. These zones easily provide the appropriate level of security for the various types of web content that users are likely to encounter. Usually, sites are added or removed from a zone depending on the functionality available to users on that particular site.

To set trusted sites via GPO

  • Open the Group Policy Management Editor .
  • Go to User Configuration > Policies > Administrative Templates > Windows Components > Internet Explorer > Internet Control Panel > Security Page .
  • Select the Site to Zone Assignment List .
  • Select Enabled and click Show to edit the list. Refer to Figure 1 below. The zone values are as follows: 1 — intranet, 2 — trusted sites, 3 — internet zone, 4 — restricted sites.
  • Click Apply and OK .

site zone assignment list values

Figure 1. Assigning sites to the Trusted Sites zone.

site zone assignment list values

Figure 2. Enabling the Site to Zone Assignment List policy.

By enabling this policy setting, you can manage a list of sites that you want to associate with a particular security zone. See Figure 2.

Restricting users from changing security zone policies

  • Go to Computer Configuration > Administrative Templates > Windows Components > Internet Explorer .
  • Double-click Security Zones: Do not allow users to change policies .
  • Select Enabled .

This prevents users from changing the security zone settings set by the administrator. Once enabled, this policy disables the Custom Level button and the security-level slider on the Security tab in the Internet Options dialog box. See Figure 3.

Restricting users from adding/deleting sites from security zones

  • Double-click Security Zones: Do not allow users to add/delete sites .

This disables the site management settings for security zones, and prevents users from changing site management settings for security zones established by the administrator. Users won’t be able to add or remove websites from the Trusted Sites and Restricted Sites zones or alter settings for the Local Intranet zone. See Figure 3.

site zone assignment list values

Figure 3. Enabling Security Zones: Do not allow users to change policies and Security Zones: Do not allow users to add/delete sites .

Removing the Security tab

The Security tab in Internet Explorer’s options controls access to websites by applying security settings to various download and browsing options, including defining security levels for respective security zones. By removing this tab, users will no longer be able to see or change the settings established by the administrator.

  • Go to User Configuration > Policies > Administrative Templates > Windows Components > Internet Explorer > Internet Control Panel .
  • Double-click Disable the Security page .

site zone assignment list values

Figure 4. Enabling the Disable the Security page policy. Enabling this policy prevents users from seeing and changing settings for security zones such as scripting, downloads, and user authentication. See Figure 4.

There’s no denying the importance of securing Internet Explorer for any enterprise. By setting security levels, restricting users from changing security zone policies, preventing them from adding or deleting sites from security zones, and removing the Security tab, users will not be able to change any security settings in Microsoft Internet Explorer that have been established by the administrator. This helps you gain more control over Internet Explorer’s settings in your environment.

' src=

Derek Melber

Cancel reply.

' src=

Is there a way to enable Site to Zone assignment list and still let the user enter their own sites to the trusted list?

site zone assignment list values

Hi Joe. You need to disable the below setting to achieve the requirement.

Securing zone levels in Internet Explorer

Note: Even if the policy is not configured, users can add their own sites. Only when the policy is enabled, users can’t add their own sites to trusted sites.

' src=

Thanks a lot.

Related Posts

site zone assignment list values

Gear up to combat data theft by securing user access permissions

ADManager Plus , General 2 min read Read

techlauve.com – a knowledge base for IT professionals.

Inhale problems, exhale solutions..

  • Nick’s Blog
  • Active Directory
  • Privacy Policy

« Outlook: “Sending and Receiving reported error (OX80040600)”

Terminal Server Does Not Accept Enough Client Connections »

Adding Sites to Internet Security Zones Using Group Policy

Sometimes it is useful to leverage the power of Group Policy in Active Directory to add sites to certain security zones in Internet Explorer.  This can save the network admin the trouble of managing the security zone lists for each computer (or user) separately.  In the following example, each user on the network needs to have a specific site added to the Trusted Sites list.

This tutorial assumes that group policy is in good working order on the domain and that all client users and computers can access the directory.

  • Open the Group Policy Management MMC console.
  • Right-click the organization unit (OU) that the policy should apply to, taking special care to consider whether the policy should apply to computers or users on this particular network.
  • Select “Create and Link a GPO Here…” to create a new group policy object.
  • In the “New GPO” window, enter a good, descriptive name for this new policy and click “OK”.   (ex.  “Trusted Sites Zone – Users” or something even more descriptive)
  • Locate the newly created GPO in the left-side navigation pane, right-click it and select “Edit…”
  • Expand “Administrative Templates” under either “Computer Configuration” or “User Configuration” depending on which type of OU the new policy was linked to in step 2.
  • The path to the settings that this example will be using is: Administrative Templates -- Windows Components -- Internet Explorer -- Internet Control Panel -- Security Page
  • In the right-hand pane, double-click “Site to Zone Assignment List”.
  • Enable the policy and click the “Show…” button next to “Enter the zone assignments here.”  This will pop up the “Show Contents” window.
  • Click the “Add…” button.  This will pop up the “Add Item” window.
  • In the first box, labeled “Enter the name of the item to be added:”, enter the URL to the site.   (ex.  https://secure.ourimportantwebapp.com) .  Keep in mind that wildcards can be used.   (ex.  https://*.ourimportantdomain.com) .  Leave off any trailing slashes or sub-folders unless that type of specific control is called for.
  • 1 – Intranet Zone
  • 2 – Trusted Sites Zone
  • 3 – Internet Zone
  • 4 – Restricted Sites Zone
  • Once the zone assignment has been entered, click “OK”.  This will once again show the “Show Contents” window and the new entry should be present.
  • Click “OK” and “OK” again to get back to the Group Policy Management Console.

The new policy will take effect at the next group policy refresh interval, which is usually 15 minutes.  To test immediately, run a gpupdate /force on a user/computer that falls into the scope of the new policy and go to “Tools -> Internet Options -> Security -> Trusted Sites -> Sites”.  The site(s) added should be in the list.  If the sites do not show up, check the event logs for any group policy processing errors.

Related content:

  • How To: Time Sync Across Windows Network
  • Group Policy Not Applied To Remote VPN Users
  • QuickBooks Payroll Opens/Saves the Wrong W2 Form
  • Microsoft Virtual Server Web Console Constantly Asks For Password
  • Group Policy: Applying Different User Policies to the Same User for Workstations and Terminal Server

No comment yet

Juicer breville says:.

November 26, 2012 at 12:11 am (UTC -5)

Hurrah, that’s what I was looking for, what a information! existing here at this web site, thanks admin of this web page.

Leave a Reply Cancel reply

Your email address will not be published.

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>

Submit Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed .

Remember Me

Connect With Us

Connect with us.

Social Connect by NewsPress

Not finding the answer that you're looking for? Need more help with a problem that is addressed in one of our articles?

techlauve.com is affiliated with Rent-A-Nerd, Inc. in New Orleans, LA.

  • DFS Replication (1)
  • Group Policy (1)
  • Microsoft Exhange (3)
  • Microsoft Outlook (11)
  • Copiers (1)
  • Multi Function Devices (1)
  • Printers (2)
  • Scanners (1)
  • Blackberry (1)
  • Firewalls (2)
  • Wireless (2)
  • Hard Drives (1)
  • SAN Systems (1)
  • Hyper-V (3)
  • Virtual Server (1)
  • WordPress (1)
  • Security (7)
  • QuickBooks (2)
  • Quicken (1)
  • Antivirus/Antimalware (4)
  • Backup Exec (2)
  • Internet Explorer (5)
  • Microsoft SQL (1)
  • Licensing (2)
  • Steinberg Nuendo (1)
  • Mac OS X (1)
  • Server 2003 (12)
  • Server 2008 (14)
  • Small Business Server 2003 (7)
  • Terminal Server (6)
  • Updates (2)
  • Windows 7 (9)
  • Windows XP (11)
  • Reviews (1)
  • Rent-A-Nerd, Inc.

Except where otherwise noted, content on this site is licensed under a Creative Commons Licence .

Valid XHTML 1.0 Strict Valid CSS Level 2.1

techlauve.com - a knowledge base for IT professionals. uses Graphene theme by Syahir Hakim.

Guest

a blog by Sander Berkouwer

  • The things that are better left unspoken

HOWTO: Add the required Hybrid Identity URLs to the Trusted Sites list of Internet Explorer and Edge

Hybrid Identity

Most Microsoft-based Hybrid Identity implementations use Active Directory Federation Services (AD FS) Servers, Web Application Proxies and Azure AD Connect installations. In this series, labeled Hardening Hybrid Identity , we’re looking at hardening these implementations, using recommended practices.

In this part of the series, we’ll look at the required Hybrid Identity URLs that you want to add to the Trusted Sites list in Internet Explorer.

Note: This is the second part for adding Microsoft Cloud URLs to Internet Explorer’s zone. In this part we look at the Trusted Sites zone. In the previous part we looked at the Local Intranet zone .

Note: Adding URLs to the Trusted Sites zone for Internet Explorer, also applies to Microsoft Edge.

Why look at the Trusted Sites?

Hybrid Identity enables functionality for people using on-premises user accounts, leveraging Azure Active Directory as an additional identity platform. By default, Azure AD is the identity platform for Microsoft Cloud services, like Exchange Online, SharePoint Online and Azure.

By adding the URLs for these services to the Trusted Sites list, we enable a seamless user experience without browser prompts or hick-ups to these services.

Internet Explorer offers built-in zones. Per zone, Internet Explorer is allowed specific functionality. Restricted Sites is the most restricted zone and Internet Explorer deploys the maximum safeguards and fewer secure features (like Windows Integrated Authentication) are enabled.

The Trusted Sites zone, by default, offers a medium level of security.

Possible negative impact (What could go wrong?)

Internet Explorer’s zones are defined with specific default settings to lower the security features for websites added to these zones.

When you use a Group Policy object to add websites that don’t need the functionality of the Trusted Sites zone to the zone, the systems in scope for the Group Policy object are opened up to these websites. This may result in unwanted behavior of the browser such as browser hijacks, identity theft and remote code executions, for example when you mistype the URLs or when DNS is compromised.

While this does not represent a clear and immediate danger, it is a situation to avoid.

Getting ready

The best way to manage Internet Explorer zones is to use Group Policy.

To create a Group Policy object, manage settings for the Group Policy object and link it to an Organizational Unit, Active Directory site and/or Active Directory domain, log into a system with the Group Policy Management Console (GPMC) installed with an account that is either:

  • A member of the Domain Admins group, or;
  • The current owner of the Group Policy Object, and have the Link GPOs permission on the Organizational Unit(s), Site(s) and/or Domain(s) where the Group Policy Object is to be linked, or;
  • Delegated the Edit Settings or Edit settings, delete and modify security permission on the GPO, and have the Link GPOs permission on the Organizational Unit(s), Site(s) and/or Domain(s) where the Group Policy Object is to be linked.

The URLs to add

You’ll want to add the following URLs to the Trusted Sites zone, depending on the way you’ve setup your Hybrid Identity implementation:

*.microsoft.com

*.microsoftonline.com, *.windows.net, ajax.aspnetcdn.com, microsoft.com, microsoftline.com, microsoftonline-p.net, onmicrosoft.com.

The above URLs are used in Hybrid Identity environments. While they overlap with some of the URLs for the Local Intranet Zone, these URLs allow side services to work properly, too.

*.msappproxy.net

Web applications that you integrate with Azure Active Directory through the Azure AD Application Proxy are published using https://*.msappproxy.net URLs. Add the above wildcard URL to the Trusted Sites list, when you’ve deployed or are planning to deploy Azure AD App Proxy. If you use vanity names for Azure AD App Proxied applications, add these to the Trusted Sites list, as well.

Other Office 365 services

Most  Hybrid Identity implementations are used to allow access to Office 365 only. Last year, 65% of Hybrid Identity implementations are used to unlock access to one or more Office 365 services, like Exchange Online, SharePoint Online, OneDrive for Business and Teams, only. This blogpost focuses on the Hybrid Identity URLs, but you might want to add more Office 365 URLs and IP address ranges to the Trusted Sites list as you deploy, roll out and use Office 365 services. You can use this (mostly outdated) Windows PowerShell script to perform that action , if you need.

How to add the URLs to the Trusted Sites zone

To add the URLs to the Trusted Sites zone, perform these steps:

  • Log into a system with the Group Policy Management Console (GPMC) installed.
  • Open the Group Policy Management Console ( gpmc.msc )
  • In the left pane, navigate to the Group Policy objects node.
  • Locate the Group Policy Object that you want to use and select it, or right-click the Group Policy Objects node and select New from the menu.
  • Right-click the Group Policy object and select Edit… from the menu. The Group Policy Management Editor window appears.
  • In the main pane of the Group Policy Management Editor window, expand the Computer Configuration node, then Policies , Administrative Templates , Windows Components , Internet Explorer , Internet Control Panel and then the Security Page node.

SiteToZoneAssignmentListSettingGPO_thumb[3]

  • In the main pane, double-click the Sites to Zone Assignment List setting.
  • Enable the Group Policy setting by selecting the Enabled option in the top pane.
  • Click the Show… button in the left pane. The Show Contents window appears.
  • Add the above URLs to the Trusted Sites zone by entering the URL in the Value name column and the number 2 in the Value column for each of the URLs.
  • Click OK when done.
  • Close the Group Policy Editor window.
  • In the left navigation pane of the Group Policy Management Console, navigate to the Organization Unit (OU) where you want to link the Group Policy object.
  • Right-click the OU and select Link an existing GPO… from the menu.
  • In the Select GPO window, select the GPO.
  • Click OK to link the GPO.

Repeat the last three steps to link the GPO to all OUs that require it. Take Block Inheritance into account for OUs by linking the GPO specifically to include all people in scope.

To enable functionality in a Hybrid Identity implementation, we need to open up the web browser to allow functionality for specific web addresses. By enabling the right URLs we minimize our efforts in enabling the functionality and also minimize the negative effect on browser security.

There is no need to add all the URLs to specific Internet Explorer zones, when you don’t need to functionality. However, do not forget to add the specific URLs when you enable specific functionality like the Azure AD Application Proxy and remove specific URLs when you move away from specific functionality.

Further reading

Office 365 URLs and IP address ranges Group Policy – Internet Explorer Security Zones Add Site to Local Intranet Zone Group Policy

' src=

Posted on October 17, 2019 by Sander Berkouwer in Active Directory , Entra ID , Security

2 Responses to HOWTO: Add the required Hybrid Identity URLs to the Trusted Sites list of Internet Explorer and Edge

 

Great Post! Thank you so much for teaching us on how to add hybrid identity urls to the trusted list of sites on browsers like internet explorer and Microsoft edge.

' src=

I want to block all websites on edge and only give access to 2 sites but using group policy can someone help on this?

leave your comment cancel

This site uses Akismet to reduce spam. Learn how your comment data is processed .

Advertisement

NiCE Microsoft 365 Monitoring

Search this site

Dirteam.com / activedir.org blogs.

  • Strategy and Stuff
  • Dave Stork's IMHO
  • The way I did it
  • Sergio's Shack
  • Things I do
  • Tomek's DS World

Microsoft MVP (2009-2025)

Veeam vanguard (2016-2024), vmware vexpert (2019-2022).

VMware vExpert

Xcitium Security MVP (2023)

Xcitium Security MVP

Recent Posts

  • VMware vSphere 8.0 Update 3 adds federation support for four Identity Providers
  • What's New in Entra ID for July 2024
  • On-premises Identity-related updates and fixes for July 2024
  • Sympathy for the devil, empathy for the Identity professional
  • The Recording of our '265 Days of Alarming Entra ID Application Discoveries' webinar is now available on-demand

Recent Comments

  • Sander Berkouwer on TODO: Upgrade the Certificates for your Windows Server 2016-based Domain Controllers (and up) to enable Windows Hello for Business Hybrid Scenarios
  • Jeff McGowan on TODO: Upgrade the Certificates for your Windows Server 2016-based Domain Controllers (and up) to enable Windows Hello for Business Hybrid Scenarios
  • Sander Berkouwer on Configuring Geo-Redundancy for AD FS on-premises with Azure Traffic Manager
  • JB on Configuring Geo-Redundancy for AD FS on-premises with Azure Traffic Manager

The information on this website is provided for informational purposes only and the authors make no warranties, either express or implied. Information in these documents, including URL and other Internet Web site references, is subject to change without notice. The entire risk of the use or the results from the use of this document remains with the user. Active Directory, Microsoft, MS-DOS, Windows, Windows NT, and Windows Server are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. All other trademarks are property of their respective owners.

logo

  • Password Tools For Windows Password Genius Windows Password Genius Windows 10 Password Genius Windows 7 Password Genius RAR Password Genius ZIP Password Genius SQL Password Genius Chrome Password Genius WiFi Password Genius For Office Office Password Genius Word Password Genius Excel Password Genius PowerPoint Password Genius Access Password Genius Outlook Password Genius Outlook Email Password Genius PDF Password Genius For Removing Office Password Remover Word Password Remover Excel Password Remover Workbook Unprotect Genius PowerPoint Unprotect Genius Word Unprotect Genius

iphone passcode genius

  • More Utilities Data Recovery BitGenius Word Repair Genius Excel Repair Genius PowerPoint Repair Genius Office Repair Genius Photo Data Genius Android Data Genius BitLocker Tools BitLocker Genius for Mac BitLocker Genius for Windows More Tools Product Key Finder SafeUSB Genius ISO Genius All Products
  • Support Support Center FAQ & Contact Resource Center How-to Articles Blog Blog, News & Guides

Adding Trusted Site to Group Policy in Windows 10

By  Sophia  | Last Updated January 03, 2024

In some cases, such as enterprise, have to add trusted site to group policy manually before visiting the website. Today, we'll show you how to solve this issue. Although you are new to use group policy, worry not, this tutorial is easy for you to understand.

Note: Windows 10 Home edition doesn't support group policy.

Cookie Settings

We use cookies for personalizing content and ads and providing social media features. Your usage information on our website will be used for social media, advertising, and traffic analytics, or shared with our partners.Clicking "Accept Cookies" means you agree with our Privacy Policy .

How to Add Trusted Site to Group Policy Windows 10

Step 1: Press Windows + R key combination to invoke Run dialog. Input gpedit.msc to the box and click on OK .

run group policy

Step 2: In the left pane, navigate to Computer Configuration > Administrative Templates > Windows Components > Internet Explorer > Internet Control Panel > Security page . Double-click on Site to Zone Assignment List in the right pane.

local group policy editor

Step 3: In the Site to Zone Assignment List window, select Enabled then tap on Show button under Options .

zone assignment list

Step 4: In the column under Value name , input the website. Then Type 2 in the box next to it.

Tips: Internet Explorer includes four safe zones, respectively, one to four. To add trusted site to group policy, we have to select number 2.

1: Intranet zone

2: Trusted Sites zone

3: Internet zone

4: Restricted Sites zone

enter zone assignments

Step 5: Go back to Site to Zone Assignment List window, tap on Apply then OK .

Step 6: When you finished the steps above, go to the desktop and check whether added successfully or not. Click on Search box then input Internet Explorer . Hit Enter , it will be opened at once.

open internet explorer

Step 7: Click the gear icon in the top-right corner then select Internet options .

internet options

Step 8: Click on Security tab, tap on Trusted sites and click on Sites button.

check trusted sites

Step 9: In the Trusted sites dialog, you will see the trusted site that added to group policy.

trusted sites windows 10

Related Articles :

  • Solutions of Screen upside down Windows 10
  • Change the Color of Taskbar and Window Border in Windows 10
  • 2 Ways to Enable/Disable Fast User Switching Windows 10
  • Allow BitLocker without a Compatible TPM Windows 10
  • Show Context Menu on Left or Right in Windows 10

reset windows 10 local microsoft account password

iSunshare is dedicated to providing the best service for Windows, Mac, Android users who are in demand for password recovery and data recovery.

Copyright © 2024 iSunshare Studio All Rights Reserved.

Group Policy Central

News, Tips and Tutorials for all your Group Policy needss

How to configuring IE Site Zone mapping using group policy without locking out the user

site zone assignment list values

Put simply we are going to setup the IE Zone registry keys manually using Group Policy Preferences…

However it’s a little complicated as the URL that is in the Site to Zone mapping is actually stored as the name of the key. Finally the protocol is the registry value with a number that assigns it to the corresponding zone. In the example we use we will first look at the currently site that the users has setup in the trusted site list ( www.bing.com ). As you can see below the zone is store at HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains then the domain is stored as a key “Bing.com” then “www”. Within the “www” key the protocol (http and/or https) is the value name with the value representing what zone it should be a member.

Note: We are just using bing.com as an example as you would never add at search engine as a trusted site.

site zone assignment list values

Now we will add the additional site www.google.com.au also to the trusted sites list using group policy.

Step 1 . Edit a Group Policy that is targeted to the users that you want the IE Zones applied.

Step 2. Create a new Group Policy Preferences Registry Extension then select the “HKEY_CURRENT_USERS” Hive and then type “Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\google.com.au\www” in the Key path. Then enter the Value name of “HTTP” and selected the Value Type as “REG_DWORD” and set the value data as “00000002”.

site zone assignment list values

And you’re Done…

TIP: For your reference the values and their corresponding Zones are listed below in the table.

Value Zone Name
00000000 My Computer
00000001 Local Intranet
00000002 Trusted Site
00000003 Internet
00000004 Restricted

As you can see below the IE zone will push out to your users and it will be added to the trusted zone list, while still allowing them to add and remove other zones from the list.

site zone assignment list values

TIP: As always the native group policy settings will take precedence over Group Policy Preferences therefore if you have the “Site to Zone Assignment List” setting configured as well this will override (not merge) the above settings (See image below).

site zone assignment list values

Author: Alan Burchill

Related articles.

site zone assignment list values

47 thoughts on “ How to configuring IE Site Zone mapping using group policy without locking out the user ”

Group Policy Central http://t.co/Y2cVZ0TP

Where on earth did you find this little gem?

I worked this one out on my own a few years back, Should have written a blog / guide back then! I’d be a millionnaire!!

But still – this is a great way to allow the users to add their own trusts, of on site to fix a broken site without returning to GPO Editor just for a single user!

  • Pingback: Security Tip: Block Internet Explorer invocation of Java with Group Policy

I wasn’t able to get this to work. I tried it on both User and Computer settings. There was no sub folder under ‘hotmail.com’. The domain I’m trying to remove.

I’m unable to get this to work. Even the group policy results test shows it is successful, but it never shows up in the IE Internet settings. I’ve added a REG entry to also “uncheck” the require https: and that doesn’t show up either. I’ve test on both WinXP with IE8 and Win7 with IE9. Same results. I’ve looked at the registry and see nothing added. Plus, there are no errors in the event log.

Strange behavior.

I just troubleshooted with the same problem that it was not working with no error message to troubleshoot anywhere.

SOLUTION: I fired up regedit and navigated to “HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\” There I saw the site I wanted to add as a sub-key to “ZoneMap” and not as a subkey to “Domains” as it is supposed to be. The “Domains” subkey was empty. I deleted the site from “ZoneMap” and then did a gpupdate. When I then refreshed regedit the site was created no the correct location and everything was working. 🙂

Thanks for the info, but this isn’t my experience at all.

I’ve checked the registry for this same error and see nothing. I’ve even searched the entire registry for the domain name, and it finds nothing…

I’ve got a computer policy that is applied to the OU where the computer lives. All items in the policy are updating successfully, except for the registry entries. I’ve run the group policy results and see no errors. I’ve even created the policy by using the registry wizard and importing the items from my local registry. When I check the local registry on my test machines, I see nothing change. If I add the entries via IE, then they show up in the correct places. I’m stumped why this isn’t working…

Tough one. I often had typos in the GP preferences mess things up for me in the past, also the correct amount of \ signs in the key path is important. Personally I have never used it in computer policy, but I’ve always used user policy, perhaps that is worth a try? Also I always use “Replace” and not “update” in the GP Preference.

What do you mean by, “the correct amount of signs in the key path”? What is a sign?

I had the same thought about user policy yesterday and tried that as well. No luck. I haven’t tried the “Replace” option. I’ll test that next.

A bit clumsy explained, sorry about that. But I meant where you put the (slash) \ in the path. “Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\*.contoso.com” is the correct path, but if you write “\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\*.contoso.com” or “Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\*.contoso.com\” then it will fail.

Not sure why but I can’t make this work at all. The GPP does not write the reg entries at all. I tried changing the action to create and also update, but no difference. Any suggestions?

well John, you don’t really tell me much of your setup so there is not much for me to go on here. But in general my checklist would be something like this:

1. It’s a GPP setting under the user (not computer) and it writes to the HKCU hive? 2. Use “replace” 3. Trippe-check that the path is written correctly. For example: “Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\*.contoso.com” 4. Use “gpresult -r” on the client computer to check that the user gets the GPP 5. If the user gets the GPP, check the application log on the computer. If a GPP fails you will see it in the application log at the time the user logs in and it usually tells you why.

That’s my suggestions at the moment.

You nailed the problem – I was using a computer policy, not a user policy. As soon as a rebuilt it as a user policy, everything fell into place perfectly. Thanks for posting this, it was a huge timesaver!

You’re welcome, I’m glad I could help. 🙂

Excellent post. I was just trying to figure out the exact registry keys to modify when I found this page. Nice work !

For the same case.. My user wants to add site to their trusted site list.. Please help…

Mahfuj: I’m not sure what you mean. If you use GPP to configure the IE zones then the users are allowed to add sites to them. Do you want ot prevernt them from adding sites to the trusted site list? Or do you want to allow them to add sites to the trusted site list?

Yes.. I want my user will add sites to trusted site list….. But “Add this website to the zone” field and “Add” button is gray out.. for all users.

Yes.. I want to allow my users to add sites to trusted site list….. But “Add this website to the zone” field and “Add” button is gray out.. for all users.

This means you have the administrative template still configured for the user so it will prevent them from editing their zone list. You have to be sure that you ONLY configure IE site zones via Group Policy Preferences…

I agree with Alan, it is most likely another GPO that contains settings for the IE zones, either in computer or user settings.

Thanks… I’ve figureout the issue.. Site to zone assignments list should be Not Configured for both Computer and user configuration settings….

You have a typo in the third paragraph that starts with “Hoever it’s a little complicted. Typo: “As you can see below the zone is store at HKCU\Software\Microsoft\CurrentVersion\Internet Settings\ZoneMap\Domains…” should be “As you can see below the zone is store at HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains…” The “Windows” part of the path is missing 😉

@KJS thanks.. I have corrected…

What versions of IE does this method support?

I have not tested it… but I think will work with all versions.

I am really loathing the decision by MS to go down the GPP route without replacing existing functionality with something equally simple. With this Zone mapping and the amount of work with getting favourites working it is a nightmare trying to replace existing simple easily updated GPOs with GPPs, I am not looking forward to doing it for Office.

Helpful. Thanks

Worked perfectly; delivering the following record helped the annoying windows security prompts for executing VBS/HTA files off network shares: file://privateDomainName.FQDN 1 file://privateDomainName 1

Many thanks,

My spouse and I absolutely love your blog and find a lot of your post’s to be exactly what I’m looking for. Would you offer guest writers to write content for you personally? I wouldn’t mind producing a post or elaborating on some of the subjects you write concerning here. Again, awesome weblog!

That brings us to quite possibly the most intriguing match-up to that point of the season when Oregon comes to Rice-Eccles. Alabama will try to rebound from their loss to the Sooners and rank fourth in the Sporting News college football preseason rankings. Ole Miss and Mississippi State moving the Egg Bowl away from Jackson, Miss.

What’s up, always i used to check web site posts here in the early hours in the morning, because i like to find out more and more.

Alan, great post. I’m having this issue my question is would this solution work for widows 7?

Yes it will

Very helpful posting, many thanks.

Has anyone had trouble getting this to work with Windows XP? It works well with all my Win& PC’s but is hit and miss on the XP.

Had a similar Issue, however a little different. This article may help you… http://www.grishbi.com/2015/03/unable-to-change-ie-zone-security-settings/

Excellent work Alan.

I know it is mentioned, but I would re-emphasize http or https as required.

As Per-Torben Sørensen suggested, use Replace. I’ve had issues with update instead of replace so I always use replace. It seems update doesn’t add something if it is missing, but replace does.

Remember rsop.msc is your friend. It doesn’t show the registry changes, but does show if an additional policy is applied that overrides the registry settings. With these specific settings, you can do a C:\>gpupdate /force, close and re-open the browser or re-run rsop.msc to see if the changes took place. All without logging out and back in, or rebooting.

Best, David

Much appreciated. Need to retain as much of the admin aspects for people doing programming while still giving them the tools needed for internal sites.

I am able to get the GP to work fine, however the site I am adding still doesn’t come up under the Intranet Zone as I have set. I am trying to add the internal IP of the site – 192.0.0.25. When I add this manually in IE, it works fine. When done through GP, it shows in IE under the Intranet zone, but doesn’t get treated like an intranet zone (File > properties, shows it as Internet). Is there a way to use the IP address instead of the domain name?

We needed to add a list of no less than 10 sites to the trusted list. Rather than doing it individually as you have shown, I exported the “Domains” key to a shared drive and then created a logon script that copies it to the local machine and then imports it to the registry. Now, whenever we need to add more trusted sites, I can just update the reg key in the shared location.

Question on using Wild Cards in the URL. I just found your post yesterday and am very excited about testing out using preferences in place of policies for our list of trusted sites.

I have several URLs that I am using wildcards in. If I enter the wildcard in the key path (Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\*.contoso.com) I end up with this listed in trusted sites in IE: http://*.contoso.com .

Will this function properly for all domains that add a prefix to .contoso.com? Also, is there anyway to use a wildcard to it would work with either http or https sites? We have several of those.

Excellent article…..working for me. One thing I want to mention that If you want to add just e.g., http://google.com it is working fine. but if you want to add http://google.com/xyz then you should add google.com/xyz after \Domains\ e.g. Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\google.com/xyz

Thanks for posting.

Is this applicable for HKLM registry location via GPP?

Since we need to implement for machine level.

Brilliant, thanks for this blog, works like a treat. thanks for your effort putting this up 5 years later and people are still coming across these things 🙂

Leave a Reply Cancel reply

Site sponsor, featured post.

site zone assignment list values

Popular Posts

site zone assignment list values

  • Best Practice (40)
  • Group Policy FAQ (3)
  • KB Focus (5)
  • Other Site Links (15)
  • Podcast (2)
  • ScreenCast (4)
  • Security (33)
  • Setting of the Week (41)
  • Site News (19)
  • TechEd (35)
  • Tutorials (117)
  • Uncategorized (6)
  • RSS - Posts
  • RSS - Comments

SuperUserTips

an endpoint admin's journal

  • Recent Posts
  • Popular Posts
  • Recent Comments

site zone assignment list values

Deploy Trusted sites zone assignment using Intune

November 6, 2023

site zone assignment list values

Zoom Desktop Client – Download older build versions from Zoom

October 31, 2023

site zone assignment list values

Uninstall Teams chat app using remediation script and a configuration profile in Intune

October 30, 2023

site zone assignment list values

Intune Last Check-in date not updating for Windows device

October 25, 2023

site zone assignment list values

How to use Event Viewer to check cause of Blue screen of Death (BSOD)

October 23, 2023

site zone assignment list values

5 Quick Mac OS Terminal commands to make a Mac user life easier

site zone assignment list values

Powershell : Find disabled users and computers in AD

' src=

  • Active Directory (1)
  • Windows (7)
  • November 2023
  • October 2023

Deploy a set of trusted sites overriding users’ ability to add trusted sites themselves. To acheive this, an Intune configuration profile Trusted site zone assignment can be deployed to devices/users group as required.

Login to Intune Portal and navigate to: Devices > Windows > Configuration Profiles .

Hit the Create button and Select New policy

site zone assignment list values

From the Create a profile menu, select Windows 10 and later for Platform , Templates for Profile type. Select Administrative templates and click Create .

site zone assignment list values

Give the profile desired name and click Next .

site zone assignment list values

In Configurations settings, select Computer Configuration and search for keyword “ Site to Zone “, Site to Zone Assignment List setting will be listed under search results. Go ahead click on it to Select it.

site zone assignment list values

Once selected, a Site to Zone Assignment List page will appear on right side explaining different zones and values required for these zone for setup. Since this profile is being used for trusted sites, we will use the Value “2” . Go ahead and select Enabled button and start entering the trusted sites as required. please ensure to set each value to “2” . See example below:

site zone assignment list values

Once done adding the list of sites, click OK to close it and Hit Next on Configuration settings page.

Add Scope tags if needed.

Under Assignments , Click Add groups to target the policy deployment to specific group of devices/users. You can also select Add all users / All all devices .

Hit Next . Then Hit Review + Save button to save.

Tags: Intune Windows

You may also like...

site zone assignment list values

[Windows 10] How to completely uninstall Flash player

  • Previous Zoom Desktop Client – Download older build versions from Zoom

guest

thanks! I was just looking for this exact solution!

logo

Managing Internet Explorer Trusted Sites with Group Policy

Internet Explorer Maintenance is dead. We all have our regrets, missed chances, and memories. But we have to move on. Depending on your love for power, you have two options. You can take the totalitarian route (known as Administrative Templates) or the benevolent method (known as Group Policy Preferences). Here are the two ways that you can configure Internet Explorer Trusted Sites with Group Policy.

Configuring IE Trusted Sites with Administrative Templates

Site to Zone Mapping allows you to configure trusted sites with Group Policy Administrative Templates. This setting can be found at:

  • Computer Configuration/Policies/Administrative Templates/Windows Components/Internet Explorer / Internet Control Panel/Security Page/Site to Zone Assignment List
  • User Configuration/Policies/Administrative Templates/Windows Components/Internet Explorer / Internet Control Panel/Security Page/Site to Zone Assignment List

When possible, use the computer configuration option as it will not impact user logons. When you enable the setting, you will be prompted for a value name (the website) and a value (the zone list). Here are the possible values and the zone that they correspond to:

  • 1 = Intranet/Local Zone
  • 2 = Trusted Sites
  • 3 = Internet/Public Zone
  • 4 = Restricted Sites

Internet Explorer Trusted Sites with Group Policy

  The screenshot above shows one trusted site and one restricted site. There is a potential downside to managing trusted sites with Administrative Templates. You will not be able to edit the trusted sites list within Internet Explorer. If you have more than four items listed, you won’t be able to see the entire list in the IE Trusted Sites window. If you view the site properties (Alt – File – Properties), you can check a specific site’s zone though. Remember this trick as it will help you when troubleshooting! You can view the entire list in the Registry by navigating to HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains. If you are an administrator, you can edit/add/remote items from this list for testing. Just be sure to run a GPUpdate /force to undo your changes.

Bonus Points : Leave a comment below explaining why a GPUpdate /force is required to undo your changes. Super Bonus Points if you answer in a haiku.

Configuring IE Trusted Sites with Group Policy Preferences Registry

You would think that Group Policy Preferences Internet Settings could set trusted sites. Unfortunately, that setting is greyed out.

Internet Explorer Trusted Sites with Group Policy

You can still configure IE site mappings with Group Policy Registry Preferences though.* The benefit of this is that your users can edit the zone lists and view all of the added sites. To set this up, create a new user side registry preference. This trick will not work under computer configuration. Enter in the following details:

  • Keypath: Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\WEBSITENAME
  • Value Name: http
  • Value Type: REG_DWORD
  • Value Data: 2

Here is an example showing DeployHappiness being set as a trusted site with registry preferences:

Internet Explorer Trusted Sites with Group Policy

If your site isn’t being placed in the Trusted Sites list, add it manually and then navigate to the registry location above. Ensure that the manual addition exactly matches your registry preference. You will also need to ensure that no Administrative Template Site to Zone settings are applied. If they are, they will wipe out your preference settings. Remember that Policies always win!

You can search your domain for site to zone settings by using this Group Policy Search script. Alan Burchill taught me this trick.

To see additional ways to configure site to zone mappings, read this very in depth example guide.

24 thoughts on “ Managing Internet Explorer Trusted Sites with Group Policy ”

I hope to replace our Site to Zone list to allow our users to enter their own in but I am not sure how to enter our entries that don’t specify a specific protocal such as http or https. So can someone tell me how I would create an entry for this:

*://*.sharepoint.com

and what about something like this – how would this be entered?

https://192.192.192.192 .:9443 (example only)

As for your first question, this info should help: https://community.spiceworks.com/topic/326140-add-trusted-sites-via-gpo-but-still-allow-users-to-add-trusted-sites?page=1#entry-2849140

As for the second question, I don’t know of a way to handle ports. In reference to your example, a link like that would be entered like this: *://192.192.192.192

This is excellent – I have used the GP preferences to add trused sites without locking users out of the setting if they need to add a site. But what about this – a program in the startup group – it is a shortcut to a file on a server – a member server of the local domain – domain.local. I want to prevent this program from prompting end-users to run it, and make sure it will run without prompting. Can this be accomplished with a GP preference as well? If so, do I need to add it to trusted sites, or to the local intranet zone or local machine zone? It would seem to be a local intranet or local machine zone I am working with here. I am not sure how to add it – whether I just need to add the local domain, or the computer name FQDN, or the path to the shared folder and the file. thanks!

This sounds like two different problems: 1. How do I get an app to run without prompting? 2. How do I make it run on startup with group policy?

The latter is easy, create it as a scheduled task that runs on startup. The former depends on what type of script it is. If it’s a vbscript then run it with cscript /b “name.vbs”.

With the old approach we had a file under trusted sites to allow the file to run. It has stopped working under 2012. Could I use this with a file? The old setting was:

file:\\Domain.com\netlogon\AsmallExe.exe

See this article on what you can configure with trusted sites: http://evilgpo.blogspot.com/2016/03/internet-explorer-site-to-zone.html

Just the ticket. Thanks a lot.

I have double-checked that the site to zone assignment policy is not configured, both under user and computer settings. We used group policy preferences because we do not want to lock down the trusted sites – only to push out the sites we want to be trusted. But for some absurd reason, the trusted sites are locked down and greyed out half the time – one day I will look and the sites are not dimmed out and will let me add or remove them. Then the next day they will be greyed out again. It is amazingly ridiculous. I am the only admin; no one else knows how to mess with the settings even if they had the admin credentials. So I have no clue why it keeps reverting back to the wrong settings. I thing our active directory needs to have dcdiag run on it a few times. Any ideas will be sincerely appreciated.

If it is locked down, it is a GP policy that is doing it (the site to zone assignment one) or a registry key that is enabling that site to zone assignment.

When you see one that does it, run a GPResult /h report.htm /f and look through that report.htm. You will see any GP settings that would block it then.

A reply to my own post – the problem was corrupted group policy on the Windows 7 computers – some of the computers were working fine. The ones that were not working, we had to delete the corrupt policy (it was preventing the updated policy settings from being applied). It was in the path C:\ProgramData\Microsoft\Group Policy\History\{policy GUID}. After deleting the corrupt policy and rebooting, it fixed the problem!

Thanks for the update Sam!

You’re welcome! I am still having some issues with the trusted sites being greyed out in IE, even though I made certain not to use site to zone assignment in the policy, and only used GP preferences to add registry items for the sites in the trusted zone. Do you know what registry key I need to be looking for, that might be causing this issue?

Many thanks! Sam S.

Are you making sure that you’re applying it under HKCU, and not under HKLM? If you configure it under HKCU, users will still have the ability to add their own entries. But if you configure it under HKLM, the option to add entries will be greyed out.

Yes, I definitely deployed the preferences under the Users GP Preferences and not computer policy/preferences. However, there are some policy settings that I set in both computer and user settings in the GPO. None of these are site to zone assignments though. These settings are for all the security settings within the zones, like, download signed activeX controls – enable, download unsigned activeX controls, Prompt… etc.. – these settings are set in the computer policy and the user policy which is probably what is wrong. I should probably just disable the computer policies in the GPO. I will try that and see if it helps. Why are all these settings available in the computer side and the user side both? Is there a reason someone would set these settings in one policy over the other?

A computer side policy is available for every user that logs in already. These are generally faster to apply and are my preferred way to configure something. However, times like this are when a user side policy would be the best route for you. Remove the computer side settings and try John’s suggestions. Let us know what you find out.

Sam, another thing you can try is to access the GPO from a Windows 7 workstation running IE 9 (and make sure that there are no current Internet Explorer policies being applied to the workstation; put it in an OU that is blocking inheritance if you have to), then drill down to “User Config\Policies\Windows Settings\Internet Explorer Maintenance\Security\Security Zones and Content Ratings”. Double-click on “Security Zones and Content Ratings”, then choose “Import…” under “Security Zones and Privacy’, click “Continue” when prompted, then click “Modify Settings, then “Trusted Sites”, then the “Sites” button. You can then make whatever changes you want (add a site, remove a site, remove the check from the https box, etc). This should give you the freedom you’re looking for :).

i`ve add multiple Sites to the Site to Zone assigment list (Trusted Sites). After a new logon, i`ve check my settings, start IE11, visit the site i`ve add to the list, press Alt – File – Properties and check the Zone. Some of the sites are correct, shown in the trusted site zone, some of them not, they are in an unkown zone (mixed). I want to check the registry path Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains but this key is empty, for HKLM and HKCU. What`s wrong?

Thanks and Regards Patrick

Are you deploying the trusted sites with Policies or registry preferences?

> comment below explaining why GPUpdate /force is required to undo your changes.

For Group Policy to apply efficiently changes trigger it.

Exceptions apply. GPUPDate force is one. Security too.

Less obtusely said: “Group Policy will normally only reprocess client side extensions that have at least one policy element that changed. The exceptions to this are Security Option settings which reapply every ~16 hours on most machines and every 5 minutes on Domain Controllers. The other exceptions are when you run a gpupdate /force, and any CSEs you configure to auto-reapply. You can view this decision tree by enabling UserEnv logging as described in http://technet.microsoft.com/en-us/library/cc775423%28v=ws.10%29.aspx ” … But not as haiku.

Hi, Is it possible to select the users you want that this GPO applies? It is because I need to add a web to trusted sites, but only to two users. Any idea?

You would need to configure these settings under user configuration. Then change the scope of the GPO from authenticated users to a group containing those two users.

With regards to deploying trusted sites via GPO, while allowing users to add their own entries, see if this post helps: http://community.spiceworks.com/topic/post/2849140

I’m finding that when I deploy Trusted Sites using GPP and the registry, users aren’t able to add entries themselves (it allows them to add to the list, but the entries don’t stick and are gone as soon as you reopen the dialog). Any ideas?

You sir, have a good last name! 🙂

Do you have any delete preferences configured to that registry key? If you manually browse to that key, do you see what the user added?

Leave a Reply Cancel reply

  • Security Essentials
  • Deploying Windows 10 (without touching a client)
  • Group Policy – Preferences to Software and Everything In Between
  • OneNote Can Centralize Your Documentation
  • Lunch and Learn: PowerShell 3
  • Lunch and Learn: Software Extraction
  • Disclosure Policy
  • Privacy Policy
  • Rebuild the Administrative Start Menu
  • Guest Posting
  • What’s This? Q&A on Sponsored Posts
  • Blogs that I Follow – 2018 Edition
  • Books to Boost Your Career!
  • Top Articles to Teach You Now!
  • Top Gadgets to be more Productive!
  • Software Tools
  • Other – eBooks, Virtual labs, etc
  • My Articles
  • Clients and Desktops
  • Group Policy
  • Deployment/MDT
  • About DeployHappiness
  • February 2024
  • October 2023
  • January 2023
  • October 2021
  • November 2020
  • October 2020
  • February 2020
  • January 2020
  • November 2019
  • October 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • August 2018
  • February 2018
  • January 2018
  • December 2017
  • October 2017
  • September 2017
  • August 2017
  • February 2017
  • January 2017
  • October 2016
  • September 2016
  • August 2016
  • February 2016
  • January 2016
  • December 2015
  • October 2015
  • September 2015
  • August 2015
  • February 2015
  • January 2015
  • December 2014
  • November 2014
  • October 2014
  • September 2014
  • August 2014
  • February 2014
  • January 2014
  • December 2013
  • November 2013
  • October 2013
  • September 2013
  • August 2013
  • Group Policy (85)
  • Best Practice (90)
  • Hardware (9)
  • Management (100)
  • Networking (3)
  • Office 365 (8)
  • Performance (23)
  • Quick Tip (26)
  • PowerShell (87)
  • Security (28)
  • Server (16)
  • Thinking about IT (14)
  • Training (6)
  • TroubleShooting (36)
  • Uncategorized (29)
  • Walkthrough (109)
  • Entries (RSS)
  • Comments (RSS)

Stack Exchange Network

Stack Exchange network consists of 183 Q&A communities including Stack Overflow , the largest, most trusted online community for developers to learn, share their knowledge, and build their careers.

Q&A for work

Connect and share knowledge within a single location that is structured and easy to search.

Assign DFS share to intranet zone via GPO?

This seems like it shouldn't be hard, but I haven't had any luck with either guessing or searching. I'll admit I'm no Windows guru, so forgive me if the answer should be obvious.

I'm trying to get Windows to stop giving me security warnings when I open files or links from a DFS share. I already have a GPO in place which does this for a couple of other network shares:

Here, I've added host1.mydomain.org and host2.mydomain.org to zone 1 (intranet), and the network shares from these hosts are correctly treated as trusted intranet sites.

However, I now want to add \\mydomain.org\shares to the intranet zone as well. Adding it just like that appears not to work (and on my client machine it appears in the list as file://*.mydomain.org ). Other things I've tried include *.mydomain.org and explicitly listing the hosts where the DFS shares originate.

"Turn on automatic detection of the intranet" is also enabled, although I've never been clear on how that actually works.

Servers and DCs are 2008 R2 and clients are (mostly) 7 Pro.

Edit: The next day, it appears that the listing of mydomain.org is in fact having the desired effect. I hadn't logged out and back in during testing; I just did a gpupdate /force and confirmed that the GPO settings appeared in the Internet Options dialog. Is this a bug or just another arcane Windows thing that I don't quite understand?

  • group-policy

eaj's user avatar

  • For those finding this via a search: run gpedit.msc to edit the policy nicely enumerated above, then gpupdate /force –  Stan Commented May 12, 2016 at 22:48

2 Answers 2

When refreshing group policy it is usually necessary to log out and for some settings a restart (sometimes 2!) is necessary. I wouldn't call it arcane but it won't be obvious if you haven't documentation regarding group policy processing.

will's user avatar

  • 1 I understand that, but when I saw that the GPO settings appeared properly in the Internet Settings after the gpupdate, I naturally assumed they had been applied. –  eaj Commented Oct 6, 2011 at 14:30
  • 1 Ok. I wonder if the network connection to the share was still alive, then had to be recreated to be recognized under the new security zone setting for the policy to take affect? –  will Commented Oct 6, 2011 at 15:20
  • 1 That sounds like a pretty good theory to me. You win the green checkmark. :) –  eaj Commented Oct 6, 2011 at 15:27

The shell (explorer.exe) is caching the policy. Simply restart the shell and many settings will start to be applied. There is no need to log out/back in for many scenarios.

Exiting the shell:

  • Windows 7: Ctrl+Shift+right click on blank area of Start Menu | Exit Explorer
  • Windows 8: Ctrl+Shift+right click on Start Menu button | Exit Explorer

Restarting shell:

  • Ctrl+Shift+Esc, File | New Task (Run...) | "explorer"

INCANDE's user avatar

You must log in to answer this question.

Not the answer you're looking for browse other questions tagged windows group-policy dfs ..

  • Featured on Meta
  • Introducing an accessibility dashboard and some upcoming changes to display...
  • We've made changes to our Terms of Service & Privacy Policy - July 2024
  • Announcing a change to the data-dump process

Hot Network Questions

  • MPs assuming office on the day of the election
  • Iterative mixing problem
  • What are some interesting applications of the theory of covering spaces?
  • Is inner speech a quale?
  • She's a black belt in judo
  • Are story points really a good measure for velocity?
  • Can I replace 2 Zinsco single pole 35amp breakers with one 35amp 2-pole?
  • Reportedly there are German-made infantry fighting vehicles in Russia's Kursk region. Has this provoked any backlash in Germany?
  • Utilising Paired T-test but data is not normally distributed and there are outliers
  • Why do most published papers hit the maximum page limit exactly?
  • Strategies for handling Maternity leave the last two weeks of the semester
  • Will lights plugged into cigarette lighter drain the battery to the point that the truck won't start?u
  • Can a train/elevator be feasible for scaling huge mountains (modern technology)?
  • Is an infinite composition of bijections always a bijection?
  • Arduino Board Getting Too Hot: Need Help Diagnosing Issue (Schematic Provided)
  • What type of concept is "mad scientist"?
  • Combining Regex and Non-Regex in the same function
  • Self-employed health insurance deduction and insurance just for my kids
  • How many kinds of contradictions are there?
  • Why do we sometimes use the concept of limits but sometimes don't forget similar kind of problems?
  • sed (or awk): print captured group or placeholder if it doesn't exist
  • Can I use specific preprocess hooks for a node type or a view mode?
  • What's so embarrassing in two wearing the same jacket?
  • Dark, cynical video game taking place in the medieval ages

site zone assignment list values

How to add a server to trusted sites

I’m not quite sure how to add a server as a trusted site with group policy. I know how to add URLs to trusted sites. I’m more confused on the syntax.

Do i just type in “serverA” or “\serverA” or do i just put the IP address? If it’s an IP address do i enter “file://10.0.0.1”?

Open the Group Policy Management Console.

Navigate to the Group Policy Object that you want to edit.

Expand the Computer Configuration or User Configuration folder, depending on whether you want to apply the policy to all users or just specific users.

Expand the Administrative Templates folder.

Expand the Windows Components folder.

Expand the Internet Explorer folder.

Click on the Security Zones and Content Ratings folder.

Double-click on the Site to Zone Assignment List policy.

Click the Enabled radio button.

Click the Show button.

In the Value name field, enter the server name in the following format: “file://servername” (replace “servername” with the actual name of the server).

In the Value field, enter the corresponding zone number for the zone that you want to add the server to:

1 for Intranet zone

2 for Trusted Sites zone

3 for Internet zone

4 for Restricted Sites zone

Click the OK button.

@spiceuser-9i0os

Thank you! I just didn’t know what to enter for the value.

Related Topics

Topic Replies Views Activity
Windows ,  ,  ,  5 793 March 6, 2016
Windows 4 189 November 20, 2014
Windows ,  ,  ,  0 109 February 24, 2010
Windows 11 16224 November 2, 2017
Windows 8 1151 October 11, 2016

site zone assignment list values

Stack Exchange Network

Stack Exchange network consists of 183 Q&A communities including Stack Overflow , the largest, most trusted online community for developers to learn, share their knowledge, and build their careers.

Q&A for work

Connect and share knowledge within a single location that is structured and easy to search.

Internet Options to add Trusted Site Greyed Out - SysPreped Windows 10 LTSB

I just deployed an custom Windows 10 ISO I created and I can't set my local file server as a trusted site in internet options. The site button is greyed out. The only change I made in the image was adding the site pre-sysprep and now It not only didn't keep the settings through the sysprep process, but also locked me from making changes to internet options. I did test this image on another computer before adding the site pre-sysprep and post deploy I was able to add the site via normal methods. Clearly somehow adding the site to trusted sites before sysprepping the OS caused the issue. Unfortunatley, this is not an easy computer to re-deploy or I would just remake the ISO and re-deploy.

Update Re Comment [The Goal is to get RID of this Message]:

  • I don't use IE or care about its "options", I just want to get rid of this nag message when I run an exe from my fileserver as almost all my software is installed on the server.

enter image description here

  • Any idea how I can reset the settings to default?
  • How can I add the site via RegEdit? I know I only need to add one site and I use the IP not DNS.

I know the keys are related to HKLM/SOFTWARE/Policies/Microsoft/Windows/CurrentVersion/Internet settings/ , I'm thinking of exporting the entire "tree" from the other computer and importing it here, but that's a hassle as well as its not my computer.

Any ideas!? Thanks!

PS: Windows 10 LTSB v 1607 x64 -Up-2-date

enter image description here

Update: I had IE11 not installed, by installing it, Internet Options now look as they used to, but the option is still greyed out!

enter image description here

Update 2: I have "reset" IE Options, but still Grey :(

enter image description here

  • internet-explorer
  • internet-security

FreeSoftwareServers's user avatar

  • I see the same photo. That registry key you mentioned shouldn’t exist at all if you don’t want policies enforced on your browser. Just delete it. Or rename it, if you want to see the effects. –  Appleoddity Commented Mar 12, 2018 at 23:49
  • I dont really care about IE, my goal is to stop the popup when I run an exe from my file server over SMB. So I'm not sure how to apply that to your comment lol –  FreeSoftwareServers Commented Mar 12, 2018 at 23:51
  • @Appleoddity I updated an image to explain just incase –  FreeSoftwareServers Commented Mar 12, 2018 at 23:53
  • Windows Explorer respects IE group policies. Are you an Administrator? –  Ramhound Commented Mar 13, 2018 at 0:17
  • I'm logged in as one, but I haven't messed much with Group Policy and I was under the impression sysprep generalize wouldn't keep group policy anyway. What GPO would I look at? –  FreeSoftwareServers Commented Mar 13, 2018 at 0:20

3 Answers 3

The issue was that Group Policy was somehow blocking me from adding into IE Options like I'm used to.

You want to configure Group Policy like so:

Navigate to Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page >> Site to Zone Assignment List

enter image description here

The "Values" are as follows:

After configuration open CMD in Administrator mode and run the following:

Now reboot and test!

https://community.spiceworks.com/topic/1182041-gpo-for-local-intranet-site http://www.grouppolicy.biz/2010/03/how-to-use-group-policy-to-configure-internet-explorer-security-zone-sites/

This worked for me even though it's for Windows XP.

All credit to the original author.

FYI, my system specs are:

LINK: Sites" button and "Custom Level" slider are grayed out in Internet Options - Security tab

This is the contents of that site should it ever get taken down.

When you open Internet Options - Security tab and click on any Zone (except Internet Zone), the Sites button may be grayed out. As a result, you may be unable to add or remove a website to the specified Zone. Additionally, you may also notice that the Custom level slider is grayed out. This prevents you from customizing the Security level for that particular Zone.

The Flags value in the registry governs the above two options (and more) for each Zone. See Description of Internet Explorer security zones registry entries for more information on the Flags value.

To enable the Sites button and the Custom Level slider for that particular Zone, follow these steps:

Open Registry Editor (regedit.exe) and navigate to

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\{Zone ID}

Backup the key by exporting it to a REG file.

  • In the right-pane, double-click Flags and click Decimal

Add 3 to the existing Value data

Example: If Flags value reads 0 (Decimal), set it to 3 (i.e., 0 + 1 + 2 )

Flags value listing (from MS-KB 182569 )

Close Registry Editor and restart your machine and follow the route in your OP.

For me, the apply button was greyed out but it works none the less.

The entry I have entered is file://PRINCE_NASEEM but yours will differ.

Ste's user avatar

  • Nice, this looks like it enables the menu operations I'm used to vs fixing via GPO. This would likely be the better fix for me to use before "Sysprepping" an image. –  FreeSoftwareServers Commented Jun 10, 2019 at 9:07
  • Thanks, I'm glad you found this useful. It's good because, if it works in win XP, then there's a good chance it works right up to win 10. –  Ste Commented Jun 11, 2019 at 10:09

I answer late, but I have the same problem. I recovered the .reg on a pc which was not impacted.

Copy the code, insert it into a text file that you rename to .reg.

BenGost's user avatar

You must log in to answer this question.

Not the answer you're looking for browse other questions tagged security internet-explorer internet-security ..

  • Featured on Meta
  • We've made changes to our Terms of Service & Privacy Policy - July 2024
  • Introducing an accessibility dashboard and some upcoming changes to display...

Hot Network Questions

  • Is Marisa Tomei in the film the Toxic Avenger?
  • Is there such a thing as icing in the propeller?
  • Reduce spacing between letters in equations
  • Iterative mixing problem
  • Tips/strategies to managing my debt
  • Why did Rio Morales say, "De-escalated that one"?
  • Are story points really a good measure for velocity?
  • Automatically closing a water valve after a few minutes
  • Self-employed health insurance deduction and insurance just for my kids
  • Is there a canonical example of the computer misinterpreting a command in any Star Trek franchise?
  • Can a Hall sensor be tested with just basic test gear?
  • Is there mutable aliasing in this list of variable references?
  • Design patterns - benefits of using with Apex code
  • Why do I see different declension tables for the same noun in different sources?
  • Is there a pre-defined compiler macro for legacy Microsoft C 5.10 to get the compiler's name and version number?
  • commands execution based on file size fails with no apparent issues
  • What's so embarrassing in two wearing the same jacket?
  • Which Boolean Math mode should I use?
  • Strategies for handling Maternity leave the last two weeks of the semester
  • What type of concept is "mad scientist"?
  • On the use of overtly
  • Will a spaceship that never stops between earth and mars save fuel?
  • In Europe, are you allowed to enter an intersection on red light in order to allow emergency vehicles to pass?
  • Best (safest) order of travel for Russia and the USA (short research trip)

site zone assignment list values

site zone assignment list values

Prajwal Desai

How To Add Sites to Internet Explorer Restricted Zone

In this post we will see the steps on how to add sites to Internet Explorer restricted zone.

To configure Internet Explorer security zones there are multiple ways to do it, in this post we will configure a group policy for the users and use Site to Zone assignment list policy setting to add the websites or URL to the restricted site zone.

This policy setting allows you to manage a list of sites that you want to associate with a particular security zone. Internet Explorer has 4 security zones, numbered 1-4, and these are used by this policy setting to associate sites to zones.

  • Intranet zone
  • Trusted Sites zone
  • Internet zone
  • Restricted Sites zone

The zone numbers have associated security settings that apply to all of the sites in the zone. Using the Site to Zone assignment list policy setting we will see how to add sites to the Internet Explorer restricted zone.

Please note that Site to Zone Assignment List policy setting is available for both Computer Configuration and User Configuration.

Launch the Group Policy Management Tool, right click on the domain and create a new group policy. Right the policy and click Edit .

How To Add Sites to Internet Explorer Restricted Zone

In the Group Policy Management Editor navigate to User Configuration > Administrative Templates > Windows Components > Internet Explorer > Internet Control Panel > Security Page.

If you want to apply the group policy for the computers then navigate to – Computer Configuration > Administrative Templates > Windows Components > Internet Explore r >  Internet Control Panel > Security Page.

On the right hand side, right click the policy setting Site to Zone Assignment List and click Edit .

How To Add Sites to Internet Explorer Restricted Zone

Click Enabled first and then under the Options click Show .  You need to enter the zone assignments. As stated earlier in this post Internet Explorer has 4 security zones and the zone numbers have associated security settings that apply to all of the sites in the zone.

We will be adding a URL to the Restricted Sites Zone . So enter the value name as the site URL that to Restricted Sites zone and enter the value as 4 . Click OK and close the Group Policy Management Editor.

How To Add Sites to Internet Explorer Restricted Zone

We will be applying the group policy to a group that consists of users. In the Security Filtering section, click Add and select the group .

How To Add Sites to Internet Explorer Restricted Zone

Login to the client computer and launch the Internet Explorer . Click on Tools > Internet Options > Security Tab > Restricted Sites > Click Sites .

Notice that the URL is added to the Restricted Sites zone and user cannot remove it from the list.

How To Add Sites to Internet Explorer Restricted Zone

Prajwal Desai is a Microsoft MVP in Intune and SCCM. He writes articles on SCCM, Intune, Windows 365, Windows Server, Windows 11, WordPress and other topics, with the goal of providing people with useful information.

This browser is no longer supported.

Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.

Policy CSP - InternetExplorer

  • 24 contributors

This CSP contains ADMX-backed policies which require a special SyncML format to enable or disable. You must specify the data type in the SyncML as <Format>chr</Format> . For details, see Understanding ADMX-backed policies .

The payload of the SyncML must be XML-encoded; for this XML encoding, there are a variety of online encoders that you can use. To avoid encoding the payload, you can use CDATA if your MDM supports it. For more information, see CDATA Sections .

Logo of Windows Insider.

This CSP contains some settings that are under development and only applicable for Windows Insider Preview builds . These settings are subject to change and may have dependencies on other features or services in preview.

AddSearchProvider

Scope Editions Applicable OS
✅ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 1703 [10.0.15063] and later

This policy setting allows you to add a specific list of search providers to the user's default list of search providers. Normally, search providers can be added from third-party toolbars or in Setup. The user can also add a search provider from the provider's website.

  • If you enable this policy setting, the user can add and remove search providers, but only from the set of search providers specified in the list of policy keys for search providers (found under [HKCU or HKLM\Software\policies\Microsoft\Internet Explorer\SearchScopes]).

This list can be created from a custom administrative template file. For information about creating this custom administrative template file, see the Internet Explorer documentation on search providers.

  • If you disable or don't configure this policy setting, the user can configure their list of search providers unless another policy setting restricts such configuration.

Description framework properties :

Property name Property value
Format (string)
Access Type Add, Delete, Get, Replace

This is an ADMX-backed policy and requires SyncML format for configuration. For an example of SyncML format, refer to Enabling a policy .

ADMX mapping :

Name Value
Name AddSearchProvider
Friendly Name Add a specific list of search providers to the user's list of search providers
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions
Registry Value Name AddPolicySearchProviders
ADMX File Name inetres.admx

AllowActiveXFiltering

This policy setting controls the ActiveX Filtering feature for websites that are running ActiveX controls. The user can choose to turn off ActiveX Filtering for specific websites so that ActiveX controls can run properly.

If you enable this policy setting, ActiveX Filtering is enabled by default for the user. The user can't turn off ActiveX Filtering, although they may add per-site exceptions.

If you disable or don't configure this policy setting, ActiveX Filtering isn't enabled by default for the user. The user can turn ActiveX Filtering on or off.

Name Value
Name TurnOnActiveXFiltering
Friendly Name Turn on ActiveX Filtering
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Safety\ActiveXFiltering
Registry Value Name IsEnabled
ADMX File Name inetres.admx

AllowAddOnList

This policy setting allows you to manage a list of add-ons to be allowed or denied by Internet Explorer. Add-ons in this case are controls like ActiveX Controls, Toolbars, and Browser Helper Objects (BHOs) which are specifically written to extend or enhance the functionality of the browser or web pages.

This list can be used with the 'Deny all add-ons unless specifically allowed in the Add-on List' policy setting, which defines whether add-ons not listed here are assumed to be denied.

  • If you enable this policy setting, you can enter a list of add-ons to be allowed or denied by Internet Explorer. For each entry that you add to the list, enter the following information:

Name of the Value - the CLSID (class identifier) for the add-on you wish to add to the list. The CLSID should be in brackets for example, '{000000000-0000-0000-0000-0000000000000}'. The CLSID for an add-on can be obtained by reading the OBJECT tag from a Web page on which the add-on is referenced.

Value - A number indicating whether Internet Explorer should deny or allow the add-on to be loaded. To specify that an add-on should be denied enter a 0 (zero) into this field. To specify that an add-on should be allowed, enter a 1 (one) into this field. To specify that an add-on should be allowed and also permit the user to manage the add-on through Add-on Manager, enter a 2 (two) into this field.

  • If you disable this policy setting, the list is deleted. The 'Deny all add-ons unless specifically allowed in the Add-on List' policy setting will still determine whether add-ons not in this list are assumed to be denied.
Name Value
Name AddonManagement_AddOnList
Friendly Name Add-on List
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Security Features > Add-on Management
Registry Key Name Software\Microsoft\Windows\CurrentVersion\Policies\Ext
Registry Value Name ListBox_Support_CLSID
ADMX File Name inetres.admx

AllowAutoComplete

Scope Editions Applicable OS
❌ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 1709 [10.0.16299] and later

This AutoComplete feature can remember and suggest User names and passwords on Forms.

If you enable this setting, the user can't change "User name and passwords on forms" or "prompt me to save passwords". The Auto Complete feature for User names and passwords on Forms will be turned on. You have to decide whether to select "prompt me to save passwords".

If you disable this setting the user can't change "User name and passwords on forms" or "prompt me to save passwords". The Auto Complete feature for User names and passwords on Forms is turned off. The user also can't opt to be prompted to save passwords.

If you don't configure this setting, the user has the freedom of turning on Auto complete for User name and passwords on forms and the option of prompting to save passwords. To display this option, the users open the Internet Options dialog box, click the Contents Tab and click the Settings button.

Name Value
Name RestrictFormSuggestPW
Friendly Name Turn on the auto-complete feature for user names and passwords on forms
Location User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main
Registry Value Name FormSuggest Passwords
ADMX File Name inetres.admx

AllowCertificateAddressMismatchWarning

Scope Editions Applicable OS
✅ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 1709 [10.0.16299] and later

This policy setting allows you to turn on the certificate address mismatch security warning. When this policy setting is turned on, the user is warned when visiting Secure HTTP (HTTPS) websites that present certificates issued for a different website address. This warning helps prevent spoofing attacks.

If you enable this policy setting, the certificate address mismatch warning always appears.

If you disable or don't configure this policy setting, the user can choose whether the certificate address mismatch warning appears (by using the Advanced page in the Internet Control panel).

Name Value
Name IZ_PolicyWarnCertMismatch
Friendly Name Turn on certificate address mismatch warning
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
Registry Value Name WarnOnBadCertRecving
ADMX File Name inetres.admx

AllowDeletingBrowsingHistoryOnExit

This policy setting allows the automatic deletion of specified items when the last browser window closes. The preferences selected in the Delete Browsing History dialog box (such as deleting temporary Internet files, cookies, history, form data, and passwords) are applied, and those items are deleted.

If you enable this policy setting, deleting browsing history on exit's turned on.

If you disable this policy setting, deleting browsing history on exit's turned off.

If you don't configure this policy setting, it can be configured on the General tab in Internet Options.

If the "Prevent access to Delete Browsing History" policy setting is enabled, this policy setting has no effect.

Name Value
Name DBHDisableDeleteOnExit
Friendly Name Allow deleting browsing history on exit
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Delete Browsing History
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Privacy
Registry Value Name ClearBrowsingHistoryOnExit
ADMX File Name inetres.admx

AllowEnhancedProtectedMode

Enhanced Protected Mode provides additional protection against malicious websites by using 64-bit processes on 64-bit versions of Windows. For computers running at least Windows 8, Enhanced Protected Mode also limits the locations Internet Explorer can read from in the registry and the file system.

If you enable this policy setting, Enhanced Protected Mode will be turned on. Any zone that has Protected Mode enabled will use Enhanced Protected Mode. Users won't be able to disable Enhanced Protected Mode.

If you disable this policy setting, Enhanced Protected Mode will be turned off. Any zone that has Protected Mode enabled will use the version of Protected Mode introduced in Internet Explorer 7 for Windows Vista.

If you don't configure this policy, users will be able to turn on or turn off Enhanced Protected Mode on the Advanced tab of the Internet Options dialog.

Name Value
Name Advanced_EnableEnhancedProtectedMode
Friendly Name Turn on Enhanced Protected Mode
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Advanced Page
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main
Registry Value Name Isolation
ADMX File Name inetres.admx

AllowEnhancedSuggestionsInAddressBar

Scope Editions Applicable OS
✅ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 1903 [10.0.18362] and later

This policy setting allows Internet Explorer to provide enhanced suggestions as the user types in the Address bar. To provide enhanced suggestions, the user's keystrokes are sent to Microsoft through Microsoft services.

If you enable this policy setting, users receive enhanced suggestions while typing in the Address bar. In addition, users won't be able to change the Suggestions setting on the Settings charm.

If you disable this policy setting, users won't receive enhanced suggestions while typing in the Address bar. In addition, users won't be able to change the Suggestions setting on the Settings charm.

If you don't configure this policy setting, users can change the Suggestions setting on the Settings charm.

Name Value
Name AllowServicePoweredQSA
Friendly Name Allow Microsoft services to provide enhanced suggestions as the user types in the Address bar
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer
Registry Value Name AllowServicePoweredQSA
ADMX File Name inetres.admx

AllowEnterpriseModeFromToolsMenu

This policy setting lets you decide whether users can turn on Enterprise Mode for websites with compatibility issues. Optionally, this policy also lets you specify where to get reports (through post messages) about the websites for which users turn on Enterprise Mode using the Tools menu.

If you turn this setting on, users can see and use the Enterprise Mode option from the Tools menu. If you turn this setting on, but don't specify a report location, Enterprise Mode will still be available to your users, but you won't get any reports.

If you disable or don't configure this policy setting, the menu option won't appear and users won't be able to run websites in Enterprise Mode.

Name Value
Name EnterpriseModeEnable
Friendly Name Let users turn on and use Enterprise Mode from the Tools menu
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main\EnterpriseMode
ADMX File Name inetres.admx

AllowEnterpriseModeSiteList

This policy setting lets you specify where to find the list of websites you want opened using Enterprise Mode IE, instead of Standard mode, because of compatibility issues. Users can't edit this list.

If you enable this policy setting, Internet Explorer downloads the website list from your location (HKCU or HKLM\Software\policies\Microsoft\Internet Explorer\Main\EnterpriseMode), opening all listed websites using Enterprise Mode IE.

If you disable or don't configure this policy setting, Internet Explorer opens all websites using Standards mode.

Name Value
Name EnterpriseModeSiteList
Friendly Name Use the Enterprise Mode IE website list
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main\EnterpriseMode
ADMX File Name inetres.admx

AllowFallbackToSSL3

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 1709 [10.0.16299] and later

This policy setting allows you to block an insecure fallback to SSL 3.0. When this policy is enabled, Internet Explorer will attempt to connect to sites using SSL 3.0 or below when TLS 1.0 or greater fails.

We recommend that you don't allow insecure fallback in order to prevent a man-in-the-middle attack.

This policy doesn't affect which security protocols are enabled.

If you disable this policy, system defaults will be used.

Name Value
Name Advanced_EnableSSL3Fallback
Friendly Name Allow fallback to SSL 3.0 (Internet Explorer)
Location Computer Configuration
Path Windows Components > Internet Explorer > Security Features
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
ADMX File Name inetres.admx

AllowInternetExplorer7PolicyList

This policy setting allows you to add specific sites that must be viewed in Internet Explorer 7 Compatibility View.

If you enable this policy setting, the user can add and remove sites from the list, but the user can't remove the entries that you specify.

If you disable or don't configure this policy setting, the user can add and remove sites from the list.

Name Value
Name CompatView_UsePolicyList
Friendly Name Use Policy List of Internet Explorer 7 sites
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Compatibility View
Registry Key Name Software\Policies\Microsoft\Internet Explorer\BrowserEmulation\PolicyList
ADMX File Name inetres.admx

AllowInternetExplorerStandardsMode

This policy setting controls how Internet Explorer displays local intranet content. Intranet content is defined as any webpage that belongs to the local intranet security zone.

If you enable this policy setting, Internet Explorer uses the current user agent string for local intranet content. Additionally, all local intranet Standards Mode pages appear in the Standards Mode available with the latest version of Internet Explorer. The user can't change this behavior through the Compatibility View Settings dialog box.

If you disable this policy setting, Internet Explorer uses an Internet Explorer 7 user agent string (with an additional string appended) for local intranet content. Additionally, all local intranet Standards Mode pages appear in Internet Explorer 7 Standards Mode. The user can't change this behavior through the Compatibility View Settings dialog box.

If you don't configure this policy setting, Internet Explorer uses an Internet Explorer 7 user agent string (with an additional string appended) for local intranet content. Additionally, all local intranet Standards Mode pages appear in Internet Explorer 7 Standards Mode. This option results in the greatest compatibility with existing webpages, but newer content written to common Internet standards may be displayed incorrectly. This option matches the default behavior of Internet Explorer.

Name Value
Name CompatView_IntranetSites
Friendly Name Turn on Internet Explorer Standards Mode for local intranet
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Compatibility View
Registry Key Name Software\Policies\Microsoft\Internet Explorer\BrowserEmulation
Registry Value Name IntranetCompatibilityMode
ADMX File Name inetres.admx

AllowInternetZoneTemplate

This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.

If you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.

If you disable this template policy setting, no security level is configured.

If you don't configure this template policy setting, no security level is configured.

Note. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.

Note. It's recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.

Name Value
Name IZ_PolicyInternetZoneTemplate
Friendly Name Internet Zone Template
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Template Policies
Registry Value Name InternetZoneTemplate
ADMX File Name inetres.admx

AllowIntranetZoneTemplate

Name Value
Name IZ_PolicyIntranetZoneTemplate
Friendly Name Intranet Zone Template
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Intranet Settings\Template Policies
Registry Value Name IntranetZoneTemplate
ADMX File Name inetres.admx

AllowLegacyURLFields

Scope Editions Applicable OS
✅ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows Insider Preview
Name Value
Name AllowLegacyURLFields
ADMX File Name inetres.admx

AllowLocalMachineZoneTemplate

Name Value
Name IZ_PolicyLocalMachineZoneTemplate
Friendly Name Local Machine Zone Template
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Local Machine Zone Settings\Template Policies
Registry Value Name LocalMachineZoneTemplate
ADMX File Name inetres.admx

AllowLockedDownInternetZoneTemplate

Name Value
Name IZ_PolicyInternetZoneLockdownTemplate
Friendly Name Locked-Down Internet Zone Template
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Lockdown Settings\Template Policies
Registry Value Name InternetZoneLockdownTemplate
ADMX File Name inetres.admx

AllowLockedDownIntranetZoneTemplate

Name Value
Name IZ_PolicyIntranetZoneLockdownTemplate
Friendly Name Locked-Down Intranet Zone Template
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Intranet Lockdown Settings\Template Policies
Registry Value Name IntranetZoneLockdownTemplate
ADMX File Name inetres.admx

AllowLockedDownLocalMachineZoneTemplate

Name Value
Name IZ_PolicyLocalMachineZoneLockdownTemplate
Friendly Name Locked-Down Local Machine Zone Template
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Local Machine Zone Lockdown Settings\Template Policies
Registry Value Name LocalMachineZoneLockdownTemplate
ADMX File Name inetres.admx

AllowLockedDownRestrictedSitesZoneTemplate

Name Value
Name IZ_PolicyRestrictedSitesZoneLockdownTemplate
Friendly Name Locked-Down Restricted Sites Zone Template
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Restricted Sites Lockdown Settings\Template Policies
Registry Value Name RestrictedSitesZoneLockdownTemplate
ADMX File Name inetres.admx

AllowOneWordEntry

This policy allows the user to go directly to an intranet site for a one-word entry in the Address bar.

If you enable this policy setting, Internet Explorer goes directly to an intranet site for a one-word entry in the Address bar, if it's available.

If you disable or don't configure this policy setting, Internet Explorer doesn't go directly to an intranet site for a one-word entry in the Address bar.

Name Value
Name UseIntranetSiteForOneWordEntry
Friendly Name Go to an intranet site for a one-word entry in the Address bar
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Settings > Advanced settings > Browsing
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main
Registry Value Name GotoIntranetSiteForSingleWordEntry
ADMX File Name inetres.admx

AllowSaveTargetAsInIEMode

Scope Editions Applicable OS
✅ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ [10.0.20348] and later
✅ Windows 10, version 1903 [10.0.18362.1350] and later
✅ Windows 10, version 2004 with [10.0.19041.789] and later

This policy setting allows admins to enable "Save Target As" context menu in Internet Explorer mode.

If you enable this policy, "Save Target As" will show up in the Internet Explorer mode context menu and work the same as Internet Explorer.

If you disable or don't configure this policy setting, "Save Target As" won't show up in the Internet Explorer mode context menu.

For more information, see https://go.microsoft.com/fwlink/?linkid=2102115

Name Value
Name AllowSaveTargetAsInIEMode
Friendly Name Allow "Save Target As" in Internet Explorer mode
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main\EnterpriseMode
Registry Value Name AllowSaveTargetAsInIEMode
ADMX File Name inetres.admx

AllowSiteToZoneAssignmentList

This policy setting allows you to manage a list of sites that you want to associate with a particular security zone. These zone numbers have associated security settings that apply to all of the sites in the zone.

Internet Explorer has 4 security zones, numbered 1-4, and these are used by this policy setting to associate sites to zones. They are: (1) Intranet zone, (2) Trusted Sites zone, (3) Internet zone, and (4) Restricted Sites zone. Security settings can be set for each of these zones through other policy settings, and their default settings are: Trusted Sites zone (Low template), Intranet zone (Medium-Low template), Internet zone (Medium template), and Restricted Sites zone (High template). (The Local Machine zone and its locked down equivalent have special security settings that protect your local computer).

  • If you enable this policy setting, you can enter a list of sites and their related zone numbers. The association of a site with a zone will ensure that the security settings for the specified zone are applied to the site. For each entry that you add to the list, enter the following information:

Valuename - A host for an intranet site, or a fully qualified domain name for other sites. The valuename may also include a specific protocol. For example, if you enter https://www.contoso.com as the valuename, other protocols aren't affected. If you enter just www.contoso.com , then all protocols are affected for that site, including http, https, ftp, and so on. The site may also be expressed as an IP address (e.g., 127.0.0.1) or range (e.g., 127.0.0.1-10). To avoid creating conflicting policies, don't include additional characters after the domain such as trailing slashes or URL path. For example, policy settings for www.contoso.com and www.contoso.com/mail would be treated as the same policy setting by Internet Explorer, and would therefore be in conflict.

Value - A number indicating the zone with which this site should be associated for security settings. The Internet Explorer zones described above are 1-4.

  • If you disable or don't configure this policy, users may choose their own site-to-zone assignments.

This policy is a list that contains the site and index value.

Name Value
Name IZ_Zonemaps
Friendly Name Site to Zone Assignment List
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
Registry Value Name ListBox_Support_ZoneMapKey
ADMX File Name inetres.admx

The list is a set of pairs of strings. Each string is separated by F000. Each pair of strings is stored as a registry name and value. The registry name is the site and the value is an index. The index has to be sequential. See an example below.

Value and index pairs in the SyncML example:

  • https://adfs.contoso.org 1
  • https://microsoft.com 2

AllowsLockedDownTrustedSitesZoneTemplate

Name Value
Name IZ_PolicyTrustedSitesZoneLockdownTemplate
Friendly Name Locked-Down Trusted Sites Zone Template
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Trusted Sites Lockdown Settings\Template Policies
Registry Value Name TrustedSitesZoneLockdownTemplate
ADMX File Name inetres.admx

AllowSoftwareWhenSignatureIsInvalid

This policy setting allows you to manage whether software, such as ActiveX controls and file downloads, can be installed or run by the user even though the signature is invalid. An invalid signature might indicate that someone has tampered with the file.

If you enable this policy setting, users will be prompted to install or run files with an invalid signature.

If you disable this policy setting, users can't run or install files with an invalid signature.

If you don't configure this policy, users can choose to run or install files with an invalid signature.

Name Value
Name Advanced_InvalidSignatureBlock
Friendly Name Allow software to run or install even if the signature is invalid
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Advanced Page
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Download
Registry Value Name RunInvalidSignatures
ADMX File Name inetres.admx

AllowsRestrictedSitesZoneTemplate

Name Value
Name IZ_PolicyRestrictedSitesZoneTemplate
Friendly Name Restricted Sites Zone Template
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Restricted Sites Settings\Template Policies
Registry Value Name RestrictedSitesZoneTemplate
ADMX File Name inetres.admx

AllowSuggestedSites

This policy setting controls the Suggested Sites feature, which recommends websites based on the user's browsing activity. Suggested Sites reports a user's browsing history to Microsoft to suggest sites that the user might want to visit.

If you enable this policy setting, the user isn't prompted to enable Suggested Sites. The user's browsing history is sent to Microsoft to produce suggestions.

If you disable this policy setting, the entry points and functionality associated with this feature are turned off.

If you don't configure this policy setting, the user can turn on and turn off the Suggested Sites feature.

Name Value
Name EnableSuggestedSites
Friendly Name Turn on Suggested Sites
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Suggested Sites
Registry Value Name Enabled
ADMX File Name inetres.admx

AllowTrustedSitesZoneTemplate

Name Value
Name IZ_PolicyTrustedSitesZoneTemplate
Friendly Name Trusted Sites Zone Template
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Trusted Sites Settings\Template Policies
Registry Value Name TrustedSitesZoneTemplate
ADMX File Name inetres.admx

CheckServerCertificateRevocation

This policy setting allows you to manage whether Internet Explorer will check revocation status of servers' certificates. Certificates are revoked when they've been compromised or are no longer valid, and this option protects users from submitting confidential data to a site that may be fraudulent or not secure.

If you enable this policy setting, Internet Explorer will check to see if server certificates have been revoked.

If you disable this policy setting, Internet Explorer won't check server certificates to see if they've been revoked.

If you don't configure this policy setting, Internet Explorer won't check server certificates to see if they've been revoked.

Name Value
Name Advanced_CertificateRevocation
Friendly Name Check for server certificate revocation
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Advanced Page
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
Registry Value Name CertificateRevocation
ADMX File Name inetres.admx

CheckSignaturesOnDownloadedPrograms

This policy setting allows you to manage whether Internet Explorer checks for digital signatures (which identifies the publisher of signed software and verifies it hasn't been modified or tampered with) on user computers before downloading executable programs.

If you enable this policy setting, Internet Explorer will check the digital signatures of executable programs and display their identities before downloading them to user computers.

If you disable this policy setting, Internet Explorer won't check the digital signatures of executable programs or display their identities before downloading them to user computers.

If you don't configure this policy, Internet Explorer won't check the digital signatures of executable programs or display their identities before downloading them to user computers.

Name Value
Name Advanced_DownloadSignatures
Friendly Name Check for signatures on downloaded programs
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Advanced Page
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Download
Registry Value Name CheckExeSignatures
ADMX File Name inetres.admx

ConfigureEdgeRedirectChannel

Enables you to configure up to three versions of Microsoft Edge to open a redirected site (in order of preference). Use this policy if your environment is configured to redirect sites from Internet Explorer 11 to Microsoft Edge. If any of the chosen versions aren't installed on the device, that preference will be bypassed.

If both the Windows Update for the next version of Microsoft Edge* and Microsoft Edge Stable channel are installed, the following behaviors occur:

If you disable or don't configure this policy, Microsoft Edge Stable channel is used. This is the default behavior.

If you enable this policy, you can configure redirected sites to open in up to three of the following channels where:

1 = Microsoft Edge Stable 2 = Microsoft Edge Beta version 77 or later 3 = Microsoft Edge Dev version 77 or later 4 = Microsoft Edge Canary version 77 or later.

If the Windows Update for the next version of Microsoft Edge* or Microsoft Edge Stable channel aren't installed, the following behaviors occur:

If you disable or don't configure this policy, Microsoft Edge version 45 or earlier is automatically used. This is the default behavior.

0 = Microsoft Edge version 45 or earlier 1 = Microsoft Edge Stable 2 = Microsoft Edge Beta version 77 or later 3 = Microsoft Edge Dev version 77 or later 4 = Microsoft Edge Canary version 77 or later.

  • For more information about the Windows update for the next version of Microsoft Edge including how to disable it, see< https://go.microsoft.com/fwlink/?linkid=2102115> . This update applies only to Windows 10 version 1709 and higher.
Name Value
Name NeedEdgeBrowser
Friendly Name Configure which channel of Microsoft Edge to use for opening redirected sites
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main\EnterpriseMode
ADMX File Name inetres.admx

ConsistentMimeHandlingInternetExplorerProcesses

Internet Explorer uses Multipurpose Internet Mail Extensions (MIME) data to determine file handling procedures for files received through a Web server.

This policy setting determines whether Internet Explorer requires that all file-type information provided by Web servers be consistent. For example, if the MIME type of a file is text/plain but the MIME sniff indicates that the file is really an executable file, Internet Explorer renames the file by saving it in the Internet Explorer cache and changing its extension.

If you enable this policy setting, Internet Explorer requires consistent MIME data for all received files.

If you disable this policy setting, Internet Explorer won't require consistent MIME data for all received files.

If you don't configure this policy setting, Internet Explorer requires consistent MIME data for all received files.

Name Value
Name IESF_PolicyExplorerProcesses_5
Friendly Name Internet Explorer Processes
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Security Features > Consistent Mime Handling
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING
ADMX File Name inetres.admx

DisableActiveXVersionListAutoDownload

Scope Editions Applicable OS
❌ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 1903 [10.0.18362] and later

This setting determines whether IE automatically downloads updated versions of Microsoft's VersionList. XML. IE uses this file to determine whether an ActiveX control should be stopped from loading.

If you enable this setting, IE stops downloading updated versions of VersionList. XML. Turning off this automatic download breaks the out-of-date ActiveX control blocking feature by not letting the version list update with newly outdated controls, potentially compromising the security of your computer.

If you disable or don't configure this setting, IE continues to download updated versions of VersionList. XML.

For more information, see "Out-of-date ActiveX control blocking" in the Internet Explorer TechNet library.

Name Value
Name VersionListAutomaticDownloadDisable
Friendly Name Turn off automatic download of the ActiveX VersionList
Location User Configuration
Path Windows Components > Internet Explorer > Security Features > Add-on Management
Registry Key Name Software\Microsoft\Internet Explorer\VersionManager
Registry Value Name DownloadVersionList
ADMX File Name inetres.admx

DisableBypassOfSmartScreenWarnings

This policy setting determines whether the user can bypass warnings from SmartScreen Filter. SmartScreen Filter prevents the user from browsing to or downloading from sites that are known to host malicious content. SmartScreen Filter also prevents the execution of files that are known to be malicious.

If you enable this policy setting, SmartScreen Filter warnings block the user.

If you disable or don't configure this policy setting, the user can bypass SmartScreen Filter warnings.

Name Value
Name DisableSafetyFilterOverride
Friendly Name Prevent bypassing SmartScreen Filter warnings
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\PhishingFilter
Registry Value Name PreventOverride
ADMX File Name inetres.admx

DisableBypassOfSmartScreenWarningsAboutUncommonFiles

This policy setting determines whether the user can bypass warnings from SmartScreen Filter. SmartScreen Filter warns the user about executable files that Internet Explorer users don't commonly download from the Internet.

Name Value
Name DisableSafetyFilterOverrideForAppRepUnknown
Friendly Name Prevent bypassing SmartScreen Filter warnings about files that are not commonly downloaded from the Internet
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\PhishingFilter
Registry Value Name PreventOverrideAppRepUnknown
ADMX File Name inetres.admx

DisableCompatView

This policy setting controls the Compatibility View feature, which allows the user to fix website display problems that he or she may encounter while browsing.

If you enable this policy setting, the user can't use the Compatibility View button or manage the Compatibility View sites list.

If you disable or don't configure this policy setting, the user can use the Compatibility View button and manage the Compatibility View sites list.

Name Value
Name CompatView_DisableList
Friendly Name Turn off Compatibility View
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Compatibility View
Registry Key Name Software\Policies\Microsoft\Internet Explorer\BrowserEmulation
Registry Value Name DisableSiteListEditing
ADMX File Name inetres.admx

DisableConfiguringHistory

This setting specifies the number of days that Internet Explorer tracks views of pages in the History List. To access the Temporary Internet Files and History Settings dialog box, from the Menu bar, on the Tools menu, click Internet Options, click the General tab, and then click Settings under Browsing history.

If you enable this policy setting, a user can't set the number of days that Internet Explorer tracks views of the pages in the History List. You must specify the number of days that Internet Explorer tracks views of pages in the History List. Users can't delete browsing history.

If you disable or don't configure this policy setting, a user can set the number of days that Internet Explorer tracks views of pages in the History list. Users can delete browsing history.

Name Value
Name RestrictHistory
Friendly Name Disable "Configuring History"
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Delete Browsing History
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Control Panel
Registry Value Name History
ADMX File Name inetres.admx

DisableCrashDetection

This policy setting allows you to manage the crash detection feature of add-on Management.

If you enable this policy setting, a crash in Internet Explorer will exhibit behavior found in Windows XP Professional Service Pack 1 and earlier, namely to invoke Windows Error Reporting. All policy settings for Windows Error Reporting continue to apply.

If you disable or don't configure this policy setting, the crash detection feature for add-on management will be functional.

Name Value
Name AddonManagement_RestrictCrashDetection
Friendly Name Turn off Crash Detection
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Restrictions
Registry Value Name NoCrashDetection
ADMX File Name inetres.admx

DisableCustomerExperienceImprovementProgramParticipation

This policy setting prevents the user from participating in the Customer Experience Improvement Program (CEIP).

If you enable this policy setting, the user can't participate in the CEIP, and the Customer Feedback Options command doesn't appear on the Help menu.

If you disable this policy setting, the user must participate in the CEIP, and the Customer Feedback Options command doesn't appear on the Help menu.

If you don't configure this policy setting, the user can choose to participate in the CEIP.

Name Value
Name SQM_DisableCEIP
Friendly Name Prevent participation in the Customer Experience Improvement Program
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\SQM
Registry Value Name DisableCustomerImprovementProgram
ADMX File Name inetres.admx

DisableDeletingUserVisitedWebsites

This policy setting prevents the user from deleting the history of websites that he or she has visited. This feature is available in the Delete Browsing History dialog box.

If you enable this policy setting, websites that the user has visited are preserved when he or she clicks Delete.

If you disable this policy setting, websites that the user has visited are deleted when he or she clicks Delete.

If you don't configure this policy setting, the user can choose whether to delete or preserve visited websites when he or she clicks Delete.

If the "Prevent access to Delete Browsing History" policy setting is enabled, this policy setting is enabled by default.

Name Value
Name DBHDisableDeleteHistory
Friendly Name Prevent deleting websites that the user has visited
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Delete Browsing History
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Privacy
Registry Value Name CleanHistory
ADMX File Name inetres.admx

DisableEnclosureDownloading

This policy setting prevents the user from having enclosures (file attachments) downloaded from a feed to the user's computer.

If you enable this policy setting, the user can't set the Feed Sync Engine to download an enclosure through the Feed property page. A developer can't change the download setting through the Feed APIs.

If you disable or don't configure this policy setting, the user can set the Feed Sync Engine to download an enclosure through the Feed property page. A developer can change the download setting through the Feed APIs.

Name Value
Name Disable_Downloading_of_Enclosures
Friendly Name Prevent downloading of enclosures
Location Computer and User Configuration
Path Windows Components > RSS Feeds
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Feeds
Registry Value Name DisableEnclosureDownload
ADMX File Name inetres.admx

DisableEncryptionSupport

This policy setting allows you to turn off support for Transport Layer Security (TLS) 1.0, TLS 1.1, TLS 1.2, Secure Sockets Layer (SSL) 2.0, or SSL 3.0 in the browser. TLS and SSL are protocols that help protect communication between the browser and the target server. When the browser attempts to set up a protected communication with the target server, the browser and server negotiate which protocol and version to use. The browser and server attempt to match each other's list of supported protocols and versions, and they select the most preferred match.

If you enable this policy setting, the browser negotiates or doesn't negotiate an encryption tunnel by using the encryption methods that you select from the drop-down list.

If you disable or don't configure this policy setting, the user can select which encryption method the browser supports.

SSL 2.0 is off by default and is no longer supported starting with Windows 10 Version 1607. SSL 2.0 is an outdated security protocol, and enabling SSL 2.0 impairs the performance and functionality of TLS 1.0.

Name Value
Name Advanced_SetWinInetProtocols
Friendly Name Turn off encryption support
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Advanced Page
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
ADMX File Name inetres.admx

DisableFeedsBackgroundSync

This policy setting controls whether to have background synchronization for feeds and Web Slices.

If you enable this policy setting, the ability to synchronize feeds and Web Slices in the background is turned off.

If you disable or don't configure this policy setting, the user can synchronize feeds and Web Slices in the background.

Name Value
Name Disable_Background_Syncing
Friendly Name Turn off background synchronization for feeds and Web Slices
Location Computer and User Configuration
Path Windows Components > RSS Feeds
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Feeds
Registry Value Name BackgroundSyncStatus
ADMX File Name inetres.admx

DisableFirstRunWizard

This policy setting prevents Internet Explorer from running the First Run wizard the first time a user starts the browser after installing Internet Explorer or Windows.

If you enable this policy setting, you must make one of the following choices:

Skip the First Run wizard, and go directly to the user's home page.

Skip the First Run wizard, and go directly to the "Welcome to Internet Explorer" webpage.

Starting with Windows 8, the "Welcome to Internet Explorer" webpage isn't available. The user's home page will display regardless of which option is chosen.

  • If you disable or don't configure this policy setting, Internet Explorer may run the First Run wizard the first time the browser is started after installation.
Name Value
Name NoFirstRunCustomise
Friendly Name Prevent running First Run wizard
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main
ADMX File Name inetres.admx

DisableFlipAheadFeature

This policy setting determines whether a user can swipe across a screen or click Forward to go to the next pre-loaded page of a website.

Microsoft collects your browsing history to improve how flip ahead with page prediction works. This feature isn't available for Internet Explorer for the desktop.

If you enable this policy setting, flip ahead with page prediction is turned off and the next webpage isn't loaded into the background.

If you disable this policy setting, flip ahead with page prediction is turned on and the next webpage is loaded into the background.

If you don't configure this setting, users can turn this behavior on or off, using the Settings charm.

Name Value
Name Advanced_DisableFlipAhead
Friendly Name Turn off the flip ahead with page prediction feature
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Advanced Page
Registry Key Name Software\Policies\Microsoft\Internet Explorer\FlipAhead
Registry Value Name Enabled
ADMX File Name inetres.admx

DisableGeolocation

This policy setting allows you to disable browser geolocation support. This will prevent websites from requesting location data about the user.

If you enable this policy setting, browser geolocation support is turned off.

If you disable this policy setting, browser geolocation support is turned on.

If you don't configure this policy setting, browser geolocation support can be turned on or off in Internet Options on the Privacy tab.

Name Value
Name GeolocationDisable
Friendly Name Turn off browser geolocation
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Geolocation
Registry Value Name PolicyDisableGeolocation
ADMX File Name inetres.admx

DisableHomePageChange

Scope Editions Applicable OS
❌ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 1703 [10.0.15063] and later

The Home page specified on the General tab of the Internet Options dialog box is the default Web page that Internet Explorer loads whenever it's run.

If you enable this policy setting, a user can't set a custom default home page. You must specify which default home page should load on the user machine. For machines with at least Internet Explorer 7, the home page can be set within this policy to override other home page policies.

If you disable or don't configure this policy setting, the Home page box is enabled and users can choose their own home page.

Name Value
Name RestrictHomePage
Friendly Name Disable changing home page settings
Location User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Control Panel
Registry Value Name HomePage
ADMX File Name inetres.admx

DisableHTMLApplication

Scope Editions Applicable OS
✅ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ [10.0.20348.1060] and later
✅ Windows 10, version 1809 [10.0.17763.3460] and later
✅ Windows 10, version 2004 [10.0.19041.2060] and later
✅ Windows 11, version 21H2 [10.0.22000.1030] and later
✅ Windows 11, version 22H2 [10.0.22621] and later

This policy setting specifies if running the HTML Application (HTA file) is blocked or allowed.

If you enable this policy setting, running the HTML Application (HTA file) will be blocked.

If you disable or don't configure this policy setting, running the HTML Application (HTA file) is allowed.

Name Value
Name DisableHTMLApplication
Friendly Name Disable HTML Application
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Hta
Registry Value Name DisableHTMLApplication
ADMX File Name inetres.admx

DisableIgnoringCertificateErrors

This policy setting prevents the user from ignoring Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificate errors that interrupt browsing (such as "expired", "revoked", or "name mismatch" errors) in Internet Explorer.

If you enable this policy setting, the user can't continue browsing.

If you disable or don't configure this policy setting, the user can choose to ignore certificate errors and continue browsing.

Name Value
Name NoCertError
Friendly Name Prevent ignoring certificate errors
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
Registry Value Name PreventIgnoreCertErrors
ADMX File Name inetres.admx

DisableInPrivateBrowsing

This policy setting allows you to turn off the InPrivate Browsing feature.

InPrivate Browsing prevents Internet Explorer from storing data about a user's browsing session. This includes cookies, temporary Internet files, history, and other data.

If you enable this policy setting, InPrivate Browsing is turned off.

If you disable this policy setting, InPrivate Browsing is available for use.

If you don't configure this policy setting, InPrivate Browsing can be turned on or off through the registry.

Name Value
Name DisableInPrivateBrowsing
Friendly Name Turn off InPrivate Browsing
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Privacy
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Privacy
Registry Value Name EnableInPrivateBrowsing
ADMX File Name inetres.admx

DisableInternetExplorerApp

This policy lets you restrict launching of Internet Explorer as a standalone browser.

If you enable this policy, it:

Prevents Internet Explorer 11 from launching as a standalone browser.

Restricts Internet Explorer's usage to Microsoft Edge's native 'Internet Explorer mode'.

Redirects all attempts at launching Internet Explorer 11 to Microsoft Edge Stable Channel browser.

Overrides any other policies that redirect to Internet Explorer 11.

If you disable, or don't configure this policy, all sites are opened using the current active browser settings.

Microsoft Edge Stable Channel must be installed for this policy to take effect.

Name Value
Name DisableInternetExplorerApp
Friendly Name Disable Internet Explorer 11 as a standalone browser
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main
ADMX File Name inetres.admx

DisableProcessesInEnhancedProtectedMode

Name Value
Name Advanced_EnableEnhancedProtectedMode64Bit
Friendly Name Turn on 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Advanced Page
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main
Registry Value Name Isolation64Bit
ADMX File Name inetres.admx

DisableProxyChange

This policy setting specifies if a user can change proxy settings.

If you enable this policy setting, the user won't be able to configure proxy settings.

If you disable or don't configure this policy setting, the user can configure proxy settings.

Name Value
Name RestrictProxy
Friendly Name Prevent changing proxy settings
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Control Panel
Registry Value Name Proxy
ADMX File Name inetres.admx

DisableSearchProviderChange

This policy setting prevents the user from changing the default search provider for the Address bar and the toolbar Search box.

If you enable this policy setting, the user can't change the default search provider.

If you disable or don't configure this policy setting, the user can change the default search provider.

Name Value
Name NoSearchProvider
Friendly Name Prevent changing the default search provider
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions
Registry Value Name NoChangeDefaultSearchProvider
ADMX File Name inetres.admx

DisableSecondaryHomePageChange

Secondary home pages are the default Web pages that Internet Explorer loads in separate tabs from the home page whenever the browser is run. This policy setting allows you to set default secondary home pages.

If you enable this policy setting, you can specify which default home pages should load as secondary home pages. The user can't set custom default secondary home pages.

If you disable or don't configure this policy setting, the user can add secondary home pages.

If the "Disable Changing Home Page Settings" policy is enabled, the user can't add secondary home pages.

Name Value
Name SecondaryHomePages
Friendly Name Disable changing secondary home page settings
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main\SecondaryStartPages
ADMX File Name inetres.admx

DisableSecuritySettingsCheck

This policy setting turns off the Security Settings Check feature, which checks Internet Explorer security settings to determine when the settings put Internet Explorer at risk.

If you enable this policy setting, the feature is turned off.

If you disable or don't configure this policy setting, the feature is turned on.

Name Value
Name Disable_Security_Settings_Check
Friendly Name Turn off the Security Settings Check feature
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Security
Registry Value Name DisableSecuritySettingsCheck
ADMX File Name inetres.admx

DisableUpdateCheck

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 1703 [10.0.15063] and later

Prevents Internet Explorer from checking whether a new version of the browser is available.

If you enable this policy, it prevents Internet Explorer from checking to see whether it's the latest available browser version and notifying users if a new version is available.

If you disable this policy or don't configure it, Internet Explorer checks every 30 days by default, and then notifies users if a new version is available.

This policy is intended to help the administrator maintain version control for Internet Explorer by preventing users from being notified about new versions of the browser.

Name Value
Name NoUpdateCheck
Friendly Name Disable Periodic Check for Internet Explorer software updates
Location Computer Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions
Registry Value Name NoUpdateCheck
ADMX File Name inetres.admx

DisableWebAddressAutoComplete

This AutoComplete feature suggests possible matches when users are entering Web addresses in the browser address bar.

If you enable this policy setting, user won't be suggested matches when entering Web addresses. The user can't change the auto-complete for web-address setting.

If you disable this policy setting, user will be suggested matches when entering Web addresses. The user can't change the auto-complete for web-address setting.

If you don't configure this policy setting, a user will have the freedom to choose to turn the auto-complete setting for web-addresses on or off.

Name Value
Name RestrictWebAddressSuggest
Friendly Name Turn off the auto-complete feature for web addresses
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete
Registry Value Name AutoSuggest
ADMX File Name inetres.admx

DoNotAllowActiveXControlsInProtectedMode

This policy setting prevents ActiveX controls from running in Protected Mode when Enhanced Protected Mode is enabled. When a user has an ActiveX control installed that isn't compatible with Enhanced Protected Mode and a website attempts to load the control, Internet Explorer notifies the user and gives the option to run the website in regular Protected Mode. This policy setting disables this notification and forces all websites to run in Enhanced Protected Mode.

When Enhanced Protected Mode is enabled, and a user encounters a website that attempts to load an ActiveX control that isn't compatible with Enhanced Protected Mode, Internet Explorer notifies the user and gives the option to disable Enhanced Protected Mode for that particular website.

If you enable this policy setting, Internet Explorer won't give the user the option to disable Enhanced Protected Mode. All Protected Mode websites will run in Enhanced Protected Mode.

If you disable or don't configure this policy setting, Internet Explorer notifies users and provides an option to run websites with incompatible ActiveX controls in regular Protected Mode. This is the default behavior.

Name Value
Name Advanced_DisableEPMCompat
Friendly Name Do not allow ActiveX controls to run in Protected Mode when Enhanced Protected Mode is enabled
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Advanced Page
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main
Registry Value Name DisableEPMCompat
ADMX File Name inetres.admx

DoNotAllowUsersToAddSites

Prevents users from adding or removing sites from security zones. A security zone is a group of Web sites with the same security level.

If you enable this policy, the site management settings for security zones are disabled. (To see the site management settings for security zones, in the Internet Options dialog box, click the Security tab, and then click the Sites button).

If you disable this policy or don't configure it, users can add Web sites to or remove sites from the Trusted Sites and Restricted Sites zones, and alter settings for the Local Intranet zone.

This policy prevents users from changing site management settings for security zones established by the administrator.

The "Disable the Security page" policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), which removes the Security tab from the interface, takes precedence over this policy. If it's enabled, this policy is ignored.

Also, see the "Security zones: Use only machine settings" policy.

Name Value
Name Security_zones_map_edit
Friendly Name Security Zones: Do not allow users to add/delete sites
Location Computer Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
Registry Value Name Security_zones_map_edit
ADMX File Name inetres.admx

DoNotAllowUsersToChangePolicies

Prevents users from changing security zone settings. A security zone is a group of Web sites with the same security level.

If you enable this policy, the Custom Level button and security-level slider on the Security tab in the Internet Options dialog box are disabled.

If you disable this policy or don't configure it, users can change the settings for security zones.

This policy prevents users from changing security zone settings established by the administrator.

The "Disable the Security page" policy (located in \User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel), which removes the Security tab from Internet Explorer in Control Panel, takes precedence over this policy. If it's enabled, this policy is ignored.

Name Value
Name Security_options_edit
Friendly Name Security Zones: Do not allow users to change policies
Location Computer Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
Registry Value Name Security_options_edit
ADMX File Name inetres.admx

DoNotBlockOutdatedActiveXControls

This policy setting determines whether Internet Explorer blocks specific outdated ActiveX controls. Outdated ActiveX controls are never blocked in the Intranet Zone.

If you enable this policy setting, Internet Explorer stops blocking outdated ActiveX controls.

If you disable or don't configure this policy setting, Internet Explorer continues to block specific outdated ActiveX controls.

For more information, see "Outdated ActiveX Controls" in the Internet Explorer TechNet library.

Name Value
Name VerMgmtDisable
Friendly Name Turn off blocking of outdated ActiveX controls for Internet Explorer
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Security Features > Add-on Management
Registry Key Name Software\Microsoft\Windows\CurrentVersion\Policies\Ext
Registry Value Name VersionCheckEnabled
ADMX File Name inetres.admx

DoNotBlockOutdatedActiveXControlsOnSpecificDomains

This policy setting allows you to manage a list of domains on which Internet Explorer will stop blocking outdated ActiveX controls. Outdated ActiveX controls are never blocked in the Intranet Zone.

  • If you enable this policy setting, you can enter a custom list of domains for which outdated ActiveX controls won't be blocked in Internet Explorer. Each domain entry must be formatted like one of the following:

"domain.name. TLD". For example, if you want to include .contoso.com/ , use "contoso.com"

"hostname". For example, if you want to include https://example, use "example".

"file:///path/filename.htm". For example, use "file:///C:/Users/contoso/Desktop/index.htm".

  • If you disable or don't configure this policy setting, the list is deleted and Internet Explorer continues to block specific outdated ActiveX controls on all domains in the Internet Zone.
Name Value
Name VerMgmtDomainAllowlist
Friendly Name Turn off blocking of outdated ActiveX controls for Internet Explorer on specific domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Security Features > Add-on Management
Registry Key Name Software\Microsoft\Windows\CurrentVersion\Policies\Ext
Registry Value Name ListBox_DomainAllowlist
ADMX File Name inetres.admx

EnableExtendedIEModeHotkeys

Scope Editions Applicable OS
✅ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ [10.0.20348.143] and later
✅ Windows 10, version 1903 [10.0.18362.1474] and later
✅ Windows 10, version 2004 with [10.0.19041.906] and later
✅ Windows 11, version 21H2 [10.0.22000] and later

This policy setting lets admins enable extended Microsoft Edge Internet Explorer mode hotkeys, such as "Ctrl+S" to have "Save as" functionality.

If you enable this policy, extended hotkey functionality is enabled in Internet Explorer mode and work the same as Internet Explorer.

If you disable, or don't configure this policy, extended hotkeys won't work in Internet Explorer mode.

Name Value
Name EnableExtendedIEModeHotkeys
Friendly Name Enable extended hot keys in Internet Explorer mode
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main\EnterpriseMode
Registry Value Name EnableExtendedIEModeHotkeys
ADMX File Name inetres.admx

EnableGlobalWindowListInIEMode

Scope Editions Applicable OS
✅ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ [10.0.20348.558] and later
✅ Windows 10, version 2004 [10.0.19041.1566] and later
✅ Windows 11, version 21H2 with [10.0.22000.527] and later
✅ Windows 11, version 22H2 [10.0.22621] and later

This setting allows Internet Explorer mode to use the global window list that enables sharing state with other applications.

The setting will take effect only when Internet Explorer 11 is disabled as a standalone browser.

If you enable this policy, Internet Explorer mode will use the global window list.

If you disable or don't configure this policy, Internet Explorer mode will continue to maintain a separate window list.

To learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2102921 To learn more about disabling Internet Explorer 11 as a standalone browser, see https://go.microsoft.com/fwlink/?linkid=2168340

Name Value
Name EnableGlobalWindowListInIEMode
Friendly Name Enable global window list in Internet Explorer mode
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main\EnterpriseMode
Registry Value Name EnableGlobalWindowListInIEMode
ADMX File Name inetres.admx

IncludeAllLocalSites

This policy setting controls whether local sites which aren't explicitly mapped into any Security Zone are forced into the local Intranet security zone.

If you enable this policy setting, local sites which aren't explicitly mapped into a zone are considered to be in the Intranet Zone.

If you disable this policy setting, local sites which aren't explicitly mapped into a zone won't be considered to be in the Intranet Zone (so would typically be in the Internet Zone).

If you don't configure this policy setting, users choose whether to force local sites into the Intranet Zone.

Name Value
Name IZ_IncludeUnspecifiedLocalSites
Friendly Name Intranet Sites: Include all local (intranet) sites not listed in other zones
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Registry Value Name IntranetName
ADMX File Name inetres.admx

IncludeAllNetworkPaths

This policy setting controls whether URLs representing UNCs are mapped into the local Intranet security zone.

If you enable this policy setting, all network paths are mapped into the Intranet Zone.

If you disable this policy setting, network paths aren't necessarily mapped into the Intranet Zone (other rules might map one there).

If you don't configure this policy setting, users choose whether network paths are mapped into the Intranet Zone.

Name Value
Name IZ_UNCAsIntranet
Friendly Name Intranet Sites: Include all network paths (UNCs)
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Registry Value Name UNCAsIntranet
ADMX File Name inetres.admx

InternetZoneAllowAccessToDataSources

This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).

If you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.

If you disable this policy setting, users can't load a page in the zone that uses MSXML or ADO to access data from another site in the zone.

If you don't configure this policy setting, users can't load a page in the zone that uses MSXML or ADO to access data from another site in the zone.

Name Value
Name IZ_PolicyAccessDataSourcesAcrossDomains_1
Friendly Name Access data sources across domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneAllowAutomaticPromptingForActiveXControls

This policy setting manages whether users will be automatically prompted for ActiveX control installations.

If you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they don't have installed.

If you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.

If you don't configure this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.

Name Value
Name IZ_PolicyNotificationBarActiveXURLaction_1
Friendly Name Automatic prompting for ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneAllowAutomaticPromptingForFileDownloads

This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.

If you enable this setting, users will receive a file download dialog for automatic download attempts.

If you disable or don't configure this setting, file downloads that aren't user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.

Name Value
Name IZ_PolicyNotificationBarDownloadURLaction_1
Friendly Name Automatic prompting for file downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneAllowCopyPasteViaScript

This policy setting allows you to manage whether scripts can perform a clipboard operation (for example, cut, copy, and paste) in a specified region.

  • If you enable this policy setting, a script can perform a clipboard operation.

If you select Prompt in the drop-down box, users are queried as to whether to perform clipboard operations.

If you disable this policy setting, a script can't perform a clipboard operation.

If you don't configure this policy setting, a script can perform a clipboard operation.

Name Value
Name IZ_PolicyAllowPasteViaScript_1
Friendly Name Allow cut, copy or paste operations from the clipboard via script
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneAllowDragAndDropCopyAndPasteFiles

This policy setting allows you to manage whether users can drag files or copy and paste files from a source within the zone.

If you enable this policy setting, users can drag files or copy and paste files from this zone automatically. If you select Prompt in the drop-down box, users are queried to choose whether to drag or copy files from this zone.

If you disable this policy setting, users are prevented from dragging files or copying and pasting files from this zone.

If you don't configure this policy setting, users can drag files or copy and paste files from this zone automatically.

Name Value
Name IZ_PolicyDropOrPasteFiles_1
Friendly Name Allow drag and drop or copy and paste files
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneAllowFontDownloads

This policy setting allows you to manage whether pages of the zone may download HTML fonts.

If you enable this policy setting, HTML fonts can be downloaded automatically.

If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.

If you disable this policy setting, HTML fonts are prevented from downloading.

If you don't configure this policy setting, HTML fonts can be downloaded automatically.

Name Value
Name IZ_PolicyFontDownload_1
Friendly Name Allow font downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneAllowLessPrivilegedSites

This policy setting allows you to manage whether Web sites from less privileged zones, such as Restricted Sites, can navigate into this zone.

If you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that's provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.

If you disable this policy setting, the possibly harmful navigations is prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.

If you don't configure this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone.

Name Value
Name IZ_PolicyZoneElevationURLaction_1
Friendly Name Web sites in less privileged Web content zones can navigate into this zone
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneAllowLoadingOfXAMLFiles

This policy setting allows you to manage the loading of Extensible Application Markup Language (XAML) files. XAML is an XML-based declarative markup language commonly used for creating rich user interfaces and graphics that take advantage of the Windows Presentation Foundation.

If you enable this policy setting and set the drop-down box to Enable, XAML files are automatically loaded inside Internet Explorer. The user can't change this behavior. If you set the drop-down box to Prompt, the user is prompted for loading XAML files.

If you disable this policy setting, XAML files aren't loaded inside Internet Explorer. The user can't change this behavior.

If you don't configure this policy setting, the user can decide whether to load XAML files inside Internet Explorer.

Name Value
Name IZ_Policy_XAML_1
Friendly Name Allow loading of XAML files
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneAllowNETFrameworkReliantComponents

This policy setting allows you to manage whether . NET Framework components that aren't signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.

If you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.

If you disable this policy setting, Internet Explorer won't execute unsigned managed components.

If you don't configure this policy setting, Internet Explorer will execute unsigned managed components.

Name Value
Name IZ_PolicyUnsignedFrameworkComponentsURLaction_1
Friendly Name Run .NET Framework-reliant components not signed with Authenticode
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneAllowOnlyApprovedDomainsToUseActiveXControls

This policy setting controls whether or not the user is prompted to allow ActiveX controls to run on websites other than the website that installed the ActiveX control.

If you enable this policy setting, the user is prompted before ActiveX controls can run from websites in this zone. The user can choose to allow the control to run from the current site or from all sites.

If you disable this policy setting, the user doesn't see the per-site ActiveX prompt, and ActiveX controls can run from all sites in this zone.

Name Value
Name IZ_PolicyOnlyAllowApprovedDomainsToUseActiveXWithoutPrompt_Both_Internet
Friendly Name Allow only approved domains to use ActiveX controls without prompt
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneAllowOnlyApprovedDomainsToUseTDCActiveXControl

This policy setting controls whether or not the user is allowed to run the TDC ActiveX control on websites.

If you enable this policy setting, the TDC ActiveX control won't run from websites in this zone.

If you disable this policy setting, the TDC Active X control will run from all sites in this zone.

Name Value
Name IZ_PolicyAllowTDCControl_Both_Internet
Friendly Name Allow only approved domains to use the TDC ActiveX control
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneAllowScriptingOfInternetExplorerWebBrowserControls

This policy setting determines whether a page can control embedded WebBrowser controls via script.

If you enable this policy setting, script access to the WebBrowser control is allowed.

If you disable this policy setting, script access to the WebBrowser control isn't allowed.

If you don't configure this policy setting, the user can enable or disable script access to the WebBrowser control. By default, script access to the WebBrowser control is allowed only in the Local Machine and Intranet zones.

Name Value
Name IZ_Policy_WebBrowserControl_1
Friendly Name Allow scripting of Internet Explorer WebBrowser controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneAllowScriptInitiatedWindows

This policy setting allows you to manage restrictions on script-initiated pop-up windows and windows that include the title and status bars.

If you enable this policy setting, Windows Restrictions security won't apply in this zone. The security zone runs without the added layer of security provided by this feature.

If you disable this policy setting, the possible harmful actions contained in script-initiated pop-up windows and windows that include the title and status bars can't be run. This Internet Explorer security feature will be on in this zone as dictated by the Scripted Windows Security Restrictions feature control setting for the process.

If you don't configure this policy setting, the possible harmful actions contained in script-initiated pop-up windows and windows that include the title and status bars can't be run. This Internet Explorer security feature will be on in this zone as dictated by the Scripted Windows Security Restrictions feature control setting for the process.

Name Value
Name IZ_PolicyWindowsRestrictionsURLaction_1
Friendly Name Allow script-initiated windows without size or position constraints
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneAllowScriptlets

This policy setting allows you to manage whether the user can run scriptlets.

If you enable this policy setting, the user can run scriptlets.

If you disable this policy setting, the user can't run scriptlets.

If you don't configure this policy setting, the user can enable or disable scriptlets.

Name Value
Name IZ_Policy_AllowScriptlets_1
Friendly Name Allow scriptlets
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneAllowSmartScreenIE

This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.

If you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.

If you disable this policy setting, SmartScreen Filter doesn't scan pages in this zone for malicious content.

If you don't configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.

In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.

Name Value
Name IZ_Policy_Phishing_1
Friendly Name Turn on SmartScreen Filter scan
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneAllowUpdatesToStatusBarViaScript

This policy setting allows you to manage whether script is allowed to update the status bar within the zone.

If you enable this policy setting, script is allowed to update the status bar.

If you disable or don't configure this policy setting, script isn't allowed to update the status bar.

Name Value
Name IZ_Policy_ScriptStatusBar_1
Friendly Name Allow updates to status bar via script
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneAllowUserDataPersistence

This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.

If you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.

If you disable this policy setting, users can't preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.

If you don't configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.

Name Value
Name IZ_PolicyUserdataPersistence_1
Friendly Name Userdata persistence
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneAllowVBScriptToRunInInternetExplorer

Scope Editions Applicable OS
✅ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 1803 [10.0.17134] and later

This policy setting allows you to manage whether VBScript can be run on pages from the specified zone in Internet Explorer.

If you selected Enable in the drop-down box, VBScript can run without user intervention.

If you selected Prompt in the drop-down box, users are asked to choose whether to allow VBScript to run.

If you selected Disable in the drop-down box, VBScript is prevented from running.

If you don't configure or disable this policy setting, VBScript is prevented from running.

Name Value
Name IZ_PolicyAllowVBScript_1
Friendly Name Allow VBScript to run in Internet Explorer
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneDoNotRunAntimalwareAgainstActiveXControls

This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.

If you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.

If you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.

If you don't configure this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.

Name Value
Name IZ_PolicyAntiMalwareCheckingOfActiveXControls_1
Friendly Name Don't run antimalware programs against ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneDownloadSignedActiveXControls

This policy setting allows you to manage whether users may download signed ActiveX controls from a page in the zone.

If you enable this policy, users can download signed controls without user intervention. If you select Prompt in the drop-down box, users are queried whether to download controls signed by publishers who aren't trusted. Code signed by trusted publishers is silently downloaded.

If you disable the policy setting, signed controls can't be downloaded.

If you don't configure this policy setting, users are queried whether to download controls signed by publishers who aren't trusted. Code signed by trusted publishers is silently downloaded.

Name Value
Name IZ_PolicyDownloadSignedActiveX_1
Friendly Name Download signed ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneDownloadUnsignedActiveXControls

This policy setting allows you to manage whether users may download unsigned ActiveX controls from the zone. Such code is potentially harmful, especially when coming from an untrusted zone.

If you enable this policy setting, users can run unsigned controls without user intervention. If you select Prompt in the drop-down box, users are queried to choose whether to allow the unsigned control to run.

If you disable this policy setting, users can't run unsigned controls.

If you don't configure this policy setting, users can't run unsigned controls.

Name Value
Name IZ_PolicyDownloadUnsignedActiveX_1
Friendly Name Download unsigned ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneEnableCrossSiteScriptingFilter

This policy controls whether or not the Cross-Site Scripting (XSS) Filter will detect and prevent cross-site script injections into websites in this zone.

If you enable this policy setting, the XSS Filter is turned on for sites in this zone, and the XSS Filter attempts to block cross-site script injections.

If you disable this policy setting, the XSS Filter is turned off for sites in this zone, and Internet Explorer permits cross-site script injections.

Name Value
Name IZ_PolicyTurnOnXSSFilter_Both_Internet
Friendly Name Turn on Cross-Site Scripting Filter
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneEnableDraggingOfContentFromDifferentDomainsAcrossWindows

This policy setting allows you to set options for dragging content from one domain to a different domain when the source and destination are in different windows.

If you enable this policy setting and click Enable, users can drag content from one domain to a different domain when the source and destination are in different windows. Users can't change this setting.

If you enable this policy setting and click Disable, users can't drag content from one domain to a different domain when both the source and destination are in different windows. Users can't change this setting.

In Internet Explorer 10, if you disable this policy setting or don't configure it, users can't drag content from one domain to a different domain when the source and destination are in different windows. Users can change this setting in the Internet Options dialog.

In Internet Explorer 9 and earlier versions, if you disable this policy or don't configure it, users can drag content from one domain to a different domain when the source and destination are in different windows. Users can't change this setting.

Name Value
Name IZ_PolicyDragDropAcrossDomainsAcrossWindows_Both_Internet
Friendly Name Enable dragging of content from different domains across windows
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneEnableDraggingOfContentFromDifferentDomainsWithinWindows

This policy setting allows you to set options for dragging content from one domain to a different domain when the source and destination are in the same window.

If you enable this policy setting and click Enable, users can drag content from one domain to a different domain when the source and destination are in the same window. Users can't change this setting.

If you enable this policy setting and click Disable, users can't drag content from one domain to a different domain when the source and destination are in the same window. Users can't change this setting in the Internet Options dialog.

In Internet Explorer 10, if you disable this policy setting or don't configure it, users can't drag content from one domain to a different domain when the source and destination are in the same window. Users can change this setting in the Internet Options dialog.

In Internet Explorer 9 and earlier versions, if you disable this policy setting or don't configure it, users can drag content from one domain to a different domain when the source and destination are in the same window. Users can't change this setting in the Internet Options dialog.

Name Value
Name IZ_PolicyDragDropAcrossDomainsWithinWindow_Both_Internet
Friendly Name Enable dragging of content from different domains within a window
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneEnableMIMESniffing

This policy setting allows you to manage MIME sniffing for file promotion from one type to another based on a MIME sniff. A MIME sniff is the recognition by Internet Explorer of the file type based on a bit signature.

If you enable this policy setting, the MIME Sniffing Safety Feature won't apply in this zone. The security zone will run without the added layer of security provided by this feature.

If you disable this policy setting, the actions that may be harmful can't run; this Internet Explorer security feature will be turned on in this zone, as dictated by the feature control setting for the process.

If you don't configure this policy setting, the MIME Sniffing Safety Feature won't apply in this zone.

Name Value
Name IZ_PolicyMimeSniffingURLaction_1
Friendly Name Enable MIME Sniffing
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneEnableProtectedMode

This policy setting allows you to turn on Protected Mode. Protected Mode helps protect Internet Explorer from exploited vulnerabilities by reducing the locations that Internet Explorer can write to in the registry and the file system.

If you enable this policy setting, Protected Mode is turned on. The user can't turn off Protected Mode.

If you disable this policy setting, Protected Mode is turned off. The user can't turn on Protected Mode.

If you don't configure this policy setting, the user can turn on or turn off Protected Mode.

Name Value
Name IZ_Policy_TurnOnProtectedMode_1
Friendly Name Turn on Protected Mode
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneIncludeLocalPathWhenUploadingFilesToServer

This policy setting controls whether or not local path information is sent when the user is uploading a file via an HTML form. If the local path information is sent, some information may be unintentionally revealed to the server. For instance, files sent from the user's desktop may contain the user name as a part of the path.

If you enable this policy setting, path information is sent when the user is uploading a file via an HTML form.

If you disable this policy setting, path information is removed when the user is uploading a file via an HTML form.

If you don't configure this policy setting, the user can choose whether path information is sent when he or she is uploading a file via an HTML form. By default, path information is sent.

Name Value
Name IZ_Policy_LocalPathForUpload_1
Friendly Name Include local path when user is uploading files to a server
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneInitializeAndScriptActiveXControls

This policy setting allows you to manage ActiveX controls not marked as safe.

If you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting isn't recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.

If you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.

If you disable this policy setting, ActiveX controls that can't be made safe aren't loaded with parameters or scripted.

If you don't configure this policy setting, ActiveX controls that can't be made safe aren't loaded with parameters or scripted.

Name Value
Name IZ_PolicyScriptActiveXNotMarkedSafe_1
Friendly Name Initialize and script ActiveX controls not marked as safe
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneJavaPermissions

This policy setting allows you to manage permissions for Java applets.

  • If you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.

Low Safety enables applets to perform all operations.

Medium Safety enables applets to run in their sandbox (an area in memory outside of which the program can't make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.

High Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.

If you disable this policy setting, Java applets can't run.

If you don't configure this policy setting, the permission is set to High Safety.

Name Value
Name IZ_PolicyJavaPermissions_1
Friendly Name Java permissions
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneLaunchingApplicationsAndFilesInIFRAME

This policy setting allows you to manage whether applications may be run and files may be downloaded from an IFRAME reference in the HTML of the pages in this zone.

If you enable this policy setting, users can run applications and download files from IFRAMEs on the pages in this zone without user intervention. If you select Prompt in the drop-down box, users are queried to choose whether to run applications and download files from IFRAMEs on the pages in this zone.

If you disable this policy setting, users are prevented from running applications and downloading files from IFRAMEs on the pages in this zone.

If you don't configure this policy setting, users are queried to choose whether to run applications and download files from IFRAMEs on the pages in this zone.

Name Value
Name IZ_PolicyLaunchAppsAndFilesInIFRAME_1
Friendly Name Launching applications and files in an IFRAME
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneLogonOptions

This policy setting allows you to manage settings for logon options.

  • If you enable this policy setting, you can choose from the following logon options.

Anonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.

Prompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.

Automatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.

Automatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response isn't supported by the server, the user is queried to provide the user name and password.

If you disable this policy setting, logon is set to Automatic logon only in Intranet zone.

If you don't configure this policy setting, logon is set to Automatic logon only in Intranet zone.

Name Value
Name IZ_PolicyLogon_1
Friendly Name Logon options
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneNavigateWindowsAndFrames

This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.

If you enable this policy setting, users can open windows and frames from other domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.

If you disable this policy setting, users can't open windows and frames to access applications from different domains.

If you don't configure this policy setting, users can open windows and frames from other domains and access applications from other domains.

Name Value
Name IZ_PolicyNavigateSubframesAcrossDomains_1
Friendly Name Navigate windows and frames across different domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneRunNETFrameworkReliantComponentsSignedWithAuthenticode

This policy setting allows you to manage whether . NET Framework components that are signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.

If you enable this policy setting, Internet Explorer will execute signed managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute signed managed components.

If you disable this policy setting, Internet Explorer won't execute signed managed components.

If you don't configure this policy setting, Internet Explorer will execute signed managed components.

Name Value
Name IZ_PolicySignedFrameworkComponentsURLaction_1
Friendly Name Run .NET Framework-reliant components signed with Authenticode
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneShowSecurityWarningForPotentiallyUnsafeFiles

This policy setting controls whether or not the "Open File - Security Warning" message appears when the user tries to open executable files or other potentially unsafe files (from an intranet file share by using File Explorer, for example).

If you enable this policy setting and set the drop-down box to Enable, these files open without a security warning. If you set the drop-down box to Prompt, a security warning appears before the files open.

If you disable this policy setting, these files don't open.

If you don't configure this policy setting, the user can configure how the computer handles these files. By default, these files are blocked in the Restricted zone, enabled in the Intranet and Local Computer zones, and set to prompt in the Internet and Trusted zones.

Name Value
Name IZ_Policy_UnsafeFiles_1
Friendly Name Show security warning for potentially unsafe files
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

InternetZoneUsePopupBlocker

This policy setting allows you to manage whether unwanted pop-up windows appear. Pop-up windows that are opened when the end user clicks a link aren't blocked.

If you enable this policy setting, most unwanted pop-up windows are prevented from appearing.

If you disable this policy setting, pop-up windows aren't prevented from appearing.

If you don't configure this policy setting, most unwanted pop-up windows are prevented from appearing.

Name Value
Name IZ_PolicyBlockPopupWindows_1
Friendly Name Use Pop-up Blocker
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
ADMX File Name inetres.admx

IntranetZoneAllowAccessToDataSources

If you don't configure this policy setting, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.

Name Value
Name IZ_PolicyAccessDataSourcesAcrossDomains_3
Friendly Name Access data sources across domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
ADMX File Name inetres.admx

IntranetZoneAllowAutomaticPromptingForActiveXControls

If you don't configure this policy setting, users will receive a prompt when a site instantiates an ActiveX control they don't have installed.

Name Value
Name IZ_PolicyNotificationBarActiveXURLaction_3
Friendly Name Automatic prompting for ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
ADMX File Name inetres.admx

IntranetZoneAllowAutomaticPromptingForFileDownloads

If you disable or don't configure this setting, users will receive a file download dialog for automatic download attempts.

Name Value
Name IZ_PolicyNotificationBarDownloadURLaction_3
Friendly Name Automatic prompting for file downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
ADMX File Name inetres.admx

IntranetZoneAllowFontDownloads

Name Value
Name IZ_PolicyFontDownload_3
Friendly Name Allow font downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
ADMX File Name inetres.admx

IntranetZoneAllowLessPrivilegedSites

Name Value
Name IZ_PolicyZoneElevationURLaction_3
Friendly Name Web sites in less privileged Web content zones can navigate into this zone
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
ADMX File Name inetres.admx

IntranetZoneAllowNETFrameworkReliantComponents

Name Value
Name IZ_PolicyUnsignedFrameworkComponentsURLaction_3
Friendly Name Run .NET Framework-reliant components not signed with Authenticode
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
ADMX File Name inetres.admx

IntranetZoneAllowScriptlets

Name Value
Name IZ_Policy_AllowScriptlets_3
Friendly Name Allow scriptlets
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
ADMX File Name inetres.admx

IntranetZoneAllowSmartScreenIE

Name Value
Name IZ_Policy_Phishing_3
Friendly Name Turn on SmartScreen Filter scan
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
ADMX File Name inetres.admx

IntranetZoneAllowUserDataPersistence

Name Value
Name IZ_PolicyUserdataPersistence_3
Friendly Name Userdata persistence
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
ADMX File Name inetres.admx

IntranetZoneDoNotRunAntimalwareAgainstActiveXControls

If you don't configure this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.

Name Value
Name IZ_PolicyAntiMalwareCheckingOfActiveXControls_3
Friendly Name Don't run antimalware programs against ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
ADMX File Name inetres.admx

IntranetZoneInitializeAndScriptActiveXControls

Name Value
Name IZ_PolicyScriptActiveXNotMarkedSafe_3
Friendly Name Initialize and script ActiveX controls not marked as safe
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
ADMX File Name inetres.admx

IntranetZoneJavaPermissions

If you don't configure this policy setting, the permission is set to Medium Safety.

Name Value
Name IZ_PolicyJavaPermissions_3
Friendly Name Java permissions
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
ADMX File Name inetres.admx

IntranetZoneLogonOptions

Scope Editions Applicable OS
✅ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ [10.0.20348.2227] and later
✅ [10.0.25398.643] and later
✅ [10.0.25965] and later
✅ Windows 10, version 2004 [10.0.19041.3758] and later
✅ Windows 11, version 22H2 with [10.0.22621.2792] and later
Name Value
Name IZ_PolicyLogon_3
Friendly Name Logon options
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
ADMX File Name inetres.admx

IntranetZoneNavigateWindowsAndFrames

Name Value
Name IZ_PolicyNavigateSubframesAcrossDomains_3
Friendly Name Navigate windows and frames across different domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
ADMX File Name inetres.admx

JScriptReplacement

Scope Editions Applicable OS
✅ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 11, version 21H2 [10.0.22000] and later

This policy setting specifies whether JScript or JScript9Legacy is loaded for MSHTML/WebOC/MSXML/Cscript based invocations.

If you enable this policy setting, JScript9Legacy will be loaded in situations where JScript is instantiated.

If you disable this policy, then JScript will be utilized.

If this policy is left unconfigured, then MSHTML will use JScript9Legacy and MSXML/Cscript will use JScript.

Name Value
Name JScriptReplacement
Friendly Name Replace JScript by loading JScript9Legacy in place of JScript via MSHTML/WebOC.
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main
Registry Value Name JScriptReplacement
ADMX File Name inetres.admx

KeepIntranetSitesInInternetExplorer

Prevents intranet sites from being opened in any browser except Internet Explorer. But note that If the 'Send all sites not included in the Enterprise Mode Site List to Microsoft Edge' ('RestrictIE') policy isn't enabled, this policy has no effect.

If you enable this policy, all intranet sites are opened in Internet Explorer 11. The only exceptions are sites listed in your Enterprise Mode Site List.

If you disable or don't configure this policy, all intranet sites are automatically opened in Microsoft Edge.

We strongly recommend keeping this policy in sync with the 'Send all intranet sites to Internet Explorer' ('SendIntranetToInternetExplorer') policy. Additionally, it's best to enable this policy only if your intranet sites have known compatibility problems with Microsoft Edge.

Related policies:

  • Send all intranet sites to Internet Explorer ('SendIntranetToInternetExplorer')
  • Send all sites not included in the Enterprise Mode Site List to Microsoft Edge ('RestrictIE')

For more info about how to use this policy together with other related policies to create the optimal configuration for your organization, see< https://go.microsoft.com/fwlink/?linkid=2094210> .

Name Value
Name KeepIntranetSitesInInternetExplorer
Friendly Name Keep all intranet sites in Internet Explorer
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main\EnterpriseMode
Registry Value Name KeepIntranetSitesInInternetExplorer
ADMX File Name inetres.admx

LocalMachineZoneAllowAccessToDataSources

If you don't configure this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone.

Name Value
Name IZ_PolicyAccessDataSourcesAcrossDomains_9
Friendly Name Access data sources across domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
ADMX File Name inetres.admx

LocalMachineZoneAllowAutomaticPromptingForActiveXControls

Name Value
Name IZ_PolicyNotificationBarActiveXURLaction_9
Friendly Name Automatic prompting for ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
ADMX File Name inetres.admx

LocalMachineZoneAllowAutomaticPromptingForFileDownloads

Name Value
Name IZ_PolicyNotificationBarDownloadURLaction_9
Friendly Name Automatic prompting for file downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
ADMX File Name inetres.admx

LocalMachineZoneAllowFontDownloads

Name Value
Name IZ_PolicyFontDownload_9
Friendly Name Allow font downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
ADMX File Name inetres.admx

LocalMachineZoneAllowLessPrivilegedSites

This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.

If you don't configure this policy setting, the possibly harmful navigations is prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.

Name Value
Name IZ_PolicyZoneElevationURLaction_9
Friendly Name Web sites in less privileged Web content zones can navigate into this zone
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
ADMX File Name inetres.admx

LocalMachineZoneAllowNETFrameworkReliantComponents

If you don't configure this policy setting, Internet Explorer won't execute unsigned managed components.

Name Value
Name IZ_PolicyUnsignedFrameworkComponentsURLaction_9
Friendly Name Run .NET Framework-reliant components not signed with Authenticode
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
ADMX File Name inetres.admx

LocalMachineZoneAllowScriptlets

Name Value
Name IZ_Policy_AllowScriptlets_9
Friendly Name Allow scriptlets
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
ADMX File Name inetres.admx

LocalMachineZoneAllowSmartScreenIE

Name Value
Name IZ_Policy_Phishing_9
Friendly Name Turn on SmartScreen Filter scan
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
ADMX File Name inetres.admx

LocalMachineZoneAllowUserDataPersistence

Name Value
Name IZ_PolicyUserdataPersistence_9
Friendly Name Userdata persistence
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
ADMX File Name inetres.admx

LocalMachineZoneDoNotRunAntimalwareAgainstActiveXControls

Name Value
Name IZ_PolicyAntiMalwareCheckingOfActiveXControls_9
Friendly Name Don't run antimalware programs against ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
ADMX File Name inetres.admx

LocalMachineZoneInitializeAndScriptActiveXControls

If you don't configure this policy setting, users are queried whether to allow the control to be loaded with parameters or scripted.

Name Value
Name IZ_PolicyScriptActiveXNotMarkedSafe_9
Friendly Name Initialize and script ActiveX controls not marked as safe
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
ADMX File Name inetres.admx

LocalMachineZoneJavaPermissions

Name Value
Name IZ_PolicyJavaPermissions_9
Friendly Name Java permissions
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
ADMX File Name inetres.admx

LocalMachineZoneLogonOptions

If you don't configure this policy setting, logon is set to Automatic logon with current username and password.

Name Value
Name IZ_PolicyLogon_9
Friendly Name Logon options
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
ADMX File Name inetres.admx

LocalMachineZoneNavigateWindowsAndFrames

Name Value
Name IZ_PolicyNavigateSubframesAcrossDomains_9
Friendly Name Navigate windows and frames across different domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
ADMX File Name inetres.admx

LockedDownInternetZoneAllowAccessToDataSources

Name Value
Name IZ_PolicyAccessDataSourcesAcrossDomains_2
Friendly Name Access data sources across domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
ADMX File Name inetres.admx

LockedDownInternetZoneAllowAutomaticPromptingForActiveXControls

Name Value
Name IZ_PolicyNotificationBarActiveXURLaction_2
Friendly Name Automatic prompting for ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
ADMX File Name inetres.admx

LockedDownInternetZoneAllowAutomaticPromptingForFileDownloads

Name Value
Name IZ_PolicyNotificationBarDownloadURLaction_2
Friendly Name Automatic prompting for file downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
ADMX File Name inetres.admx

LockedDownInternetZoneAllowFontDownloads

Name Value
Name IZ_PolicyFontDownload_2
Friendly Name Allow font downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
ADMX File Name inetres.admx

LockedDownInternetZoneAllowLessPrivilegedSites

Name Value
Name IZ_PolicyZoneElevationURLaction_2
Friendly Name Web sites in less privileged Web content zones can navigate into this zone
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
ADMX File Name inetres.admx

LockedDownInternetZoneAllowNETFrameworkReliantComponents

Name Value
Name IZ_PolicyUnsignedFrameworkComponentsURLaction_2
Friendly Name Run .NET Framework-reliant components not signed with Authenticode
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
ADMX File Name inetres.admx

LockedDownInternetZoneAllowScriptlets

Name Value
Name IZ_Policy_AllowScriptlets_2
Friendly Name Allow scriptlets
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
ADMX File Name inetres.admx

LockedDownInternetZoneAllowSmartScreenIE

Name Value
Name IZ_Policy_Phishing_2
Friendly Name Turn on SmartScreen Filter scan
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
ADMX File Name inetres.admx

LockedDownInternetZoneAllowUserDataPersistence

Name Value
Name IZ_PolicyUserdataPersistence_2
Friendly Name Userdata persistence
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
ADMX File Name inetres.admx

LockedDownInternetZoneInitializeAndScriptActiveXControls

Name Value
Name IZ_PolicyScriptActiveXNotMarkedSafe_2
Friendly Name Initialize and script ActiveX controls not marked as safe
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
ADMX File Name inetres.admx

LockedDownInternetZoneJavaPermissions

If you don't configure this policy setting, Java applets are disabled.

Name Value
Name IZ_PolicyJavaPermissions_2
Friendly Name Java permissions
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
ADMX File Name inetres.admx

LockedDownInternetZoneNavigateWindowsAndFrames

Name Value
Name IZ_PolicyNavigateSubframesAcrossDomains_2
Friendly Name Navigate windows and frames across different domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Internet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
ADMX File Name inetres.admx

LockedDownIntranetJavaPermissions

Name Value
Name IZ_PolicyJavaPermissions_4
Friendly Name Java permissions
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
ADMX File Name inetres.admx

LockedDownIntranetZoneAllowAccessToDataSources

Name Value
Name IZ_PolicyAccessDataSourcesAcrossDomains_4
Friendly Name Access data sources across domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
ADMX File Name inetres.admx

LockedDownIntranetZoneAllowAutomaticPromptingForActiveXControls

Name Value
Name IZ_PolicyNotificationBarActiveXURLaction_4
Friendly Name Automatic prompting for ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
ADMX File Name inetres.admx

LockedDownIntranetZoneAllowAutomaticPromptingForFileDownloads

Name Value
Name IZ_PolicyNotificationBarDownloadURLaction_4
Friendly Name Automatic prompting for file downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
ADMX File Name inetres.admx

LockedDownIntranetZoneAllowFontDownloads

Name Value
Name IZ_PolicyFontDownload_4
Friendly Name Allow font downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
ADMX File Name inetres.admx

LockedDownIntranetZoneAllowLessPrivilegedSites

Name Value
Name IZ_PolicyZoneElevationURLaction_4
Friendly Name Web sites in less privileged Web content zones can navigate into this zone
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
ADMX File Name inetres.admx

LockedDownIntranetZoneAllowNETFrameworkReliantComponents

Name Value
Name IZ_PolicyUnsignedFrameworkComponentsURLaction_4
Friendly Name Run .NET Framework-reliant components not signed with Authenticode
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
ADMX File Name inetres.admx

LockedDownIntranetZoneAllowScriptlets

Name Value
Name IZ_Policy_AllowScriptlets_4
Friendly Name Allow scriptlets
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
ADMX File Name inetres.admx

LockedDownIntranetZoneAllowSmartScreenIE

Name Value
Name IZ_Policy_Phishing_4
Friendly Name Turn on SmartScreen Filter scan
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
ADMX File Name inetres.admx

LockedDownIntranetZoneAllowUserDataPersistence

Name Value
Name IZ_PolicyUserdataPersistence_4
Friendly Name Userdata persistence
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
ADMX File Name inetres.admx

LockedDownIntranetZoneInitializeAndScriptActiveXControls

Name Value
Name IZ_PolicyScriptActiveXNotMarkedSafe_4
Friendly Name Initialize and script ActiveX controls not marked as safe
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
ADMX File Name inetres.admx

LockedDownIntranetZoneNavigateWindowsAndFrames

Name Value
Name IZ_PolicyNavigateSubframesAcrossDomains_4
Friendly Name Navigate windows and frames across different domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Intranet Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
ADMX File Name inetres.admx

LockedDownLocalMachineZoneAllowAccessToDataSources

Name Value
Name IZ_PolicyAccessDataSourcesAcrossDomains_10
Friendly Name Access data sources across domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
ADMX File Name inetres.admx

LockedDownLocalMachineZoneAllowAutomaticPromptingForActiveXControls

Name Value
Name IZ_PolicyNotificationBarActiveXURLaction_10
Friendly Name Automatic prompting for ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
ADMX File Name inetres.admx

LockedDownLocalMachineZoneAllowAutomaticPromptingForFileDownloads

Name Value
Name IZ_PolicyNotificationBarDownloadURLaction_10
Friendly Name Automatic prompting for file downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
ADMX File Name inetres.admx

LockedDownLocalMachineZoneAllowFontDownloads

Name Value
Name IZ_PolicyFontDownload_10
Friendly Name Allow font downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
ADMX File Name inetres.admx

LockedDownLocalMachineZoneAllowLessPrivilegedSites

Name Value
Name IZ_PolicyZoneElevationURLaction_10
Friendly Name Web sites in less privileged Web content zones can navigate into this zone
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
ADMX File Name inetres.admx

LockedDownLocalMachineZoneAllowNETFrameworkReliantComponents

Name Value
Name IZ_PolicyUnsignedFrameworkComponentsURLaction_10
Friendly Name Run .NET Framework-reliant components not signed with Authenticode
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
ADMX File Name inetres.admx

LockedDownLocalMachineZoneAllowScriptlets

Name Value
Name IZ_Policy_AllowScriptlets_10
Friendly Name Allow scriptlets
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
ADMX File Name inetres.admx

LockedDownLocalMachineZoneAllowSmartScreenIE

Name Value
Name IZ_Policy_Phishing_10
Friendly Name Turn on SmartScreen Filter scan
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
ADMX File Name inetres.admx

LockedDownLocalMachineZoneAllowUserDataPersistence

Name Value
Name IZ_PolicyUserdataPersistence_10
Friendly Name Userdata persistence
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
ADMX File Name inetres.admx

LockedDownLocalMachineZoneInitializeAndScriptActiveXControls

Name Value
Name IZ_PolicyScriptActiveXNotMarkedSafe_10
Friendly Name Initialize and script ActiveX controls not marked as safe
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
ADMX File Name inetres.admx

LockedDownLocalMachineZoneJavaPermissions

Name Value
Name IZ_PolicyJavaPermissions_10
Friendly Name Java permissions
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
ADMX File Name inetres.admx

LockedDownLocalMachineZoneNavigateWindowsAndFrames

Name Value
Name IZ_PolicyNavigateSubframesAcrossDomains_10
Friendly Name Navigate windows and frames across different domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Local Machine Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
ADMX File Name inetres.admx

LockedDownRestrictedSitesZoneAllowAccessToDataSources

Name Value
Name IZ_PolicyAccessDataSourcesAcrossDomains_8
Friendly Name Access data sources across domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
ADMX File Name inetres.admx

LockedDownRestrictedSitesZoneAllowAutomaticPromptingForActiveXControls

Name Value
Name IZ_PolicyNotificationBarActiveXURLaction_8
Friendly Name Automatic prompting for ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
ADMX File Name inetres.admx

LockedDownRestrictedSitesZoneAllowAutomaticPromptingForFileDownloads

Name Value
Name IZ_PolicyNotificationBarDownloadURLaction_8
Friendly Name Automatic prompting for file downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
ADMX File Name inetres.admx

LockedDownRestrictedSitesZoneAllowFontDownloads

If you don't configure this policy setting, users are queried whether to allow HTML fonts to download.

Name Value
Name IZ_PolicyFontDownload_8
Friendly Name Allow font downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
ADMX File Name inetres.admx

LockedDownRestrictedSitesZoneAllowLessPrivilegedSites

Name Value
Name IZ_PolicyZoneElevationURLaction_8
Friendly Name Web sites in less privileged Web content zones can navigate into this zone
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
ADMX File Name inetres.admx

LockedDownRestrictedSitesZoneAllowNETFrameworkReliantComponents

Name Value
Name IZ_PolicyUnsignedFrameworkComponentsURLaction_8
Friendly Name Run .NET Framework-reliant components not signed with Authenticode
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
ADMX File Name inetres.admx

LockedDownRestrictedSitesZoneAllowScriptlets

Name Value
Name IZ_Policy_AllowScriptlets_8
Friendly Name Allow scriptlets
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
ADMX File Name inetres.admx

LockedDownRestrictedSitesZoneAllowSmartScreenIE

Name Value
Name IZ_Policy_Phishing_8
Friendly Name Turn on SmartScreen Filter scan
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
ADMX File Name inetres.admx

LockedDownRestrictedSitesZoneAllowUserDataPersistence

If you don't configure this policy setting, users can't preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.

Name Value
Name IZ_PolicyUserdataPersistence_8
Friendly Name Userdata persistence
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
ADMX File Name inetres.admx

LockedDownRestrictedSitesZoneInitializeAndScriptActiveXControls

Name Value
Name IZ_PolicyScriptActiveXNotMarkedSafe_8
Friendly Name Initialize and script ActiveX controls not marked as safe
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
ADMX File Name inetres.admx

LockedDownRestrictedSitesZoneJavaPermissions

Name Value
Name IZ_PolicyJavaPermissions_8
Friendly Name Java permissions
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
ADMX File Name inetres.admx

LockedDownRestrictedSitesZoneNavigateWindowsAndFrames

If you enable this policy setting, users can open additional windows and frames from other domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow additional windows and frames to access applications from other domains.

If you disable this policy setting, users can't open other windows and frames from other domains or access applications from different domains.

If you don't configure this policy setting, users can't open other windows and frames from different domains or access applications from different domains.

Name Value
Name IZ_PolicyNavigateSubframesAcrossDomains_8
Friendly Name Navigate windows and frames across different domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
ADMX File Name inetres.admx

LockedDownTrustedSitesZoneAllowAccessToDataSources

Name Value
Name IZ_PolicyAccessDataSourcesAcrossDomains_6
Friendly Name Access data sources across domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
ADMX File Name inetres.admx

LockedDownTrustedSitesZoneAllowAutomaticPromptingForActiveXControls

Name Value
Name IZ_PolicyNotificationBarActiveXURLaction_6
Friendly Name Automatic prompting for ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
ADMX File Name inetres.admx

LockedDownTrustedSitesZoneAllowAutomaticPromptingForFileDownloads

Name Value
Name IZ_PolicyNotificationBarDownloadURLaction_6
Friendly Name Automatic prompting for file downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
ADMX File Name inetres.admx

LockedDownTrustedSitesZoneAllowFontDownloads

Name Value
Name IZ_PolicyFontDownload_6
Friendly Name Allow font downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
ADMX File Name inetres.admx

LockedDownTrustedSitesZoneAllowLessPrivilegedSites

Name Value
Name IZ_PolicyZoneElevationURLaction_6
Friendly Name Web sites in less privileged Web content zones can navigate into this zone
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
ADMX File Name inetres.admx

LockedDownTrustedSitesZoneAllowNETFrameworkReliantComponents

Name Value
Name IZ_PolicyUnsignedFrameworkComponentsURLaction_6
Friendly Name Run .NET Framework-reliant components not signed with Authenticode
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
ADMX File Name inetres.admx

LockedDownTrustedSitesZoneAllowScriptlets

Name Value
Name IZ_Policy_AllowScriptlets_6
Friendly Name Allow scriptlets
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
ADMX File Name inetres.admx

LockedDownTrustedSitesZoneAllowSmartScreenIE

Name Value
Name IZ_Policy_Phishing_6
Friendly Name Turn on SmartScreen Filter scan
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
ADMX File Name inetres.admx

LockedDownTrustedSitesZoneAllowUserDataPersistence

Name Value
Name IZ_PolicyUserdataPersistence_6
Friendly Name Userdata persistence
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
ADMX File Name inetres.admx

LockedDownTrustedSitesZoneInitializeAndScriptActiveXControls

Name Value
Name IZ_PolicyScriptActiveXNotMarkedSafe_6
Friendly Name Initialize and script ActiveX controls not marked as safe
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
ADMX File Name inetres.admx

LockedDownTrustedSitesZoneJavaPermissions

Name Value
Name IZ_PolicyJavaPermissions_6
Friendly Name Java permissions
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
ADMX File Name inetres.admx

LockedDownTrustedSitesZoneNavigateWindowsAndFrames

Name Value
Name IZ_PolicyNavigateSubframesAcrossDomains_6
Friendly Name Navigate windows and frames across different domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Locked-Down Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
ADMX File Name inetres.admx

MimeSniffingSafetyFeatureInternetExplorerProcesses

This policy setting determines whether Internet Explorer MIME sniffing will prevent promotion of a file of one type to a more dangerous file type.

If you enable this policy setting, MIME sniffing will never promote a file of one type to a more dangerous file type.

If you disable this policy setting, Internet Explorer processes will allow a MIME sniff promoting a file of one type to a more dangerous file type.

If you don't configure this policy setting, MIME sniffing will never promote a file of one type to a more dangerous file type.

Name Value
Name IESF_PolicyExplorerProcesses_6
Friendly Name Internet Explorer Processes
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Security Features > Mime Sniffing Safety Feature
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING
ADMX File Name inetres.admx

MKProtocolSecurityRestrictionInternetExplorerProcesses

The MK Protocol Security Restriction policy setting reduces attack surface area by preventing the MK protocol. Resources hosted on the MK protocol will fail.

If you enable this policy setting, the MK Protocol is prevented for File Explorer and Internet Explorer, and resources hosted on the MK protocol will fail.

If you disable this policy setting, applications can use the MK protocol API. Resources hosted on the MK protocol will work for the File Explorer and Internet Explorer processes.

If you don't configure this policy setting, the MK Protocol is prevented for File Explorer and Internet Explorer, and resources hosted on the MK protocol will fail.

Name Value
Name IESF_PolicyExplorerProcesses_3
Friendly Name Internet Explorer Processes
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Security Features > MK Protocol Security Restriction
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL
ADMX File Name inetres.admx

NewTabDefaultPage

This policy setting allows you to specify what's displayed when the user opens a new tab.

If you enable this policy setting, you can choose which page to display when the user opens a new tab: blank page (about:blank), the first home page, the new tab page or the new tab page with my news feed.

If you disable or don't configure this policy setting, the user can select his or her preference for this behavior.

Name Value
Name NewTabAction
Friendly Name Specify default behavior for a new tab
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\TabbedBrowsing
ADMX File Name inetres.admx

NotificationBarInternetExplorerProcesses

This policy setting allows you to manage whether the Notification bar is displayed for Internet Explorer processes when file or code installs are restricted. By default, the Notification bar is displayed for Internet Explorer processes.

If you enable this policy setting, the Notification bar will be displayed for Internet Explorer Processes.

If you disable this policy setting, the Notification bar won't be displayed for Internet Explorer processes.

If you don't configure this policy setting, the Notification bar will be displayed for Internet Explorer Processes.

Name Value
Name IESF_PolicyExplorerProcesses_10
Friendly Name Internet Explorer Processes
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Security Features > Notification bar
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND
ADMX File Name inetres.admx

PreventManagingSmartScreenFilter

This policy setting prevents the user from managing SmartScreen Filter, which warns the user if the website being visited is known for fraudulent attempts to gather personal information through "phishing," or is known to host malware.

If you enable this policy setting, the user isn't prompted to turn on SmartScreen Filter. All website addresses that aren't on the filter's allow list are sent automatically to Microsoft without prompting the user.

If you disable or don't configure this policy setting, the user is prompted to decide whether to turn on SmartScreen Filter during the first-run experience.

Name Value
Name Disable_Managing_Safety_Filter_IE9
Friendly Name Prevent managing SmartScreen Filter
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\PhishingFilter
ADMX File Name inetres.admx

PreventPerUserInstallationOfActiveXControls

This policy setting allows you to prevent the installation of ActiveX controls on a per-user basis.

If you enable this policy setting, ActiveX controls can't be installed on a per-user basis.

If you disable or don't configure this policy setting, ActiveX controls can be installed on a per-user basis.

Name Value
Name DisablePerUserActiveXInstall
Friendly Name Prevent per-user installation of ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Security\ActiveX
Registry Value Name BlockNonAdminActiveXInstall
ADMX File Name inetres.admx

ProtectionFromZoneElevationInternetExplorerProcesses

Internet Explorer places restrictions on each Web page it opens. The restrictions are dependent upon the location of the Web page (Internet, Intranet, Local Machine zone, etc.). Web pages on the local computer have the fewest security restrictions and reside in the Local Machine zone, making the Local Machine security zone a prime target for malicious users. Zone Elevation also disables JavaScript navigation if there is no security context.

If you enable this policy setting, any zone can be protected from zone elevation by Internet Explorer processes.

If you disable this policy setting, no zone receives such protection for Internet Explorer processes.

If you don't configure this policy setting, any zone can be protected from zone elevation by Internet Explorer processes.

Name Value
Name IESF_PolicyExplorerProcesses_9
Friendly Name Internet Explorer Processes
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Security Features > Protection From Zone Elevation
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION
ADMX File Name inetres.admx

RemoveRunThisTimeButtonForOutdatedActiveXControls

This policy setting allows you to stop users from seeing the "Run this time" button and from running specific outdated ActiveX controls in Internet Explorer.

If you enable this policy setting, users won't see the "Run this time" button on the warning message that appears when Internet Explorer blocks an outdated ActiveX control.

If you disable or don't configure this policy setting, users will see the "Run this time" button on the warning message that appears when Internet Explorer blocks an outdated ActiveX control. Clicking this button lets the user run the outdated ActiveX control once.

Name Value
Name VerMgmtDisableRunThisTime
Friendly Name Remove "Run this time" button for outdated ActiveX controls in Internet Explorer
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Security Features > Add-on Management
Registry Key Name Software\Microsoft\Windows\CurrentVersion\Policies\Ext
Registry Value Name RunThisTimeEnabled
ADMX File Name inetres.admx

ResetZoomForDialogInIEMode

Scope Editions Applicable OS
✅ Device
✅ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ [10.0.20348.261] and later
✅ Windows 10, version 1903 [10.0.18362.1832] and later
✅ Windows 10, version 2004 with [10.0.19041.1266] and later
✅ Windows 11, version 21H2 with [10.0.22000.282] and later
✅ Windows 11, version 22H2 [10.0.22621] and later

This policy setting lets admins reset zoom to default for HTML dialogs in Internet Explorer mode.

If you enable this policy, the zoom of an HTML dialog in Internet Explorer mode won't get propagated from its parent page.

If you disable, or don't configure this policy, the zoom of an HTML dialog in Internet Explorer mode will be set based on the zoom of it's parent page.

Name Value
Name ResetZoomForDialogInIEMode
Friendly Name Reset zoom to default for HTML dialogs in Internet Explorer mode
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main\EnterpriseMode
Registry Value Name ResetZoomForDialogInIEMode
ADMX File Name inetres.admx

RestrictActiveXInstallInternetExplorerProcesses

This policy setting enables blocking of ActiveX control installation prompts for Internet Explorer processes.

If you enable this policy setting, prompting for ActiveX control installations will be blocked for Internet Explorer processes.

If you disable this policy setting, prompting for ActiveX control installations won't be blocked for Internet Explorer processes.

If you don't configure this policy setting, the user's preference will be used to determine whether to block ActiveX control installations for Internet Explorer processes.

Name Value
Name IESF_PolicyExplorerProcesses_11
Friendly Name Internet Explorer Processes
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Security Features > Restrict ActiveX Install
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL
ADMX File Name inetres.admx

RestrictedSitesZoneAllowAccessToDataSources

Name Value
Name IZ_PolicyAccessDataSourcesAcrossDomains_7
Friendly Name Access data sources across domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowActiveScripting

This policy setting allows you to manage whether script code on pages in the zone is run.

If you enable this policy setting, script code on pages in the zone can run automatically. If you select Prompt in the drop-down box, users are queried to choose whether to allow script code on pages in the zone to run.

If you disable this policy setting, script code on pages in the zone is prevented from running.

If you don't configure this policy setting, script code on pages in the zone is prevented from running.

Name Value
Name IZ_PolicyActiveScripting_7
Friendly Name Allow active scripting
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowAutomaticPromptingForActiveXControls

Name Value
Name IZ_PolicyNotificationBarActiveXURLaction_7
Friendly Name Automatic prompting for ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowAutomaticPromptingForFileDownloads

Name Value
Name IZ_PolicyNotificationBarDownloadURLaction_7
Friendly Name Automatic prompting for file downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowBinaryAndScriptBehaviors

This policy setting allows you to manage dynamic binary and script behaviors: components that encapsulate specific functionality for HTML elements to which they were attached.

If you enable this policy setting, binary and script behaviors are available. If you select Administrator approved in the drop-down box, only behaviors listed in the Admin-approved Behaviors under Binary Behaviors Security Restriction policy are available.

If you disable this policy setting, binary and script behaviors aren't available unless applications have implemented a custom security manager.

If you don't configure this policy setting, binary and script behaviors aren't available unless applications have implemented a custom security manager.

Name Value
Name IZ_PolicyBinaryBehaviors_7
Friendly Name Allow binary and script behaviors
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowCopyPasteViaScript

If you don't configure this policy setting, a script can't perform a clipboard operation.

Name Value
Name IZ_PolicyAllowPasteViaScript_7
Friendly Name Allow cut, copy or paste operations from the clipboard via script
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowDragAndDropCopyAndPasteFiles

If you don't configure this policy setting, users are queried to choose whether to drag or copy files from this zone.

Name Value
Name IZ_PolicyDropOrPasteFiles_7
Friendly Name Allow drag and drop or copy and paste files
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowFileDownloads

This policy setting allows you to manage whether file downloads are permitted from the zone. This option is determined by the zone of the page with the link causing the download, not the zone from which the file is delivered.

If you enable this policy setting, files can be downloaded from the zone.

If you disable this policy setting, files are prevented from being downloaded from the zone.

If you don't configure this policy setting, files are prevented from being downloaded from the zone.

Name Value
Name IZ_PolicyFileDownload_7
Friendly Name Allow file downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowFontDownloads

Name Value
Name IZ_PolicyFontDownload_7
Friendly Name Allow font downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowLessPrivilegedSites

Name Value
Name IZ_PolicyZoneElevationURLaction_7
Friendly Name Web sites in less privileged Web content zones can navigate into this zone
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowLoadingOfXAMLFiles

Name Value
Name IZ_Policy_XAML_7
Friendly Name Allow loading of XAML files
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowMETAREFRESH

This policy setting allows you to manage whether a user's browser can be redirected to another Web page if the author of the Web page uses the Meta Refresh setting (tag) to redirect browsers to another Web page.

If you enable this policy setting, a user's browser that loads a page containing an active Meta Refresh setting can be redirected to another Web page.

If you disable this policy setting, a user's browser that loads a page containing an active Meta Refresh setting can't be redirected to another Web page.

If you don't configure this policy setting, a user's browser that loads a page containing an active Meta Refresh setting can't be redirected to another Web page.

Name Value
Name IZ_PolicyAllowMETAREFRESH_7
Friendly Name Allow META REFRESH
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowNETFrameworkReliantComponents

Name Value
Name IZ_PolicyUnsignedFrameworkComponentsURLaction_7
Friendly Name Run .NET Framework-reliant components not signed with Authenticode
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowOnlyApprovedDomainsToUseActiveXControls

Name Value
Name IZ_PolicyOnlyAllowApprovedDomainsToUseActiveXWithoutPrompt_Both_Restricted
Friendly Name Allow only approved domains to use ActiveX controls without prompt
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowOnlyApprovedDomainsToUseTDCActiveXControl

Name Value
Name IZ_PolicyAllowTDCControl_Both_Restricted
Friendly Name Allow only approved domains to use the TDC ActiveX control
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowScriptingOfInternetExplorerWebBrowserControls

Name Value
Name IZ_Policy_WebBrowserControl_7
Friendly Name Allow scripting of Internet Explorer WebBrowser controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowScriptInitiatedWindows

Name Value
Name IZ_PolicyWindowsRestrictionsURLaction_7
Friendly Name Allow script-initiated windows without size or position constraints
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowScriptlets

Name Value
Name IZ_Policy_AllowScriptlets_7
Friendly Name Allow scriptlets
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowSmartScreenIE

Name Value
Name IZ_Policy_Phishing_7
Friendly Name Turn on SmartScreen Filter scan
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowUpdatesToStatusBarViaScript

Name Value
Name IZ_Policy_ScriptStatusBar_7
Friendly Name Allow updates to status bar via script
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowUserDataPersistence

Name Value
Name IZ_PolicyUserdataPersistence_7
Friendly Name Userdata persistence
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneAllowVBScriptToRunInInternetExplorer

Name Value
Name IZ_PolicyAllowVBScript_7
Friendly Name Allow VBScript to run in Internet Explorer
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneDoNotRunAntimalwareAgainstActiveXControls

Name Value
Name IZ_PolicyAntiMalwareCheckingOfActiveXControls_7
Friendly Name Don't run antimalware programs against ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneDownloadSignedActiveXControls

If you don't configure this policy setting, signed controls can't be downloaded.

Name Value
Name IZ_PolicyDownloadSignedActiveX_7
Friendly Name Download signed ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneDownloadUnsignedActiveXControls

Name Value
Name IZ_PolicyDownloadUnsignedActiveX_7
Friendly Name Download unsigned ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneEnableCrossSiteScriptingFilter

Name Value
Name IZ_PolicyTurnOnXSSFilter_Both_Restricted
Friendly Name Turn on Cross-Site Scripting Filter
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneEnableDraggingOfContentFromDifferentDomainsAcrossWindows

Name Value
Name IZ_PolicyDragDropAcrossDomainsAcrossWindows_Both_Restricted
Friendly Name Enable dragging of content from different domains across windows
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneEnableDraggingOfContentFromDifferentDomainsWithinWindows

Name Value
Name IZ_PolicyDragDropAcrossDomainsWithinWindow_Both_Restricted
Friendly Name Enable dragging of content from different domains within a window
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneEnableMIMESniffing

If you don't configure this policy setting, the actions that may be harmful can't run; this Internet Explorer security feature will be turned on in this zone, as dictated by the feature control setting for the process.

Name Value
Name IZ_PolicyMimeSniffingURLaction_7
Friendly Name Enable MIME Sniffing
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneIncludeLocalPathWhenUploadingFilesToServer

Name Value
Name IZ_Policy_LocalPathForUpload_7
Friendly Name Include local path when user is uploading files to a server
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneInitializeAndScriptActiveXControls

Name Value
Name IZ_PolicyScriptActiveXNotMarkedSafe_7
Friendly Name Initialize and script ActiveX controls not marked as safe
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneJavaPermissions

Name Value
Name IZ_PolicyJavaPermissions_7
Friendly Name Java permissions
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneLaunchingApplicationsAndFilesInIFRAME

If you don't configure this policy setting, users are prevented from running applications and downloading files from IFRAMEs on the pages in this zone.

Name Value
Name IZ_PolicyLaunchAppsAndFilesInIFRAME_7
Friendly Name Launching applications and files in an IFRAME
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneLogonOptions

If you don't configure this policy setting, logon is set to Prompt for username and password.

Name Value
Name IZ_PolicyLogon_7
Friendly Name Logon options
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneNavigateWindowsAndFrames

Name Value
Name IZ_PolicyNavigateSubframesAcrossDomains_7
Friendly Name Navigate windows and frames across different domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneRunActiveXControlsAndPlugins

This policy setting allows you to manage whether ActiveX controls and plug-ins can be run on pages from the specified zone.

  • If you enable this policy setting, controls and plug-ins can run without user intervention.

If you selected Prompt in the drop-down box, users are asked to choose whether to allow the controls or plug-in to run.

If you disable this policy setting, controls and plug-ins are prevented from running.

If you don't configure this policy setting, controls and plug-ins are prevented from running.

Name Value
Name IZ_PolicyRunActiveXControls_7
Friendly Name Run ActiveX controls and plugins
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneRunNETFrameworkReliantComponentsSignedWithAuthenticode

If you don't configure this policy setting, Internet Explorer won't execute signed managed components.

Name Value
Name IZ_PolicySignedFrameworkComponentsURLaction_7
Friendly Name Run .NET Framework-reliant components signed with Authenticode
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneScriptActiveXControlsMarkedSafeForScripting

This policy setting allows you to manage whether an ActiveX control marked safe for scripting can interact with a script.

  • If you enable this policy setting, script interaction can occur automatically without user intervention.

If you select Prompt in the drop-down box, users are queried to choose whether to allow script interaction.

If you disable this policy setting, script interaction is prevented from occurring.

If you don't configure this policy setting, script interaction is prevented from occurring.

Name Value
Name IZ_PolicyScriptActiveXMarkedSafe_7
Friendly Name Script ActiveX controls marked safe for scripting
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneScriptingOfJavaApplets

This policy setting allows you to manage whether applets are exposed to scripts within the zone.

  • If you enable this policy setting, scripts can access applets automatically without user intervention.

If you select Prompt in the drop-down box, users are queried to choose whether to allow scripts to access applets.

If you disable this policy setting, scripts are prevented from accessing applets.

If you don't configure this policy setting, scripts are prevented from accessing applets.

Name Value
Name IZ_PolicyScriptingOfJavaApplets_7
Friendly Name Scripting of Java applets
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneShowSecurityWarningForPotentiallyUnsafeFiles

Name Value
Name IZ_Policy_UnsafeFiles_7
Friendly Name Show security warning for potentially unsafe files
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneTurnOnProtectedMode

Name Value
Name IZ_Policy_TurnOnProtectedMode_7
Friendly Name Turn on Protected Mode
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictedSitesZoneUsePopupBlocker

Name Value
Name IZ_PolicyBlockPopupWindows_7
Friendly Name Use Pop-up Blocker
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Restricted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ADMX File Name inetres.admx

RestrictFileDownloadInternetExplorerProcesses

This policy setting enables blocking of file download prompts that aren't user initiated.

If you enable this policy setting, file download prompts that aren't user initiated will be blocked for Internet Explorer processes.

If you disable this policy setting, prompting will occur for file downloads that aren't user initiated for Internet Explorer processes.

If you don't configure this policy setting, the user's preference determines whether to prompt for file downloads that aren't user initiated for Internet Explorer processes.

Name Value
Name IESF_PolicyExplorerProcesses_12
Friendly Name Internet Explorer Processes
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Security Features > Restrict File Download
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD
ADMX File Name inetres.admx

ScriptedWindowSecurityRestrictionsInternetExplorerProcesses

Internet Explorer allows scripts to programmatically open, resize, and reposition windows of various types. The Window Restrictions security feature restricts popup windows and prohibits scripts from displaying windows in which the title and status bars aren't visible to the user or obfuscate other Windows' title and status bars.

If you enable this policy setting, popup windows and other restrictions apply for File Explorer and Internet Explorer processes.

If you disable this policy setting, scripts can continue to create popup windows and windows that obfuscate other windows.

If you don't configure this policy setting, popup windows and other restrictions apply for File Explorer and Internet Explorer processes.

Name Value
Name IESF_PolicyExplorerProcesses_8
Friendly Name Internet Explorer Processes
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Security Features > Scripted Window Security Restrictions
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS
ADMX File Name inetres.admx

SearchProviderList

This policy setting allows you to restrict the search providers that appear in the Search box in Internet Explorer to those defined in the list of policy keys for search providers (found under [HKCU or HKLM\Software\policies\Microsoft\Internet Explorer\SearchScopes]). Normally, search providers can be added from third-party toolbars or in Setup, but the user can also add them from a search provider's website.

  • If you enable this policy setting, the user can't configure the list of search providers on his or her computer, and any default providers installed don't appear (including providers installed from other applications). The only providers that appear are those in the list of policy keys for search providers.

This list can be created through a custom administrative template file. For information about creating this custom administrative template file, see the Internet Explorer documentation on search providers.

  • If you disable or don't configure this policy setting, the user can configure his or her list of search providers.
Name Value
Name SpecificSearchProvider
Friendly Name Restrict search providers to a specific list
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions
Registry Value Name UsePolicySearchProvidersOnly
ADMX File Name inetres.admx

SecurityZonesUseOnlyMachineSettings

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ Windows SE
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 10, version 1803 [10.0.17134] and later

Applies security zone information to all users of the same computer. A security zone is a group of Web sites with the same security level.

If you enable this policy, changes that the user makes to a security zone will apply to all users of that computer.

If you disable this policy or don't configure it, users of the same computer can establish their own security zone settings.

This policy is intended to ensure that security zone settings apply uniformly to the same computer and don't vary from user to user.

Also, see the "Security zones: Don't allow users to change policies" policy.

Name Value
Name Security_HKLM_only
Friendly Name Security Zones: Use only machine settings
Location Computer Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
Registry Value Name Security_HKLM_only
ADMX File Name inetres.admx

SendSitesNotInEnterpriseSiteListToEdge

This setting lets you decide whether to open all sites not included in the Enterprise Mode Site List in Microsoft Edge. If you use this setting, you must also turn on the Administrative Templates\Windows Components\Internet Explorer\Use the Enterprise Mode IE website list policy setting and you must include at least one site in the Enterprise Mode Site List.

Enabling this setting automatically opens all sites not included in the Enterprise Mode Site List in Microsoft Edge.

Disabling, or not configuring this setting, opens all sites based on the currently active browser.

If you've also enabled the Administrative Templates\Windows Components\Microsoft Edge\Send all intranet sites to Internet Explorer 11 policy setting, then all intranet sites will continue to open in Internet Explorer 11.

This MDM policy is still outstanding.

Name Value
Name RestrictInternetExplorer
Friendly Name Send all sites not included in the Enterprise Mode Site List to Microsoft Edge
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Internet Explorer\Main\EnterpriseMode
Registry Value Name RestrictIE
ADMX File Name inetres.admx

SpecifyUseOfActiveXInstallerService

This policy setting allows you to specify how ActiveX controls are installed.

If you enable this policy setting, ActiveX controls are installed only if the ActiveX Installer Service is present and has been configured to allow the installation of ActiveX controls.

If you disable or don't configure this policy setting, ActiveX controls, including per-user controls, are installed through the standard installation process.

Name Value
Name OnlyUseAXISForActiveXInstall
Friendly Name Specify use of ActiveX Installer Service for installation of ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer
Registry Key Name Software\Policies\Microsoft\Windows\AxInstaller
Registry Value Name OnlyUseAXISForActiveXInstall
ADMX File Name inetres.admx

TrustedSitesZoneAllowAccessToDataSources

Name Value
Name IZ_PolicyAccessDataSourcesAcrossDomains_5
Friendly Name Access data sources across domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
ADMX File Name inetres.admx

TrustedSitesZoneAllowAutomaticPromptingForActiveXControls

Name Value
Name IZ_PolicyNotificationBarActiveXURLaction_5
Friendly Name Automatic prompting for ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
ADMX File Name inetres.admx

TrustedSitesZoneAllowAutomaticPromptingForFileDownloads

Name Value
Name IZ_PolicyNotificationBarDownloadURLaction_5
Friendly Name Automatic prompting for file downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
ADMX File Name inetres.admx

TrustedSitesZoneAllowFontDownloads

Name Value
Name IZ_PolicyFontDownload_5
Friendly Name Allow font downloads
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
ADMX File Name inetres.admx

TrustedSitesZoneAllowLessPrivilegedSites

If you don't configure this policy setting, a warning is issued to the user that potentially risky navigation is about to occur.

Name Value
Name IZ_PolicyZoneElevationURLaction_5
Friendly Name Web sites in less privileged Web content zones can navigate into this zone
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
ADMX File Name inetres.admx

TrustedSitesZoneAllowNETFrameworkReliantComponents

Name Value
Name IZ_PolicyUnsignedFrameworkComponentsURLaction_5
Friendly Name Run .NET Framework-reliant components not signed with Authenticode
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
ADMX File Name inetres.admx

TrustedSitesZoneAllowScriptlets

Name Value
Name IZ_Policy_AllowScriptlets_5
Friendly Name Allow scriptlets
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
ADMX File Name inetres.admx

TrustedSitesZoneAllowSmartScreenIE

Name Value
Name IZ_Policy_Phishing_5
Friendly Name Turn on SmartScreen Filter scan
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
ADMX File Name inetres.admx

TrustedSitesZoneAllowUserDataPersistence

Name Value
Name IZ_PolicyUserdataPersistence_5
Friendly Name Userdata persistence
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
ADMX File Name inetres.admx

TrustedSitesZoneDoNotRunAntimalwareAgainstActiveXControls

Name Value
Name IZ_PolicyAntiMalwareCheckingOfActiveXControls_5
Friendly Name Don't run antimalware programs against ActiveX controls
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
ADMX File Name inetres.admx

TrustedSitesZoneInitializeAndScriptActiveXControls

Name Value
Name IZ_PolicyScriptActiveXNotMarkedSafe_5
Friendly Name Initialize and script ActiveX controls not marked as safe
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
ADMX File Name inetres.admx

TrustedSitesZoneJavaPermissions

If you don't configure this policy setting, the permission is set to Low Safety.

Name Value
Name IZ_PolicyJavaPermissions_5
Friendly Name Java permissions
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
ADMX File Name inetres.admx

TrustedSitesZoneLogonOptions

Name Value
Name IZ_PolicyLogon_5
Friendly Name Logon options
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
ADMX File Name inetres.admx

TrustedSitesZoneNavigateWindowsAndFrames

Name Value
Name IZ_PolicyNavigateSubframesAcrossDomains_5
Friendly Name Navigate windows and frames across different domains
Location Computer and User Configuration
Path Windows Components > Internet Explorer > Internet Control Panel > Security Page > Trusted Sites Zone
Registry Key Name Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
ADMX File Name inetres.admx

Related articles

Policy configuration service provider

Was this page helpful?

Coming soon: Throughout 2024 we will be phasing out GitHub Issues as the feedback mechanism for content and replacing it with a new feedback system. For more information see: https://aka.ms/ContentUserFeedback .

Submit and view feedback for

Additional resources

IMAGES

  1. Securing zone levels in Internet Explorer

    site zone assignment list values

  2. Adding Site to Zone assignment list using IE ADMX/L in ProfileUnity

    site zone assignment list values

  3. 16.site to zone assignment list

    site zone assignment list values

  4. Adding Trusted Site to Group Policy in Windows 10

    site zone assignment list values

  5. Site to Zone Assignment list и Internet Explorer с включенной Enhanced

    site zone assignment list values

  6. Site to Zone Assignment list и Internet Explorer с включенной Enhanced

    site zone assignment list values

COMMENTS

  1. internet explorer

    The key should contain several string values with a name indicating the URL and numeric data indicating the zone, one of the following by default. 0 = My Computer; 1 = Local Intranet Zone; 2 = Trusted sites Zone; ... double-click on the Site to Zone Assignment List option, then click ...

  2. Securing zone levels in Internet Explorer

    The zone values are as follows: 1 — intranet, 2 — trusted sites, 3 — internet zone, 4 — restricted sites. Click OK. Click Apply and OK. Figure 1. Assigning sites to the Trusted Sites zone. Figure 2. Enabling the Site to Zone Assignment List policy. By enabling this policy setting, you can manage a list of sites that you want to ...

  3. Adding Sites to Internet Security Zones Using Group Policy

    In the second box, labeled "Enter the value of the item to be added:", enter the number that corresponds to the Internet Explorer security zone that the site should be added to. The zone assignments are as follows: 1 - Intranet Zone; 2 - Trusted Sites Zone; 3 - Internet Zone; 4 - Restricted Sites Zone; Once the zone assignment has ...

  4. Group Policy Template "Site to Zone Assignment List"

    Open Group Policy Management Console. Navigate to the desired GPO or create a new one. Expand User Configuration or Computer Configuration and go to Preferences -> Windows Settings -> Registry. Right-click and select New -> Registry Item. Configure the Registry Item to delete the specified entries under the ZoneMap registry key.

  5. How to add the URLs to the Trusted Sites zone

    In this part of the series, we'll look at the required Hybrid Identity URLs that you want to add to the Trusted Sites list in Internet Explorer. Note: This is the second part for adding Microsoft Cloud URLs to Internet Explorer's zone. In this part we look at the Trusted Sites zone. In the previous part we looked at the Local Intranet zone ...

  6. Per-site configuration by policy

    In managed environments, administrators can use Group Policy to assign specific sites to Zones (via "Site to Zone Assignment List" policy) and specify the settings for URLActions on a per-zone basis. Beyond manual administrative or user assignment of sites to Zones, other heuristics could assign sites to the Local Intranet Zone.

  7. How to use Group Policy to configure Internet Explorer security zone sites

    Step 2. Navigate to User Configuration > Administrative Templates > Windows Components > Internet Explorer > Internet Control Panel > Security Page and double click on the “Site to Zone Assignment List†and check the “Enable†option then click on the “Show..†button. Step 3.

  8. Adding Trusted Site to Group Policy in Windows 10

    Double-click on Site to Zone Assignment List in the right pane. Step 3: In the Site to Zone Assignment List window, select Enabled then tap on Show button under Options. Step 4: In the column under Value name, input the website. Then Type 2 in the box next to it. Tips: Internet Explorer includes four safe zones, respectively, one to four. To ...

  9. How to configuring IE Site Zone mapping using group policy without

    TIP: For your reference the values and their corresponding Zones are listed below in the table. Value: Zone Name: 00000000: My Computer: 00000001: Local Intranet: 00000002: Trusted Site: 00000003: ... I've figureout the issue.. Site to zone assignments list should be Not Configured for both Computer and user configuration settings….

  10. Deploy Trusted sites zone assignment using Intune

    Deploy a set of trusted sites overriding users' ability to add trusted sites themselves. To acheive this, an Intune configuration profile Trusted site zone assignment can be deployed to devices/users group as required. Login to Intune Portal and navigate to: Devices > Windows > Configuration Profiles. Hit the Create button and Select New policy.

  11. IE security zones registry entries for advanced users

    The value of the DWORD is the same as the numeric value of the security zone where the domain is added. The ... Value Setting ----- 0 My Computer 1 Local Intranet Zone 2 Trusted sites Zone 3 Internet Zone 4 Restricted Sites Zone Note. By default, My Computer does not appear in the Zone box on the Security tab as it is locked down to help ...

  12. Managing Internet Explorer Trusted Sites with Group Policy

    When possible, use the computer configuration option as it will not impact user logons. When you enable the setting, you will be prompted for a value name (the website) and a value (the zone list). Here are the possible values and the zone that they correspond to: 1 = Intranet/Local Zone. 2 = Trusted Sites. 3 = Internet/Public Zone.

  13. Adding trusted sites using GPO

    If you want to lock it down and add as needed, GPO will work just fine, just go to Win Components/Internet Explorer/Internet Control Panel/Security Page - Site to Zone Assignment - enable the policy, click List and add the sites as needed, a value of 1 is Intranet a value of 2 would be Trusted. Yes. I want to lock it down so I will do it in ...

  14. Assign DFS share to intranet zone via GPO?

    Policies Administrative Templates Windows Components Internet Explorer Internet Control Panel Security Page Site to Zone Assignment List Here, I've added host1.mydomain.org and host2.mydomain.org to zone 1 (intranet), and the network shares from these hosts are correctly treated as trusted intranet sites.

  15. Centrally control IE security zone site assignments via GP

    Step 4: Add URLs to the list and assign a zone. Add the FQDN and then assign the zone; the zone numbers are: 1 = Local Intranet Zone 2 = Trusted Sites Zone 3 = Internet Zone 4 = Restricted Sites Zone. Once you have created your list and zones just apply the GPO to the OU, refresh the policy which will grey-out the option for the user to modify ...

  16. How to add a server to trusted sites

    Click on the Security Zones and Content Ratings folder. Double-click on the Site to Zone Assignment List policy. Click the Enabled radio button. Click the Show button. In the Value name field, enter the server name in the following format: "file://servername" (replace "servername" with the actual name of the server).

  17. Internet Options to add Trusted Site Greyed Out

    In the right-pane, double-click Flags and click Decimal. Add 3 to the existing Value data. Example: If Flags value reads 0 (Decimal), set it to 3 (i.e., 0 + 1 + 2) Flags value listing (from MS-KB 182569) Flags value Setting. 1 Allow changes to custom settings. 2 Allow users to add Web sites to this zone.

  18. Troubleshoot Internet Explorer Zonemapping failures when processing

    The "Site To Zone Assignment List" policy. The format of the Site To Zone Assignment List policy is described within the policy. This policy setting allows you to manage a list of sites that you want to associate with a particular security zone. These zone numbers have associated security settings that apply to all sites in the zone.

  19. Site to Zone Assignment List

    Re: Site to Zone Assignment List - Powershell. # Step 2: Navigate to the Site to Zone Assignment List # This step is manual and requires navigating through the Group Policy Management Editor interface. # Step 3: Enable the Policy and Specify Zone Assignments # Define the list of URLs and their corresponding zone assignments.

  20. How To Add Sites to Internet Explorer Restricted Zone

    In the Security Filtering section, click Add and select the group. Login to the client computer and launch the Internet Explorer. Click on Tools > Internet Options > Security Tab > Restricted Sites > Click Sites. Notice that the URL is added to the Restricted Sites zone and user cannot remove it from the list. In this post we will see the steps ...

  21. IE and Microsoft Edge FAQ for IT Pros

    The Site to Zone Assignment List policy setting associates sites to zones by using the following values for the Internet security zones: Intranet zone; Trusted Sites zone; Internet zone; Restricted Sites zone; If you set this policy setting to Enabled, you can enter a list of sites and their related zone numbers. By associating a site to a zone ...

  22. Site to Zone Assignment List

    the list of sites is blank for users - but populated for my admin account. My GPO settings under Computer\Admin Templates\Windows Components\IE\IE. Control Panel\Security Page : Site to Zone Assignment List Enabled (and populated with sites) Intranet Sites : Include all local Enabled. Intranet Sites Include all sites that bypass proxy Enabled.

  23. InternetExplorer Policy CSP

    Value - A number indicating the zone with which this site should be associated for security settings. The Internet Explorer zones described above are 1-4. If you disable or don't configure this policy, users may choose their own site-to-zone assignments.